A powerful macOS triage collection tool designed for forensic analysis. It gathers critical system artifacts such as FSEvents, Spotlight, Unified Logs, user data and many more, while preserving the original macOS file system structure. Ideal for incident response, digital forensics, and security investigations.
☆49Oct 24, 2025Updated 11 months ago
Alternatives and similar repositories for Mac-Triage
Users that are interested in Mac-Triage are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- macos-collector - Automated Collection of macOS Forensic Artifacts for DFIR☆51Sep 13, 2026Updated last week
- A collection of PowerShell scripts for analyzing macOS Forensic Artifacts☆35Mar 16, 2026Updated 6 months ago
- Quick script to build host or investigation timelines using Carbon Black Response☆12Sep 25, 2018Updated 7 years ago
- macOS forensic acquisition made simple☆301Jun 2, 2026Updated 3 months ago
- An AWS CloudTrail exported logs analyzer tool☆21Jul 26, 2026Updated last month
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Forensic cheatsheets for use with cheat☆15Dec 2, 2021Updated 4 years ago
- Python web app for previewing data in a Chrome Profile Folder☆28Jul 1, 2024Updated 2 years ago
- A series of python scripts to extract information from Dark Web Applications☆14Mar 26, 2025Updated last year
- Automatic, fast parsing of browser artifacts☆17Jan 4, 2025Updated last year
- DFIR Timeline Analysis for macOS — SQLite-backed viewer for CSV, TSV, XLSX, EVTX, Plaso, $MFT, and $J files with AI Artifacts, AI Secret …☆369Sep 8, 2026Updated 2 weeks ago
- USN Journal full path builder☆71Apr 16, 2026Updated 5 months ago
- Suzaku (朱雀) is a sigma-based threat hunting and fast forensics timeline generator for cloud logs.☆223Updated this week
- ☆12Aug 3, 2018Updated 8 years ago
- macOS Artifacts☆33Mar 2, 2025Updated last year
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- Takajō (鷹匠) is a Hayabusa results analyzer.☆166Jul 11, 2026Updated 2 months ago
- Registry to JSON. This Project is for learning purposes and is not maintained.☆12Dec 28, 2021Updated 4 years ago
- Parser for Sdba memory pool tags☆20Jul 16, 2021Updated 5 years ago
- OneDriveExplorer is a command line and GUI based application for reconstructing the folder structure of OneDrive from the <UserCid>.dat a…☆245Sep 15, 2026Updated last week
- ☆24Sep 7, 2026Updated 2 weeks ago
- This tool parses Windows EVTX logs to extract login and logout sessions from a security.evtx file. It uses a Tkinter GUI to let you selec…☆32Feb 22, 2025Updated last year
- Bash tool used for proactive detection of malicious activity on macOS systems.☆39Sep 29, 2025Updated 11 months ago
- A forensic analysis framework for enumerating slack artifacts residing in the Operating system.☆18Sep 23, 2025Updated last year
- Just Another broken Registry Parser (JARP)☆16May 23, 2024Updated 2 years ago
- End-to-end encrypted email - Proton Mail • AdSpecial offer: 40% Off Yearly / 80% Off First Month. All Proton services are open source and independently audited for security.
- Plugins for parsing CSV files in Timeline Explorer. This project allows for anyone to add more supported files (i,e. they get a Line #/ta…☆37Jun 5, 2026Updated 3 months ago
- mister-skinnylegs is an open plugin framework for parsing website/webapp artifacts in browser data. It currently provides a command line …☆22Jul 20, 2026Updated 2 months ago
- Contains compiled binaries of Volatility☆37May 18, 2025Updated last year
- A hex viewer for the sleuths!☆20Nov 7, 2025Updated 10 months ago
- DFIR notebooks GCIH Gold project, paper☆12Apr 30, 2015Updated 11 years ago
- Invoke-Forensics provides PowerShell commands to simplify working with the forensic tools KAPE and RegRipper.☆118Nov 28, 2023Updated 2 years ago
- A forensic open-source parser module for Autopsy that allows extracting the messages, comments, posts, contacts, calendar entries and rea…☆123Aug 4, 2026Updated last month
- Quick ESXi Log Parser☆33Jul 21, 2026Updated 2 months ago
- macOS Security Resources☆38Aug 15, 2025Updated last year
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- Scripts to process macOS forensic artifacts☆213Aug 4, 2024Updated 2 years ago
- macOS (& ios) Artifact Parsing Tool☆1,086Aug 21, 2026Updated last month
- Digital forensic analysis tool that provides a user-friendly interface for investigating disk images.☆214Sep 1, 2026Updated 3 weeks ago
- ☆18Jun 4, 2025Updated last year
- macOS .DS_Store Parser☆81Aug 17, 2021Updated 5 years ago
- a simple python script to de-obfuscate ABOBUS Batch script obfuscator☆10Jan 2, 2025Updated last year
- Parses USB connection artifacts from offline Registry hives☆110Feb 8, 2026Updated 7 months ago