Scripts for MacOS related tasks.
☆18Feb 16, 2020Updated 6 years ago
Alternatives and similar repositories for Darwin
Users that are interested in Darwin are comparing it to the libraries listed below
Sorting:
- Disk Image Mounting Script☆11Jan 22, 2026Updated last month
- macOS Artifact Intelligence Tool☆13Apr 30, 2019Updated 6 years ago
- MasterParser is a simple, all-in-one, digital forensics artifact parser☆24Jul 9, 2021Updated 4 years ago
- Carve $MFT records from a chunk of data (for instance a memory dump)☆16Aug 21, 2016Updated 9 years ago
- A preconfigured Windows-based system designed for rapid forensic investigations in both Azure and AWS.☆39Mar 25, 2024Updated last year
- Mass Triage Tools☆20Dec 16, 2025Updated 2 months ago
- Emulates the Sysinternals Autoruns tool, but for DFIR purposes e.g. multi user processing☆55May 18, 2019Updated 6 years ago
- Cumulonimbus-UAL_Extractor is a PowerShell based tool created by the Tesorion CERT team to help gather the Unified Audit Logging out of a…☆21Oct 25, 2023Updated 2 years ago
- Extract files off NTFS☆22Nov 1, 2014Updated 11 years ago
- Fast, inline geolocation decoration of IPv4 and IPv6 addresses written in Rust☆29Updated this week
- Easy to extend initial access scenario to help with EDR testing on Linux and Mac☆26Mar 20, 2022Updated 3 years ago
- ☆93Jul 30, 2025Updated 7 months ago
- A RESTful API frontend for Stenographer☆54Dec 7, 2022Updated 3 years ago
- Initial triage of Windows Event logs☆106Jun 16, 2024Updated last year
- Cobalt Strike log state tracking, parsing, and storage☆24Jul 18, 2019Updated 6 years ago
- Yara rules☆22Mar 27, 2023Updated 2 years ago
- Simple Imager has been created for performing live acquisition of Windows based systems in a forensically sound manner☆30Feb 27, 2026Updated last week
- Tool for analysts to perform simultaneous lookups (IP, Domain, URL, MD5) against multiple data sources☆28Jan 27, 2017Updated 9 years ago
- Tool to parse SRU database☆25Mar 1, 2018Updated 8 years ago
- Core incident handling plugins for aws_ir cli, incident pony, and more.☆21Jul 7, 2018Updated 7 years ago
- Lokix Platform is a free open-source solution to help blue teams and threat hunters use Loki Scanner to sweep enterprise networks☆25Aug 8, 2020Updated 5 years ago
- Extract BITS jobs from QMGR queue and store them as CSV records☆74Feb 13, 2025Updated last year
- ☆67Feb 19, 2025Updated last year
- Generates visualizations from the output of flow tools such as SiLK.☆35Dec 8, 2016Updated 9 years ago
- PowerShell 'Hero': scripts for DFIR and automation with a PowerShell menu example.☆37Jul 11, 2023Updated 2 years ago
- Windows 10 Live Information viewer☆38Jan 27, 2022Updated 4 years ago
- ☆36Jan 11, 2023Updated 3 years ago
- Library of python scripts to apply Data Science in several forensics artifacts☆31Jul 16, 2020Updated 5 years ago
- Evidence Fetcher (efetch) is a web-based file explorer, viewer, and analyzer.☆39Apr 11, 2020Updated 5 years ago
- Filters that process and transform the output of osxcollector☆77Sep 6, 2019Updated 6 years ago
- Stand-alone parser for User Access Logging from Server 2012 and newer systems☆78Jan 9, 2024Updated 2 years ago
- A python script to acquire multiple aws ec2 instances in a forensically sound-ish way☆38Nov 8, 2021Updated 4 years ago
- The Cold Disk Quick Response (CDQR) tool is a fast and easy to use forensic artifact parsing tool that works on disk images, mounted driv…☆343Jun 25, 2022Updated 3 years ago
- Zeek Extension to Collect Metadata for Profiling of Endpoints and Proxies☆40Sep 2, 2025Updated 6 months ago
- A parser for Unified logging tracev3 files☆97Jul 25, 2025Updated 7 months ago
- Threat Response API Module☆10Oct 4, 2023Updated 2 years ago
- Fluxion is a easy to use wifi cracker, to test your own network☆11Feb 8, 2017Updated 9 years ago
- Scripts that cover the basics of interacting with the Threat Grid API☆11Jan 21, 2020Updated 6 years ago
- Automate ISSG Tool Setups☆13Nov 21, 2024Updated last year