jjarava / mac-osx-forensics
Automatically exported from code.google.com/p/mac-osx-forensics
☆28Updated 9 years ago
Alternatives and similar repositories for mac-osx-forensics:
Users that are interested in mac-osx-forensics are comparing it to the libraries listed below
- ☆19Updated 5 years ago
- Forensic Artifact Collection Tool for macOS☆110Updated 7 months ago
- Automatically exported from code.google.com/p/pac4mac☆40Updated 6 years ago
- Slides and material from my conference presentations☆16Updated last year
- Scripts and tools created for appx analysis talk (Magnet summit 2019)☆16Updated last year
- machofile is a module to parse Mach-O binary files☆51Updated last year
- A parser for Unified logging tracev3 files☆85Updated last year
- macOS Artifact Intelligence Tool☆13Updated 5 years ago
- Binaries for the log2timeline projects and dependencies☆39Updated 7 months ago
- Module(s) related to reading SEGB (fka "Biome") data from iOS, mascOS, etc.☆20Updated 10 months ago
- ☆65Updated 2 months ago
- Windows link file (shortcuts) examiner☆68Updated 10 months ago
- A minimal malware analysis sandbox for macOS☆29Updated 2 years ago
- macOS XProtect definition files☆40Updated 3 years ago
- Different DFIR and CTI utilities☆36Updated 4 years ago
- A small tool to easily mount APFS image on macOS for forensics.☆15Updated 4 years ago
- AFF4 Standard Documents☆28Updated 3 years ago
- macOS forensic timeline generator using the analysis result DBs of mac_apt☆93Updated last year
- ☆31Updated 10 months ago
- A fork of The Sleuthkit with Pooled Storage and APFS support. See https://www.youtube.com/watch?v=k1XPillJ7aw for more info and usage.☆26Updated 5 years ago
- Script that checks for available updates for the most commonly used Digital Forensics tools☆59Updated 4 years ago
- A simple utility for stripping out either the SHA-1, MD5 or CRC values alone from the NSRL hash database☆14Updated 3 years ago
- WLEAPP is an open source project that aims to parse Windows OS artifacts for the purpose of triage analysis.☆30Updated last year
- Windows registry samples☆23Updated 6 years ago
- Queries for parsed spotlight database in sqlite☆12Updated 4 years ago
- The current repository contains all the scripts needed to complement kernel-mode mac-a-mal malicious activity hooking on macOS to Cuckoo …☆48Updated 6 years ago
- Scripts to extract compound bplists in the iOS -> KnowledgeC.db -> structuredmetadata table.☆24Updated 5 years ago
- A collection of Volatility Framework plugins.☆26Updated 11 years ago
- Tools for macOS Forensic Bootable media☆15Updated 4 years ago
- Carves and recreates VSS catalog and store from Windows disk image.☆98Updated 2 years ago