🍏

Mac OS X Forensics

Mac OS X Forensics Cheat Sheets

🛠️
DFIR Tooling

🍎
Crescendo
osxevent viewer
🗃️
mac_apt - macOS Artifact Parsing Tool
osx artificat collection
🗃️
OSXCollector
osx artificat collection
🗃️
OS X Auditor
osx artificat collection
💾
Magnet ACQUIRE
disk image creationosxandroid
🍎
TaskExplorer (Objective-See)
osxartifact analysis
🍎
ReiKey (Objective-See)
osxartifact analysiskeylogger
🍎
Netiquette (Objective-See)
osxnetwork monitoring
🍎
KextViewr (Objective-See)
osxartifact analysis
🍎
Dylib Hijack Scanner (Objective-See)
osxartifact analysishijacking scanner
🍎
What's Your Sign? (Objective-See)
osxartifact analysiscrypto signature
🍎
ProcessMonitor (Objective-See)
osxmalware analysissystem monitoring
🍎
LuLu (Objective-See)
osxfirewallnetwork monitoring
🍎
KnockKnock (Objective-See)
osxartifact analysispersistence
⚙️
Skadi
all-in-onewindowslinuxosx
🔍
Limacharlie
all-in-onesaaswindowsosxlinuxandroidiosforensics
🔍
Zentral
artifact collectionartifact analysislinuxosxall-in-one
🔍
Redline (FireEye)
forensicsanalyticswindowslinuxosxartifact collection
🔍
Fleetdm
remoteforensicslinuxosx
🔍
Doorman
remoteforensicsosxlinux
🔍
Google Rapid Response (GRR)
forensicsremotewindowslinuxosxframeworkall-in-one
🔍
osquery
analyticssystem monitoringosxlinuxwindowsfreebsd
🗃️
AppCompatProcessor
logparsingosxlinux
📑
Fenrir
ioc scannerlinuxosx
🗃️
FastIR Artifacts
artifact collectionwindowslinuxosx
📑
rastrea2r
yaraartifact analysiswindowslinuxosx
🐧
UAC (Unix-like Artifacts Collector)
artifact collectionlinuxosxosx artificat collectionsolarisaixbsd