Read and extract data from macOS spotlight databases
☆128Dec 7, 2025Updated 2 months ago
Alternatives and similar repositories for spotlight_parser
Users that are interested in spotlight_parser are comparing it to the libraries listed below
Sorting:
- A parser for Unified logging tracev3 files☆97Jul 25, 2025Updated 7 months ago
- Tools for macOS Forensic Bootable media☆15May 20, 2020Updated 5 years ago
- macOS (& ios) Artifact Parsing Tool☆1,003Updated this week
- macOS Artifact Intelligence Tool☆13Apr 30, 2019Updated 6 years ago
- Queries for parsed spotlight database in sqlite☆13Dec 29, 2020Updated 5 years ago
- Scripts to process macOS forensic artifacts☆205Aug 4, 2024Updated last year
- ☆11Aug 3, 2018Updated 7 years ago
- Module(s) related to reading SEGB (fka "Biome") data from iOS, mascOS, etc.☆28Sep 9, 2025Updated 5 months ago
- Different DFIR and CTI utilities☆39May 13, 2020Updated 5 years ago
- Python script to parse the Most Recently Used (MRU) plist files on macOS into a more human friendly format.☆108Feb 22, 2018Updated 8 years ago
- Scripts and tools created for appx analysis talk (Magnet summit 2019)☆19Feb 26, 2024Updated 2 years ago
- Automating forensic data extraction, reduction, and overall triage of cold disk and memory images.☆21Mar 12, 2019Updated 6 years ago
- Parser for OSX/iOS FSEvents Logs☆276Dec 4, 2024Updated last year
- A script to mine SQLite databases for hidden gems that might be overlooked☆58Sep 19, 2020Updated 5 years ago
- Windows 10 Live Information viewer☆38Jan 27, 2022Updated 4 years ago
- File recovery for APFS☆162Apr 20, 2022Updated 3 years ago
- Forensic Artifact Collection Tool for macOS☆118Jul 28, 2025Updated 7 months ago
- Python utilities related to plists☆55Oct 28, 2025Updated 4 months ago
- SQLite queries☆85Mar 8, 2023Updated 2 years ago
- macOS .DS_Store Parser☆76Aug 17, 2021Updated 4 years ago
- A utility to process the iOS Cache.sqlite database and create a timelined KML map for use in Google Earth☆30Dec 3, 2024Updated last year
- Google Filestream Forensic Tool☆22Mar 10, 2022Updated 3 years ago
- Parses USB connection artifacts from offline Registry hives☆107Feb 8, 2026Updated 3 weeks ago
- Parser fo macOS/iOS FSEvents Logs☆43May 6, 2024Updated last year
- A cross platform parser for Apple UnifiedLogs!☆330Feb 15, 2026Updated 2 weeks ago
- Help deobfuscate VBScript☆18Jul 1, 2022Updated 3 years ago
- PowerShell scripts to aid investigators when utilizing O365 and Magnet Axiom.☆12Aug 26, 2024Updated last year
- Repo with supporting material for the talk titled "Cracking the Beacon: Automating the extraction of implant configurations"☆11Feb 6, 2025Updated last year
- Apple Pattern of Life Lazy Output'er☆635Feb 25, 2024Updated 2 years ago
- Backstage Parser☆33Jun 23, 2022Updated 3 years ago
- Parse Manifest.mbdb files from iTunes backup directories☆20Jun 29, 2017Updated 8 years ago
- CLBX file format☆20May 13, 2021Updated 4 years ago
- Slides and material from my conference presentations☆16Mar 30, 2024Updated last year
- NTFS Security Descriptor Stream ($Secure:$SDS) parser☆14Jan 9, 2023Updated 3 years ago
- Synopsis is a tool to aid analysts reviewing browser history files by providing a high-level “synopsis” of key information.☆22Oct 31, 2018Updated 7 years ago
- APFS filesystem format for Kaitai Struct☆81Apr 20, 2022Updated 3 years ago
- Scripts to extract compound bplists in the iOS -> KnowledgeC.db -> structuredmetadata table.☆27May 12, 2019Updated 6 years ago
- ☆24Mar 12, 2025Updated 11 months ago
- USN to JSON☆22Apr 4, 2020Updated 5 years ago