a1l4m / Mac-TriageLinks
A powerful macOS triage collection tool designed for forensic analysis. It gathers critical system artifacts such as FSEvents, Spotlight, Unified Logs, user data and many more, while preserving the original macOS file system structure. Ideal for incident response, digital forensics, and security investigations.
☆20Updated 4 months ago
Alternatives and similar repositories for Mac-Triage
Users that are interested in Mac-Triage are comparing it to the libraries listed below
Sorting:
- Quick ESXi Log Parser☆22Updated 6 months ago
- Scripts to for ready-to-use Velociraptor instance deployment in Azure☆14Updated 2 years ago
- Contains compiled binaries of Volatility☆34Updated last month
- Tools and scripts to deploy and manage OpenRelik instances☆14Updated last month
- ☆21Updated 4 months ago
- orc2timeline extracts and analyzes artifacts contained in archives generated with DFIR-ORC.exe to create a timeline from them☆33Updated 2 weeks ago
- Placeholder for my detection repo and misc detection engineering content☆42Updated last year
- macOS Artifacts☆31Updated 4 months ago
- Detection rule validation☆41Updated last year
- ESXi Cyber Security Incident Response Script☆24Updated 10 months ago
- Python based tool to extract forensic info from EventTranscript.db (Windows Diagnostic Data)☆69Updated last year
- ☆22Updated 2 years ago
- A tool for fetching DFIR and other GitHub tools.☆24Updated last month
- These FLARE-VM configuration files are designed to be help setup a purpose-built installation, remove unnecessary packages to help stream…☆14Updated last year
- ☆11Updated 2 years ago
- Hundred Days of Yara Challenge☆12Updated 3 years ago
- A proof-of-concept re-assembler for reverse VNC traffic.☆25Updated 2 years ago
- SubCrawl is a modular framework for discovering open directories, identifying unique content through signatures and organizing the data w…☆52Updated 7 months ago
- ShellSweeping the evil.☆53Updated last year
- my MSTICpy practice and custom tools repository☆11Updated 2 months ago
- A project that aims to automate Volatility3 at scale with the use of cloud strength and the power of KQL inside ADX.☆16Updated 7 months ago
- Assist analyst and threat hunters to understand Windows authentication logs and to analyze brutforce scenarios.☆18Updated 2 years ago
- Just Another broken Registry Parser (JARP)☆16Updated last year
- A YARA & Malware Analysis Toolkit written in Rust.☆36Updated last week
- ☆14Updated last year
- Security Content for the PEAK Threat Hunting Framework☆30Updated last year
- A repository containing the research output from my GCFE Gold Paper which compared Windows 10 and Windows 11.☆27Updated 2 years ago
- An experimental Velociraptor implementation using cloud infrastructure☆25Updated 2 weeks ago
- ☆24Updated 11 months ago
- Repo with supporting material for the talk titled "Cracking the Beacon: Automating the extraction of implant configurations"☆11Updated 5 months ago