Skip to content

Commit

Permalink
Add further macOS artifact collection tool
Browse files Browse the repository at this point in the history
  • Loading branch information
Karneades authored Oct 1, 2021
1 parent e36a539 commit 43e2024
Showing 1 changed file with 1 addition and 0 deletions.
1 change: 1 addition & 0 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -75,6 +75,7 @@ Tools for artifact collection
* [mac_apt - macOS (and iOS) Artifact Parsing Tool](https://github.com/ydkhatri/mac_apt) - mac_apt is a DFIR (Digital Forensics and Incident Response) tool to process Mac computer full disk images (or live machines) and extract data/metadata useful for forensic investigation. It is a python based framework, which has plugins to process individual artifacts (such as Safari internet history, Network interfaces, Recently accessed files & volumes, ..).
* [macOS Artifact Collector (macosac)](https://github.com/mnrkbys/macosac) - This is a DFIR tool for collecting artifact files on macOS. The "Extended Attributes" of artifact files are collected too. Furthermore, this tool can collect artifacts in Time Machine backups as well as ones on the current disk. This tool does not provide features for analyzing artifacts, so you can analyze them with your favorite artifact analyzing tools.
* [AutoMacTC: Automated Mac Forensic Triage Collector](https://github.com/CrowdStrike/automactc) - This is a modular forensic triage collection framework designed to access various forensic artifacts on macOS, parse them, and present them in formats viable for analysis. The output may provide valuable insights for incident response in a macOS environment. Automactc can be run against a live system or dead disk (as a mounted volume.)
* [macOS Triage Tool](https://github.com/Recruit-CSIRT/macOSTriageTool) - A DFIR tool to collect artifacts on macOS.
* [OSXCollector](https://github.com/Yelp/osxcollector) - [ARCHIVED] OSXCollector is a forensic evidence collection & analysis toolkit for OSX.
* [OSXAuditor](https://github.com/jipegit/OSXAuditor) - [NO LONGER MAINTAINED] OS X Auditor is a free Mac OS X computer forensics tool. OS X Auditor parses and hashes the various artifacts on the running system or a copy of a system you want to analyze. Forked by Yelp into osxcollector.

Expand Down

0 comments on commit 43e2024

Please sign in to comment.