a1l4m / Mac-TriageLinks
A powerful macOS triage collection tool designed for forensic analysis. It gathers critical system artifacts such as FSEvents, Spotlight, Unified Logs, user data and many more, while preserving the original macOS file system structure. Ideal for incident response, digital forensics, and security investigations.
☆25Updated 6 months ago
Alternatives and similar repositories for Mac-Triage
Users that are interested in Mac-Triage are comparing it to the libraries listed below
Sorting:
- Contains compiled binaries of Volatility☆35Updated 3 months ago
- A tool for fetching DFIR and other GitHub tools.☆24Updated last month
- Quick ESXi Log Parser☆25Updated last week
- Tools and scripts to deploy and manage OpenRelik instances☆15Updated 3 months ago
- Scripts to for ready-to-use Velociraptor instance deployment in Azure☆14Updated 2 years ago
- Python based tool to extract forensic info from EventTranscript.db (Windows Diagnostic Data)☆69Updated 2 years ago
- PowerShell scripts for running Magnet RESPONSE forensic collection tool in large enterprises.☆28Updated 8 months ago
- Thor Artifacts for Velociraptor☆18Updated last year
- ☆24Updated 7 months ago
- ESXi Cyber Security Incident Response Script☆25Updated last year
- Penguin OS Forensic (or Flight) Recorder☆40Updated 8 months ago
- ☆22Updated 2 years ago
- ☆21Updated 6 months ago
- A Windows Event Log MCP☆36Updated 3 weeks ago
- macOS Artifacts☆31Updated 6 months ago
- Sigma detection rules for hunting with the threathunting-keywords project☆56Updated 6 months ago
- Python script to walk a folder or a zip file for SQLite Databases☆37Updated last year
- Get-MiniTimeline - Triage Collection and Timeline Generation w/ KAPE☆33Updated last year
- Helping Incident Responders hunt for potential persistence mechanisms on UNIX-based systems.☆16Updated last year
- A repository containing the research output from my GCFE Gold Paper which compared Windows 10 and Windows 11.☆27Updated 3 years ago
- Various commands, tools, techniques that you can use to examine live Windows systems for signs of Compromise or for Threat Hunting.Can al…☆12Updated 3 years ago
- A preconfigured Windows-based system designed for rapid forensic investigations in both Azure and AWS.☆39Updated last year
- A YARA & Malware Analysis Toolkit written in Rust.☆48Updated last month
- Capture. Detonate. Collect☆14Updated 11 months ago
- Linux Baseline and Forensic Triage Tool - BETA☆57Updated 3 years ago
- ReWrite of AChoir in Go for Cross Platform☆41Updated 2 weeks ago
- ShellSweeping the evil.☆53Updated last year
- Rapid7 Labs operates as the division of Rapid7 focused on threat research. It is renowned for providing comprehensive threat intelligence…☆71Updated 3 months ago
- Just Another broken Registry Parser (JARP)☆16Updated last year
- orc2timeline extracts and analyzes artifacts contained in archives generated with DFIR-ORC.exe to create a timeline from them☆34Updated 2 months ago