Built Out of Necessity
LEAPPs began in 2019 as a direct response to a gap in the digital forensics toolset. Alexis Brignoni, then a Special Agent and digital forensic examiner with the FBI, was regularly encountering mobile device artifacts that commercial tools either did not support or parsed incorrectly. Rather than wait for vendors to catch up, he wrote his own parser.
That first parser grew into iLEAPP — the iOS Logs, Events and Plists Parser. iLEAPP was open-sourced on GitHub so that any examiner facing the same problem could use it, improve it, and build on it. The response from the forensics community was immediate. Examiners filed issues, submitted pull requests, and extended the tool in directions that no single person could have anticipated.
What followed was a natural expansion. Android examiners needed the same capability, so ALEAPP followed. ISP return data required its own tooling, so RLEAPP was created. Vehicle system artifacts gave rise to VLEAPP. And as the volume and complexity of parsed output grew, a dedicated viewer — LAVA — was built to make that data navigable in investigations and court proceedings.
"Tool reports are not the data. The data is the data. Validate everything that matters."
Principles That Drive the Project
Every decision in LEAPPs — what to build, how to build it, and who can use it — flows from a small set of principles that have held since the beginning.
How LEAPPs Fits in Your Workflow
LEAPPs is not a replacement for commercial tools — it's a complement. Use what works for your case.
| LEAPPs | Commercial Tools | Manual Review | |
|---|---|---|---|
| Cost | Free | Licensed | Free |
| Source code | ✅ Open | ❌ Closed | — |
| Parser contributions | ✅ Community | ❌ Vendor only | — |
| Code auditable | ✅ Yes | ❌ No | — |
| Offline use | ✅ Yes | Varies | ✅ Yes |
| Custom artifacts | ✅ Yes | ❌ Limited | ✅ Yes |
| Interface | GUI & CLI | GUI only | — |
How We Got Here
Alexis Brignoni
Alexis Brignoni is a digital forensics practitioner, researcher, and educator. He built iLEAPP while working as a Special Agent and digital forensic examiner with the FBI, and has continued to develop the LEAPPs suite alongside his work in the field.
Alexis has presented at SANS DFIR Summit, OSDFCon, Magnet Virtual Summit, and other major DFIR conferences. He has been featured in interviews by Forensic Focus and Cellebrite, and appeared on multiple forensics podcasts. His work on mobile forensics has been incorporated into professional training programs including SANS FOR585 and IACIS Advanced Mobile Device Forensics.
He continues to actively develop and maintain the suite, and regularly hosts live coding sessions open to the community — working through new artifacts, parser patterns, and tool development in the open.
github.com/abrignoni abrignoni.github.io linkedin.com/in/abrignoni
Core Contributors
The LEAPPs suite is shaped by a community of forensics practitioners who contribute parsers, research, and tooling. These contributors have had the most impact on the project.
Johann Polewczyk, retired from law enforcement (French Gendarmerie), is now a Research Manager at the École des Sciences Criminelles, University of Lausanne (UNIL), where he works within the Faculty of Law, Criminal Justice and Public Administration. Based in France, his research focuses on mobile and Apple platform forensics, with particular depth in iOS artifact analysis and Apple Unified Logs.
Johann runs digital-forensics.polewczyk.fr, a technical blog where he publishes in-depth forensic research, and contributes to the field through open-source work on GitHub. In 2026 he was recognized with the Cellebrite JUSTYS Award for Excellence in Digital Forensics in the EMEA region.
github.com/Johann-PLWJames Habben is a Strategy Executive and Cybersecurity Advisor with deep roots in digital forensics and incident response. He has held senior roles at Verizon's RISK Team, Guidance Software, and AlixPartners, where he performed complex forensic examinations and shaped incident response practices. He also serves as a Reserve Deputy Probation Officer for Los Angeles County and as President of ISSA-Orange County.
James is an active contributor to the DFIR community through open-source tooling, writing, and blogging. His work includes contributions to iLEAPP, LAVA, and the 4n6 App Finder. He has spoken at security conferences on topics ranging from weaponized USB devices to forensic methodology.
github.com/JamesHabbenKevin Pagano is a private sector digital forensics and incident response professional with years of experience investigating complex cases at Siemens Healthineers. He holds multiple certifications and has done additional R&D work alongside his primary role. His focus spans mobile forensics and artifact analysis.
Kevin runs stark4n6.com, a blog where he publishes research, tool updates, and forensic findings. He also maintains one of the most comprehensive community forensics resource pages in the field at startme.stark4n6.com and created The Evidence Locker, a repository of publicly available DFIR evidence images for training and research. He is a co-author of The Hitchhiker's Guide to DFIR: Experiences From Beginners and Experts and has been featured on multiple podcasts including Forensic Happy Hour and Chewing the FAT.
github.com/stark4n6Yogesh Khatri is a digital forensics and incident response professional with over 20 years of experience investigating hacking, malware outbreaks, intellectual property theft, zero-day attacks, fraud, and other electronic crimes. He currently serves as DFIR Director at CyberCX in Sydney, Australia.
Yogesh holds industry certifications including EnCE, GREM, GCIA, and GPEN. He has been a regular speaker at CEIC since 2007 and has served as Guest Lecturer at UCLA. His research focus spans macOS forensics, reverse engineering, and artifact analysis, and he is the author of mac_apt (macOS Artifact Parsing Tool) among other open-source tools. He publishes his research at swiftforensics.com.
github.com/ydkhatriJohn Hyla is an Investigator and Forensic Examiner at the Putnam County Sheriff's Office in New York, where he has served in law enforcement for over 19 years — first as Deputy Sheriff and now as Investigator. He also volunteers as an instructor with IACIS (International Association of Computer Investigative Specialists), where he co-teaches the Advanced Mobile Device Forensics course alongside Alexis Brignoni.
John brings over 20 years of IT experience to his forensic work, holding a bachelor's degree in Information Systems and hands-on programming skills in Python, PHP, C#, JavaScript, HTML, and CSS. He publishes mobile forensics research on his blog at bluecrewforensics.com.
github.com/snoop168