A powerful macOS triage collection tool designed for forensic analysis. It gathers critical system artifacts such as FSEvents, Spotlight, Unified Logs, user data and many more, while preserving the original macOS file system structure. Ideal for incident response, digital forensics, and security investigations.
☆49Oct 24, 2025Updated 10 months ago
Alternatives and similar repositories for Mac-Triage
Users that are interested in Mac-Triage are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- macos-collector - Automated Collection of macOS Forensic Artifacts for DFIR☆51Updated this week
- A collection of PowerShell scripts for analyzing macOS Forensic Artifacts☆34Mar 16, 2026Updated 5 months ago
- An AWS CloudTrail exported logs analyzer tool☆21Jul 26, 2026Updated last month
- Quick script to build host or investigation timelines using Carbon Black Response☆12Sep 25, 2018Updated 7 years ago
- macOS forensic acquisition made simple☆297Jun 2, 2026Updated 3 months ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- Forensic cheatsheets for use with cheat☆15Dec 2, 2021Updated 4 years ago
- Python web app for previewing data in a Chrome Profile Folder☆28Jul 1, 2024Updated 2 years ago
- A series of python scripts to extract information from Dark Web Applications☆14Mar 26, 2025Updated last year
- DFIR Timeline Analysis for macOS — SQLite-backed viewer for CSV, TSV, XLSX, EVTX, Plaso, $MFT, and $J files with AI Artifacts, AI Secret …☆353Aug 24, 2026Updated last week
- Automatic, fast parsing of browser artifacts☆17Jan 4, 2025Updated last year
- Suzaku (朱雀) is a sigma-based threat hunting and fast forensics timeline generator for cloud logs.☆221Updated this week
- USN Journal full path builder☆71Apr 16, 2026Updated 4 months ago
- ☆11Aug 3, 2018Updated 8 years ago
- macOS Artifacts☆33Mar 2, 2025Updated last year
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- Takajō (鷹匠) is a Hayabusa results analyzer.☆166Jul 11, 2026Updated last month
- Registry to JSON. This Project is for learning purposes and is not maintained.☆12Dec 28, 2021Updated 4 years ago
- Parser for Sdba memory pool tags☆21Jul 16, 2021Updated 5 years ago
- OneDriveExplorer is a command line and GUI based application for reconstructing the folder structure of OneDrive from the <UserCid>.dat a…☆236Aug 20, 2026Updated 2 weeks ago
- ☆24Updated this week
- This tool parses Windows EVTX logs to extract login and logout sessions from a security.evtx file. It uses a Tkinter GUI to let you selec…☆32Feb 22, 2025Updated last year
- A comprehensive PowerShell toolkit for RDP forensics analysis, tracking connection attempts, authentication, sessions, and logoffs across…☆18Aug 26, 2026Updated last week
- Bash tool used for proactive detection of malicious activity on macOS systems.☆39Sep 29, 2025Updated 11 months ago
- A forensic analysis framework for enumerating slack artifacts residing in the Operating system.☆18Sep 23, 2025Updated 11 months ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- Just Another broken Registry Parser (JARP)☆16May 23, 2024Updated 2 years ago
- Plugins for parsing CSV files in Timeline Explorer. This project allows for anyone to add more supported files (i,e. they get a Line #/ta…☆35Jun 5, 2026Updated 2 months ago
- mister-skinnylegs is an open plugin framework for parsing website/webapp artifacts in browser data. It currently provides a command line …☆21Jul 20, 2026Updated last month
- A Model Context Protocol (MCP) server that integrates Volatility 3 memory forensics framework with Claude☆39Jul 7, 2025Updated last year
- Contains compiled binaries of Volatility☆37May 18, 2025Updated last year
- A hex viewer for the sleuths!☆20Nov 7, 2025Updated 9 months ago
- DFIR notebooks GCIH Gold project, paper☆12Apr 30, 2015Updated 11 years ago
- Invoke-Forensics provides PowerShell commands to simplify working with the forensic tools KAPE and RegRipper.☆118Nov 28, 2023Updated 2 years ago
- A forensic open-source parser module for Autopsy that allows extracting the messages, comments, posts, contacts, calendar entries and rea…☆122Aug 4, 2026Updated last month
- Managed Kubernetes at scale on DigitalOcean • AdDigitalOcean Kubernetes includes the control plane, bandwidth allowance, container registry, automatic updates, and more for free.
- Quick ESXi Log Parser☆33Jul 21, 2026Updated last month
- Scripts to process macOS forensic artifacts☆213Aug 4, 2024Updated 2 years ago
- macOS (& ios) Artifact Parsing Tool☆1,080Aug 21, 2026Updated last week
- Digital forensic analysis tool that provides a user-friendly interface for investigating disk images.☆212Updated this week
- ☆18Jun 4, 2025Updated last year
- macOS .DS_Store Parser☆81Aug 17, 2021Updated 5 years ago
- a simple python script to de-obfuscate ABOBUS Batch script obfuscator☆10Jan 2, 2025Updated last year