KeepSafe is a mobile application designed to provide secure storage for
photos, videos, and other personal files. It uses passcodes, biometrics,
and encryption to restrict access and protect sensitive media from
unauthorized viewing. The app is popular among users seeking privacy for
their digital content, offering a hidden vault separate from the
standard iOS photo library. The iOS version enables users to import,
organize, and manage their private files directly from their devices
while maintaining a protected environment.
Forensic investigators can obtain critical evidence from artifacts
stored locally by KeepSafe. These may include details about imported
media, timestamps, file names, and user access activity. The parsers can
analyze these artifacts to reveal patterns of use, attempted access, or
deleted content. Such findings can assist in reconstructing timelines,
identifying user intent, and determining whether the application was
used to conceal relevant evidence.
iOS KeepSafe artifact can be found at the following location:
*private/var/mobile/Containers/Data/Application/<App-GUID>/Library/Application
Support/adjust/adjustIoActivityState
private/var/mobile/Containers/Shared/AppGroup/<App-GUID>/Preference/group.com.keepsafe.keep..Safe.plist
This section will discuss how to use ArtiFast to extract iOS KeepSafe
artifacts from iOS machines’ files and what kind of digital forensics
insights we can gain from the artifact.
After you have created your case and added evidence for the
investigation, at the Artifact Selection phase, you can select iOS
KeepSafe artifact parsers:
Once ArtiFast parsers plugins complete processing the artifact for analysis, it can be reviewed via “Artifact View” or “Timeline View,” with indexing, filtering, and searching capabilities. Below is a detailed description of iOS KeepSafe artifacts in ArtiFast.
iOS KeepSafe Albums
iOS KeepSafe Preferences
iOS KeepSafe Adjust Activity State
For more information or suggestions please contact: ekrma.elnour@forensafe.com