ainfosec / MacResponse-Forensics
☆33Updated 12 years ago
Related projects ⓘ
Alternatives and complementary repositories for MacResponse-Forensics
- OSX Events Monitor☆21Updated 6 years ago
- Volatility plugin to extract FileVault 2 VMK's☆49Updated 3 years ago
- Resources for HFS+ Forensics☆35Updated 9 years ago
- Recover event log entries from an image by heurisitically looking for record structures.☆27Updated 9 years ago
- A small utility to read and write to Macs physical memory using default AppleHWAccess.kext.☆25Updated 9 years ago
- Convert Windows Netmon Monitor Mode Wireless Packet Captures to Libpcap Format☆15Updated 5 years ago
- iOS forensics utility☆12Updated 6 years ago
- a collection of yara rules for binary analysis☆24Updated 7 years ago
- A collection of Volatility Framework plugins.☆26Updated 11 years ago
- Dump the iOS Frequent Location binary plist files☆82Updated 6 years ago
- A USB armory based USB sandbox☆20Updated 7 years ago
- New and Improved☆16Updated 8 years ago
- Yara syntax highlighting☆25Updated 3 years ago
- OSX Security Compliance & Hardening☆49Updated 9 years ago
- macOS XProtect definition files☆38Updated 2 years ago
- ☆41Updated 7 years ago
- ☆32Updated 5 months ago
- Automatically exported from code.google.com/p/pac4mac☆40Updated 5 years ago
- Digital Forensics Windows Registry (dfWinReg)☆49Updated last month
- vstruct based dissectors for various file/protocol formats☆15Updated 7 years ago
- A Volatility plugin for finding sqlite database rows☆22Updated 5 years ago
- r2yara - Module for Yara using radare2 information☆34Updated last year
- NDISPktScan is a plugin for the Volatility Framework. It parses the Ethernet packets stored by ndis.sys in Windows kernel space memory.☆11Updated 9 years ago
- ☆60Updated 4 years ago
- tracy - a system call tracer and injector. Find us in #tracy on irc.freenode.net☆32Updated 8 months ago
- A python script that can be used to scan data within in an IDB using Yara.☆22Updated 6 years ago
- The current repository contains all the scripts needed to build kernel-mode mac-a-mal malicious activity hooking on macOS.☆82Updated 6 years ago
- Automatically exported from code.google.com/p/mac-osx-forensics☆27Updated 8 years ago
- Parse Manifest.mbdb files from iTunes backup directories☆19Updated 7 years ago