A powerful macOS triage collection tool designed for forensic analysis. It gathers critical system artifacts such as FSEvents, Spotlight, Unified Logs, user data and many more, while preserving the original macOS file system structure. Ideal for incident response, digital forensics, and security investigations.
☆48Oct 24, 2025Updated 9 months ago
Alternatives and similar repositories for Mac-Triage
Users that are interested in Mac-Triage are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- macos-collector - Automated Collection of macOS Forensic Artifacts for DFIR☆49Jul 20, 2026Updated 3 weeks ago
- A collection of PowerShell scripts for analyzing macOS Forensic Artifacts☆33Mar 16, 2026Updated 4 months ago
- An AWS CloudTrail exported logs analyzer tool☆21Jul 26, 2026Updated 2 weeks ago
- Quick script to build host or investigation timelines using Carbon Black Response☆12Sep 25, 2018Updated 7 years ago
- macOS forensic acquisition made simple☆294Jun 2, 2026Updated 2 months ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- Forensic cheatsheets for use with cheat☆15Dec 2, 2021Updated 4 years ago
- Python web app for previewing data in a Chrome Profile Folder☆26Jul 1, 2024Updated 2 years ago
- A series of python scripts to extract information from Dark Web Applications☆14Mar 26, 2025Updated last year
- DFIR Timeline Analysis for macOS — SQLite-backed viewer for CSV, TSV, XLSX, EVTX, Plaso, $MFT, and $J files with AI Artifacts, AI Secret …☆307Updated this week
- Automatic, fast parsing of browser artifacts☆17Jan 4, 2025Updated last year
- Suzaku (朱雀) is a sigma-based threat hunting and fast forensics timeline generator for cloud logs.☆211Aug 3, 2026Updated last week
- USN Journal full path builder☆71Apr 16, 2026Updated 3 months ago
- ☆11Aug 3, 2018Updated 8 years ago
- macOS Artifacts☆33Mar 2, 2025Updated last year
- 1-Click AI Models by DigitalOcean Gradient • AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click. Zero configuration with optimized deployments.
- Takajō (鷹匠) is a Hayabusa results analyzer.☆164Jul 11, 2026Updated last month
- Registry to JSON. This Project is for learning purposes and is not maintained.☆12Dec 28, 2021Updated 4 years ago
- Parser for Sdba memory pool tags☆21Jul 16, 2021Updated 5 years ago
- OneDriveExplorer is a command line and GUI based application for reconstructing the folder structure of OneDrive from the <UserCid>.dat a…☆235Aug 1, 2026Updated 2 weeks ago
- ☆24Jul 13, 2026Updated last month
- This tool parses Windows EVTX logs to extract login and logout sessions from a security.evtx file. It uses a Tkinter GUI to let you selec…☆32Feb 22, 2025Updated last year
- A comprehensive PowerShell toolkit for RDP forensics analysis, tracking connection attempts, authentication, sessions, and logoffs across…☆18May 27, 2026Updated 2 months ago
- A forensic analysis framework for enumerating slack artifacts residing in the Operating system.☆18Sep 23, 2025Updated 10 months ago
- Just Another broken Registry Parser (JARP)☆16May 23, 2024Updated 2 years ago
- Virtual machines for every use case on DigitalOcean • AdGet dependable uptime with 99.99% SLA, simple security tools, and predictable monthly pricing with DigitalOcean's virtual machines, called Droplets.
- Plugins for parsing CSV files in Timeline Explorer. This project allows for anyone to add more supported files (i,e. they get a Line #/ta…☆35Jun 5, 2026Updated 2 months ago
- mister-skinnylegs is an open plugin framework for parsing website/webapp artifacts in browser data. It currently provides a command line …☆20Jul 20, 2026Updated 3 weeks ago
- A Model Context Protocol (MCP) server that integrates Volatility 3 memory forensics framework with Claude☆39Jul 7, 2025Updated last year
- Contains compiled binaries of Volatility☆37May 18, 2025Updated last year
- A hex viewer for the sleuths!☆20Nov 7, 2025Updated 9 months ago
- DFIR notebooks GCIH Gold project, paper☆12Apr 30, 2015Updated 11 years ago
- Invoke-Forensics provides PowerShell commands to simplify working with the forensic tools KAPE and RegRipper.☆118Nov 28, 2023Updated 2 years ago
- A forensic open-source parser module for Autopsy that allows extracting the messages, comments, posts, contacts, calendar entries and rea…☆122Aug 4, 2026Updated last week
- Quick ESXi Log Parser☆33Jul 21, 2026Updated 3 weeks ago
- Proton VPN Special Offer - Get 70% off • AdSpecial partner offer. Trusted by over 100 million users worldwide. Tested, Approved and Recommended by Experts.
- Scripts to process macOS forensic artifacts☆213Aug 4, 2024Updated 2 years ago
- macOS (& ios) Artifact Parsing Tool☆1,073Jul 23, 2026Updated 3 weeks ago
- Digital forensic analysis tool that provides a user-friendly interface for investigating disk images.☆212Nov 12, 2025Updated 9 months ago
- ☆18Jun 4, 2025Updated last year
- macOS .DS_Store Parser☆81Aug 17, 2021Updated 4 years ago
- a simple python script to de-obfuscate ABOBUS Batch script obfuscator☆10Jan 2, 2025Updated last year
- Parses USB connection artifacts from offline Registry hives☆110Feb 8, 2026Updated 6 months ago