Mac OS X Forensics Cheat Sheets
Crescendo
osxevent viewer
mac_apt - macOS Artifact Parsing Tool
osx artificat collection
OSXCollector
osx artificat collection
OS X Auditor
osx artificat collection
Magnet ACQUIRE
disk image creationosxandroid
TaskExplorer (Objective-See)
osxartifact analysis
ReiKey (Objective-See)
osxartifact analysiskeylogger
Netiquette (Objective-See)
osxnetwork monitoring
KextViewr (Objective-See)
osxartifact analysis
Dylib Hijack Scanner (Objective-See)
osxartifact analysishijacking scanner
What's Your Sign? (Objective-See)
osxartifact analysiscrypto signature
ProcessMonitor (Objective-See)
osxmalware analysissystem monitoring
LuLu (Objective-See)
osxfirewallnetwork monitoring
KnockKnock (Objective-See)
osxartifact analysispersistence
Skadi
all-in-onewindowslinuxosx
Limacharlie
all-in-onesaaswindowsosxlinuxandroidiosforensics
Zentral
artifact collectionartifact analysislinuxosxall-in-one
Redline (FireEye)
forensicsanalyticswindowslinuxosxartifact collection
Fleetdm
remoteforensicslinuxosx
Doorman
remoteforensicsosxlinux
Google Rapid Response (GRR)
forensicsremotewindowslinuxosxframeworkall-in-one
osquery
analyticssystem monitoringosxlinuxwindowsfreebsd
AppCompatProcessor
logparsingosxlinux
Fenrir
ioc scannerlinuxosx
FastIR Artifacts
artifact collectionwindowslinuxosx
rastrea2r
yaraartifact analysiswindowslinuxosx
UAC (Unix-like Artifacts Collector)
artifact collectionlinuxosxosx artificat collectionsolarisaixbsd