mandiant / macos-UnifiedLogs
☆232Updated 3 weeks ago
Alternatives and similar repositories for macos-UnifiedLogs:
Users that are interested in macos-UnifiedLogs are comparing it to the libraries listed below
- Mapping XProtect's obfuscated malware family names to common industry names.☆84Updated 9 months ago
- Forensic Artifact Collection Tool for macOS☆105Updated 5 months ago
- A parser for Unified logging tracev3 files☆84Updated last year
- A command line tool for pstree-like output on macOS with additional pid capturing capabilities☆250Updated 5 months ago
- A ruleset to find potentially malicious code in macOS malware samples☆39Updated last year
- Phorion Kronos is a macOS security tool designed to enhance Apple's Transparency Consent and Control (TCC) security and privacy mechanism…☆72Updated last year
- Scripts (python3 and Swift) for macOS to recursively check /Applications and also check /usr/local/bin, /usr/bin, and /usr/sbin for binar…☆95Updated 2 years ago
- Aftermath is a free macOS IR framework☆493Updated 2 months ago
- macOS forensic timeline generator using the analysis result DBs of mac_apt☆91Updated last year
- A library to parse macOS FsEvents☆19Updated 2 years ago
- And open-source version of % sfltool dumpbtm☆119Updated last year
- Living Off the Orchard: macOS Binaries (LOOBins) is designed to provide detailed information on various built-in "living off the land" ma…☆453Updated 2 months ago
- Swift Command line tool used for proactive detection of malicious activity on macOS systems.☆68Updated 4 years ago
- Forensic toolkit for iOS sysdiagnose feature☆175Updated this week
- Scripts to parse various iOS sysdiagnose logs. Based upon the forensic research of Mattia Epifani, Heather Mahalik and Cheeky4n6monkey.☆182Updated 2 years ago
- macOS .DS_Store Parser☆66Updated 3 years ago
- machofile is a module to parse Mach-O binary files☆48Updated last year
- Parser fo macOS/iOS FSEvents Logs☆29Updated 9 months ago
- Post-Infection Collection Toolkit☆94Updated 2 years ago
- Programmatic Electron fuse detection☆19Updated 7 months ago
- Scripts to process macOS forensic artifacts☆187Updated 6 months ago
- Python utilities related to plists☆54Updated last year
- Parser for OSX/iOS FSEvents Logs☆243Updated 2 months ago
- macOS Security Research☆114Updated 11 months ago
- Run Sigma detection rules on logs from the new MacOS EndpointSecurity Framework☆20Updated 4 years ago
- https://wojciechregula.blog/post/macos-red-teaming-get-ad-credentials-from-nomad/☆39Updated 2 years ago
- Collection of macOS persistence methods and miscellaneous tools in JXA☆268Updated last year
- A DNS Monitor, leveraging Apple's NEDNSProxyProvider/Network Extension Framework☆180Updated 6 months ago
- DFIQ is a collection of investigative questions and the approaches for answering them☆271Updated last month
- Collection of forensics artifacts location for Mac OS X and iOS☆328Updated 3 years ago