jjarava / mac-osx-forensics
Automatically exported from code.google.com/p/mac-osx-forensics
☆27Updated 8 years ago
Related projects ⓘ
Alternatives and complementary repositories for mac-osx-forensics
- Parses the WMI object database....looking for persistence☆31Updated 4 years ago
- Parse Manifest.mbdb files from iTunes backup directories☆19Updated 7 years ago
- Forensic Artifact Collection Tool for macOS☆98Updated last month
- A parser for Unified logging tracev3 files☆80Updated 9 months ago
- Binaries for the log2timeline projects and dependencies☆38Updated last month
- Community modules for FAME☆64Updated last week
- Comae Hibernation File Decompressor☆141Updated last year
- A rewrite of mactime, a bodyfile reader☆36Updated 3 months ago
- Yet another registry parser☆129Updated 2 years ago
- ☆33Updated 6 years ago
- Slides and material from my conference presentations☆14Updated 7 months ago
- Scripts for MacOS related tasks.☆17Updated 4 years ago
- macOS forensic timeline generator using the analysis result DBs of mac_apt☆89Updated last year
- A simple utility for stripping out either the SHA-1, MD5 or CRC values alone from the NSRL hash database☆14Updated 2 years ago
- Scripts and tools created for appx analysis talk (Magnet summit 2019)☆13Updated 8 months ago
- A small tool to easily mount APFS image on macOS for forensics.☆14Updated 4 years ago
- Different DFIR and CTI utilities☆36Updated 4 years ago
- Windows link file (shortcuts) examiner☆67Updated 5 months ago
- macOS .DS_Store Parser☆60Updated 3 years ago
- hopefully a source-to-source deobfuscator, aiming at deobfuscating common scripts languages such as Powershell, VBA and Javascript. Curre…☆40Updated 5 years ago
- ☆19Updated 5 years ago
- incident response tool for iOS devices☆49Updated 2 years ago
- Looks stuff up (MD5, SHA256, IP, Domains, URL's, strings e.g. mutexes)...☆36Updated 7 years ago
- Extract BITS jobs from QMGR queue and store them as CSV records☆74Updated 4 months ago
- macOS triage is a python script to collect various macOS logs, artifacts, and other data.☆26Updated 3 years ago
- Carves and recreates VSS catalog and store from Windows disk image.☆96Updated last year
- A sort of a toolkit to decrypt Dropbox Windows DBX files☆30Updated 7 years ago
- CIRCL system forensic tools or a jumble of tools to support forensic☆42Updated last year
- machofile is a module to parse Mach-O binary files☆48Updated 9 months ago