jjarava / mac-osx-forensicsLinks
Automatically exported from code.google.com/p/mac-osx-forensics
☆28Updated 10 years ago
Alternatives and similar repositories for mac-osx-forensics
Users that are interested in mac-osx-forensics are comparing it to the libraries listed below
Sorting:
- A parser for Unified logging tracev3 files☆96Updated 5 months ago
- Slides and material from my conference presentations☆16Updated last year
- Forensic Artifact Collection Tool for macOS☆118Updated 5 months ago
- Parse Manifest.mbdb files from iTunes backup directories☆20Updated 8 years ago
- Python library for parsing AccessData AD1 images☆33Updated 2 years ago
- Script that checks for available updates for the most commonly used Digital Forensics tools☆60Updated 5 years ago
- Scripts and tools created for appx analysis talk (Magnet summit 2019)☆19Updated last year
- Comae Hibernation File Decompressor☆155Updated 2 years ago
- A small tool to easily mount APFS image on macOS for forensics.☆16Updated 5 years ago
- A DFIR tool to collect artifacts on macOS☆56Updated 5 years ago
- ☆20Updated 6 years ago
- AFF4 Standard Documents☆29Updated 3 years ago
- Yet another registry parser☆138Updated 3 years ago
- Parses the WMI object database....looking for persistence☆34Updated 6 years ago
- A sort of a toolkit to decrypt Dropbox Windows DBX files☆31Updated 8 years ago
- Carves and recreates VSS catalog and store from Windows disk image.☆99Updated 2 years ago
- incident response tool for iOS devices☆49Updated 3 years ago
- macOS .DS_Store Parser☆74Updated 4 years ago
- Command line utility and Python package to ease the (un)mounting of forensic disk images☆124Updated 2 years ago
- NTFS parser, plus linking capabilites between MFT LogFile and UsnJrnl☆39Updated 9 years ago
- Different DFIR and CTI utilities☆37Updated 5 years ago
- macOS Artifact Intelligence Tool☆13Updated 6 years ago
- Windows link file (shortcuts) examiner☆68Updated last year
- macOS forensic timeline generator using the analysis result DBs of mac_apt☆92Updated 2 years ago
- machofile is a module to parse Mach-O binary files☆90Updated 5 months ago
- An AFF4 C++ implementation.☆211Updated 2 years ago
- unXOR will search a XORed file and try to guess the key using known-plaintext attacks.☆145Updated 5 years ago
- Parse Windows Prefetch files: Supports XP - Windows 10 Prefetch files☆121Updated last year
- Scripts to extract compound bplists in the iOS -> KnowledgeC.db -> structuredmetadata table.☆27Updated 6 years ago
- ☆35Updated 7 years ago