a1l4m / Mac-TriageLinks
A powerful macOS triage collection tool designed for forensic analysis. It gathers critical system artifacts such as FSEvents, Spotlight, Unified Logs, user data and many more, while preserving the original macOS file system structure. Ideal for incident response, digital forensics, and security investigations.
☆30Updated last month
Alternatives and similar repositories for Mac-Triage
Users that are interested in Mac-Triage are comparing it to the libraries listed below
Sorting:
- Contains compiled binaries of Volatility☆37Updated 6 months ago
- Quick ESXi Log Parser☆28Updated last month
- A tool for fetching DFIR and other GitHub tools.☆24Updated 4 months ago
- ☆27Updated last month
- Python based tool to extract forensic info from EventTranscript.db (Windows Diagnostic Data)☆67Updated 2 years ago
- ☆22Updated 2 years ago
- Tools and scripts to deploy and manage OpenRelik instances☆14Updated 6 months ago
- Linux Baseline and Forensic Triage Tool - BETA☆57Updated 3 years ago
- macOS Artifacts☆33Updated 9 months ago
- Scripts to for ready-to-use Velociraptor instance deployment in Azure☆14Updated 2 years ago
- Thor Artifacts for Velociraptor☆18Updated last week
- PowerShell scripts for running Magnet RESPONSE forensic collection tool in large enterprises.☆29Updated 11 months ago
- Detection rule validation☆40Updated 2 years ago
- orc2timeline extracts and analyzes artifacts contained in archives generated with DFIR-ORC.exe to create a timeline from them☆34Updated 5 months ago
- A YARA & Malware Analysis Toolkit written in Rust.☆78Updated 2 months ago
- These FLARE-VM configuration files are designed to be help setup a purpose-built installation, remove unnecessary packages to help stream…☆15Updated last year
- Python script to walk a folder or a zip file for SQLite Databases☆37Updated 2 years ago
- ESXi Cyber Security Incident Response Script☆25Updated last year
- Parses USB connection artifacts from offline Registry hives☆105Updated 5 months ago
- Sigma detection rules for hunting with the threathunting-keywords project☆57Updated 9 months ago
- ☆21Updated last month
- ☆23Updated 9 months ago
- Search datasets for Bitlocker recovery files and triage live systems for Bitlocker keys.☆50Updated 10 months ago
- Helping Incident Responders hunt for potential persistence mechanisms on UNIX-based systems.☆17Updated 2 years ago
- Placeholder for my detection repo and misc detection engineering content☆42Updated 2 years ago
- ReWrite of AChoir in Go for Cross Platform forensic artifact collection and processing☆42Updated this week
- SubCrawl is a modular framework for discovering open directories, identifying unique content through signatures and organizing the data w…☆54Updated last year
- ☆68Updated 2 weeks ago
- A Windows Event Log MCP☆37Updated 3 months ago
- A repository containing the research output from my GCFE Gold Paper which compared Windows 10 and Windows 11.☆27Updated 3 years ago