Cover
Alexis Brignoni
Alexis Brignoni
Certified Digital Forensics Examiner
Creator of LEAPPs · Podcast Co-Host · Python for DFIR
—
LEAPPs Downloads
3
Peer-Reviewed Papers
30+
Talks & Interviews
CISSP
ISC2 Certified
—
Podcast Episodes
—
GitHub Stars
About

Digital Forensics with 15+ years in the field. Mobile forensics specialist. Building open-source DFIR tools since 2019. Python for DFIR. Native Spanish speaker.

“Tool reports are not the data. The data is the data. Validate everything that matters.”

Credentials

Education — B.S. in Computer Science, Antillean Adventist University; M.B.A. in Management of Information Systems, Universidad Interamericana de Puerto Rico

CISSP — ISC2 Certified Information Systems Security Professional. Badges on Credly

SANS Institute — FOR 585 Advanced Smartphone Forensics, FOR 498 Battlefield Data Acquisition, Netwars DFIR Champion, recurring DFIR Summit speaker

IACIS — Instructor; authored the Android portion of the Mobile Device Forensics course and the data-structure content of the Advanced Mobile Device Forensics course

Recognition — Extraordinary Visiting Scholar, FASTA University — Mar del Plata, Argentina

Judge — DFIR + AI 2026 Challenge, a vendor-agnostic initiative on GenAI in investigations

What I Do

Podcast — Co-host of Digital Forensics Now — Podcast · YouTube Live

LEAPPs — Creator of the open-source DFIR platform for iOS, Android, vehicle, legal-return, desktop & image/video forensics; integrated into Autopsy, Paraben, Atrio, Evanole & Mobasi. leapps.org/releases

DFIR Python Study Group — Founder & facilitator; teaching examiners to read and write Python. Session playlist

Blog — Research & notes at leapps.org/blog

Opinions are mine only, are subject to change, and do not represent my employer or anyone else.

Jump to: LEAPPs · Papers · Talks · Links

LEAPPs Tools
🌋 LAVA — LEAPPs Artifact Viewer Application

LAVA is a modern reporting and visualization tool for the LEAPPs family of digital forensics parsers (iLEAPP, ALEAPP, etc.). It provides faster, efficient reporting of LEAPPs’ parsed data.

Video explanation & demo: youtube.com/watch?v=17TQn7IsM4E

How to make LAVA compliant artifacts: youtube.com/watch?v=qTgZUh4GPxk

Download: leapps.org/releases

📱 iLEAPP — iOS Logs Events and Plist Parser

A python based framework to quickly triage iOS full file system extractions and unencrypted iTunes backups. A community project.

Get it: leapps.org/releases

Demo: cellebrite.com — Getting Started

🤖 ALEAPP — Android Logs Events and Protobuf Parser

Shares the same codebase as iLEAPP but focused on Android forensic artifacts.

Get it: leapps.org/releases

17-min presentation: youtu.be/Wb35VKHfrgc

📂 RLEAPP — Returns Events Logs And Properties Parser

Takes web service legal returns, as well as user-initiated archives, and parses them for easy review.

Get it: leapps.org/releases

🚗 VLEAPP — Vehicle Logs Events And Properties Parser

Takes extractions from cars and parses them for interesting artifacts.

Get it: leapps.org/releases

Demo: cellebrite.com — What’s new with xLEAPP?

🖥️ DLEAPP — Desktop Logs, Events and Protobuf Parser

Parses desktop application artifacts (Electron, Chromium and friends), plus any artifact that doesn’t fit the platform-specific LEAPPs.

Get it: leapps.org/releases

🖼️ GLEAPP — Graphics, Logs, Examination, Automated Processing, Parsing

Triage and analysis for large sets of images and video. Ingests folders, full file system extractions and disk images, hashes and de-duplicates the media, reads metadata, pulls video key frames, matches known-hash lists, and opens a local review gallery. Written by Heather Charpentier.

Get it: leapps.org/releases

⚙️ Batch LEAPP — Run any LEAPP across a folder of extractions

Point it at a directory and it finds every extraction inside, runs the matching LEAPP against each one in parallel, and builds a single report index linking every result, with SHA-256 hashing and a manifest for your case file.

Get it: leapps.org/releases

Research & Papers
🎓 Cited 77+ times in academic research — view on Google Scholar ↗
Peer Reviewed — User Notifications in iOS
Peer Reviewed — iOS Mobile Installation Logs
Peer Reviewed — Kik Messenger iOS analysis
SANS Reading Room — Six Steps to Successful Mobile Validation
SANS Reading Room — Identifying Android OS Version thru UsageStats
Mentioned — SANS iOS Third-Party Apps Forensics Reference Poster
Mentioned — DFIR Advanced Smartphone Forensics Poster
Mentioned — Android Third-Party Apps Forensics Poster
Forensic Pattern of Life Analysis
ALEAPP & iLEAPP in DFRWS Research Paper
iLEAPP in MDPI Research Paper
ALEAPP in Garmin for Android Research Paper
LEAPPs in Forensic Analysis of OpenAI ChatGPT Apps
DFPulse 2024 — LEAPPs & Podcast Mentioned
Exploring Frame Counts & Hashing Pixel Data
ALEAPP Used — Forensic Framework for Ray-Ban Meta AI Smart Glasses
So you found a python script. Now what?
iLEAPP Walkthrough by Hexordia
ALEAPP Walkthrough by Hexordia
RLEAPP Walkthrough by Hexordia
DFIR Python Study Group — Playlist
Mobile Forensics Explainer — iLEAPP
Mobile Forensics Explainer — ALEAPP
Gallery
Interviews
Gallery
Talks & Presentations
Gallery
Talks en Español
Gallery
Tool Integrations
Gallery
LEAPPs Walkthroughs
Gallery
Awards
Gallery
Album — Alexis Brignoni
Gallery
Coins & Achievements
Currently Sharing
Link Hub — what I’m sharing right now
→
Platforms
LEAPPs Web Page
↗
LAVA — LEAPPs Artifact Viewer Application
↗
Content
DFIR — YouTube Tutorials & Talks
↗
Digital Forensics Now Podcast
↗
Digital Forensics Now Podcast on Twitch
↗
Blog — Digital Forensics Research
↗
Newsletter — LEAPPs Mailing List
↗
Community
Discord — LEAPPs
↗
GitHub — Python Scripts for DFIR
↗
Social
LinkedIn
↗
Bluesky
↗
Threads — 4n6_abrignoni
↗
Mastodon
↗
Instagram — Digital Forensics
↗
TikTok
↗
Resources
Certifications Digital Forensics Start.me Josh Hickman’s Mobile Test Images The Evidence Locker Digital Forensics Discord Android Forensics Reference iOS Forensics Reference Peer Review Checklist by Hexordia Parsed Extractions for LAVA Testing LEAPPs UI Language Translations
🌐