A cross platform parser for Apple UnifiedLogs!
☆330Feb 15, 2026Updated 2 weeks ago
Alternatives and similar repositories for macos-UnifiedLogs
Users that are interested in macos-UnifiedLogs are comparing it to the libraries listed below
Sorting:
- A parser for Unified logging tracev3 files☆97Jul 25, 2025Updated 7 months ago
- macOS (& ios) Artifact Parsing Tool☆1,003Updated this week
- Module(s) related to reading SEGB (fka "Biome") data from iOS, mascOS, etc.☆28Sep 9, 2025Updated 5 months ago
- Forensic Artifact Collection Tool for macOS☆118Jul 28, 2025Updated 7 months ago
- Aftermath is a free macOS IR framework☆569Sep 25, 2025Updated 5 months ago
- macOS forensic timeline generator using the analysis result DBs of mac_apt☆93Sep 7, 2023Updated 2 years ago
- A command line tool for pstree-like output on macOS with additional pid capturing capabilities☆276Aug 23, 2024Updated last year
- Run Sigma detection rules on logs from the new MacOS EndpointSecurity Framework☆22Jan 22, 2021Updated 5 years ago
- Parses USB connection artifacts from offline Registry hives☆107Feb 8, 2026Updated 3 weeks ago
- Stand-alone parser for User Access Logging from Server 2012 and newer systems☆78Jan 9, 2024Updated 2 years ago
- Forensic toolkit for iOS sysdiagnose feature☆248Updated this week
- Suzaku (朱雀) is a sigma-based threat hunting and fast forensics timeline generator for cloud logs.☆168Dec 7, 2025Updated 2 months ago
- One-Click to Completely Take Over A macOS Device☆18Aug 25, 2022Updated 3 years ago
- ESF modular ingestion tool for development and research.☆38Dec 21, 2021Updated 4 years ago
- macOS .DS_Store Parser☆76Aug 17, 2021Updated 4 years ago
- Mapping XProtect's obfuscated malware family names to common industry names.☆94Nov 14, 2025Updated 3 months ago
- JPCERT/CC public YARA rules repository☆109Nov 14, 2025Updated 3 months ago
- Forensic cheatsheets for use with cheat☆15Dec 2, 2021Updated 4 years ago
- Scripts to process macOS forensic artifacts☆205Aug 4, 2024Updated last year
- Search Index Database Reporter☆131Oct 28, 2025Updated 4 months ago
- Parser for OSX/iOS FSEvents Logs☆276Dec 4, 2024Updated last year
- A python script developed to process Windows memory images based on triage type.☆266Nov 25, 2023Updated 2 years ago
- Returns Logs Events And Properties Parser☆124Dec 24, 2025Updated 2 months ago
- A parser of Windows Defender's DetectionHistory forensic artifact, containing substantial info about quarantined files and executables.☆117Jan 26, 2022Updated 4 years ago
- iOS Logs, Events, And Plist Parser☆1,025Updated this week
- Parser fo macOS/iOS FSEvents Logs☆43May 6, 2024Updated last year
- ☆24Mar 12, 2025Updated 11 months ago
- Slides and material from my conference presentations☆16Mar 30, 2024Updated last year
- macOS Endpoint Security Message Analysis Tool☆47Jan 31, 2022Updated 4 years ago
- USN Journal full path builder☆65Sep 16, 2024Updated last year
- Living Off the Orchard: macOS Binaries (LOOBins) is designed to provide detailed information on various built-in "living off the land" ma…☆520Updated this week
- Read and extract data from macOS spotlight databases☆128Dec 7, 2025Updated 2 months ago
- Windows 10 (v1803+) ActivitiesCache.db parsers (SQLite, PowerShell, .EXE)☆196Feb 16, 2023Updated 3 years ago
- Windows Event Log "Microsoft-Windows-Partition%4Diagnostic.evtx" parser and devices' VSNs extractor.☆20Nov 28, 2023Updated 2 years ago
- Accompanying code for blog post "Mapping iOS Persistence Attack Surface using Corellium"☆11Jun 10, 2025Updated 8 months ago
- A JXA script for enumerating running processes, printed out in a json, parent-child tree.☆14Jan 28, 2022Updated 4 years ago
- Memory Baseliner is a script that can compare two windows memory images or perform frequency of occurrence / data stacking analysis on mu…☆56Jul 2, 2023Updated 2 years ago
- Documentation and scripts to properly enable Windows event logs.☆672Oct 3, 2025Updated 4 months ago
- WELA (Windows Event Log Analyzer): The Swiss Army knife for Windows Event Logs! ゑ羅(ウェラ)☆779Feb 3, 2023Updated 3 years ago