A powerful macOS triage collection tool designed for forensic analysis. It gathers critical system artifacts such as FSEvents, Spotlight, Unified Logs, user data and many more, while preserving the original macOS file system structure. Ideal for incident response, digital forensics, and security investigations.
☆46Oct 24, 2025Updated 9 months ago
Alternatives and similar repositories for Mac-Triage
Users that are interested in Mac-Triage are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- macos-collector - Automated Collection of macOS Forensic Artifacts for DFIR☆49Updated this week
- A collection of PowerShell scripts for analyzing macOS Forensic Artifacts☆33Mar 16, 2026Updated 4 months ago
- An AWS CloudTrail exported logs analyzer tool☆20Jul 12, 2026Updated 2 weeks ago
- Quick script to build host or investigation timelines using Carbon Black Response☆12Sep 25, 2018Updated 7 years ago
- macOS forensic acquisition made simple☆288Jun 2, 2026Updated last month
- Open source password manager - Proton Pass • AdSecurely store, share, and autofill your credentials with Proton Pass, the end-to-end encrypted password manager trusted by millions.
- Forensic cheatsheets for use with cheat☆15Dec 2, 2021Updated 4 years ago
- Python web app for previewing data in a Chrome Profile Folder☆26Jul 1, 2024Updated 2 years ago
- A series of python scripts to extract information from Dark Web Applications☆14Mar 26, 2025Updated last year
- DFIR Timeline Analysis for macOS — SQLite-backed viewer for CSV, TSV, XLSX, EVTX, Plaso, $MFT, and $J files with AI Artifacts, AI Secret …☆296Jun 6, 2026Updated last month
- Automatic, fast parsing of browser artifacts☆17Jan 4, 2025Updated last year
- Suzaku (朱雀) is a sigma-based threat hunting and fast forensics timeline generator for cloud logs.☆182Updated this week
- USN Journal full path builder☆69Apr 16, 2026Updated 3 months ago
- ☆11Aug 3, 2018Updated 7 years ago
- macOS Artifacts☆33Mar 2, 2025Updated last year
- GPUs on demand by Runpod - Special Offer Available • AdRun AI, ML, and HPC workloads on powerful cloud GPUs—without limits or wasted spend. Deploy GPUs in under a minute and pay by the second.
- Takajō (鷹匠) is a Hayabusa results analyzer.☆162Jul 11, 2026Updated 2 weeks ago
- Registry to JSON. This Project is for learning purposes and is not maintained.☆12Dec 28, 2021Updated 4 years ago
- Parser for Sdba memory pool tags☆21Jul 16, 2021Updated 5 years ago
- OneDriveExplorer is a command line and GUI based application for reconstructing the folder structure of OneDrive from the <UserCid>.dat a…☆235Jun 29, 2026Updated 3 weeks ago
- ☆24Jul 13, 2026Updated last week
- This tool parses Windows EVTX logs to extract login and logout sessions from a security.evtx file. It uses a Tkinter GUI to let you selec…☆32Feb 22, 2025Updated last year
- A comprehensive PowerShell toolkit for RDP forensics analysis, tracking connection attempts, authentication, sessions, and logoffs across…☆18May 27, 2026Updated last month
- A forensic analysis framework for enumerating slack artifacts residing in the Operating system.☆18Sep 23, 2025Updated 10 months ago
- Just Another broken Registry Parser (JARP)☆16May 23, 2024Updated 2 years ago
- Proton VPN Special Offer - Get 70% off • AdSpecial partner offer. Trusted by over 100 million users worldwide. Tested, Approved and Recommended by Experts.
- Plugins for parsing CSV files in Timeline Explorer. This project allows for anyone to add more supported files (i,e. they get a Line #/ta…☆34Jun 5, 2026Updated last month
- mister-skinnylegs is an open plugin framework for parsing website/webapp artifacts in browser data. It currently provides a command line …☆20Updated this week
- A Model Context Protocol (MCP) server that integrates Volatility 3 memory forensics framework with Claude☆39Jul 7, 2025Updated last year
- Contains compiled binaries of Volatility☆37May 18, 2025Updated last year
- A hex viewer for the sleuths!☆20Nov 7, 2025Updated 8 months ago
- DFIR notebooks GCIH Gold project, paper☆12Apr 30, 2015Updated 11 years ago
- Invoke-Forensics provides PowerShell commands to simplify working with the forensic tools KAPE and RegRipper.☆118Nov 28, 2023Updated 2 years ago
- A forensic open-source parser module for Autopsy that allows extracting the messages, comments, posts, contacts, calendar entries and rea…☆122Updated this week
- Quick ESXi Log Parser☆33Updated this week
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- Scripts to process macOS forensic artifacts☆213Aug 4, 2024Updated last year
- macOS (& ios) Artifact Parsing Tool☆1,066Updated this week
- Digital forensic analysis tool that provides a user-friendly interface for investigating disk images.☆211Nov 12, 2025Updated 8 months ago
- ☆18Jun 4, 2025Updated last year
- macOS .DS_Store Parser☆81Aug 17, 2021Updated 4 years ago
- a simple python script to de-obfuscate ABOBUS Batch script obfuscator☆10Jan 2, 2025Updated last year
- Parses USB connection artifacts from offline Registry hives☆109Feb 8, 2026Updated 5 months ago