Awesome Cybersecurity Blue Team
Section: Evidence collection · Forensic evidence collection & analysis toolkit for macOS.
Entry
Appears in 6 awesome lists
Forensic evidence collection & analysis toolkit for macOS.
Section: Evidence collection · Forensic evidence collection & analysis toolkit for macOS.
Section: 事件证据搜集(取证) · 适用于macOS的证据收集和分析工具包
Section: OSX Evidence Collection · OSX Auditor offshoot for live response.
Section: Security · Forensic evidence collection & analysis toolkit.
Section: OS X Forensics
Section: macOS Security · Forensic analysis.
A tool to uncover persistently installed software in order to generically reveal such malware. See GitHub repository too for the source code.
Free Mac OS X computer forensics tool.
Plugin based forensics framework for quick mac triage that works on live machines, disk images or individual artifact files.
ir-rescue is a Windows Batch script and a Unix Bash script to comprehensively collect host forensic data during incident response.
Command line utility (that works with or without Amazon EC2 instances) to parallelize remote memory acquisition.
A tool to view the events in Apple Endpoint Security Framework (ESF) in real time.
Modular, automated forensic triage collection framework designed to access various forensic artifacts on macOS, parse them, and present them in formats viable for analysis.
Assists incident response teams by exporting cloud artifacts from Azure/AzureAD/M365 environments in order to run a full investigation despite lacking in logs ingested by a SIEM.