Skip to content

Entry

OSXCollector

Appears in 6 awesome lists

Forensic evidence collection & analysis toolkit for macOS.

Open github.comyelp/osxcollector

Found in these lists

Awesome Cybersecurity Blue Team

Section: Evidence collection · Forensic evidence collection & analysis toolkit for macOS.

StaleScore 53

Awesome Cybersecurity Blue Team - CN

Section: 事件证据搜集(取证) · 适用于macOS的证据收集和分析工具包

StaleScore 47

Awesome Incident Response

Section: OSX Evidence Collection · OSX Auditor offshoot for live response.

ActiveScore 82

Awesome MacOS

Section: Security · Forensic evidence collection & analysis toolkit.

FreshScore 85

Forensics Tools

Section: OS X Forensics

ActiveScore 77

macOS and iOS Security Related Tools

Section: macOS Security · Forensic analysis.

FreshScore 85

KnockKnock

A tool to uncover persistently installed software in order to generically reveal such malware. See GitHub repository too for the source code.

In 4 listsDetails

OSXAuditor

Free Mac OS X computer forensics tool.

In 5 listsDetails

mac_apt

Plugin based forensics framework for quick mac triage that works on live machines, disk images or individual artifact files.

In 4 lists

ir-rescue

ir-rescue is a Windows Batch script and a Unix Bash script to comprehensively collect host forensic data during incident response.

In 4 lists

Margarita Shotgun

Command line utility (that works with or without Amazon EC2 instances) to parallelize remote memory acquisition.

In 3 lists

The ESF Playground

A tool to view the events in Apple Endpoint Security Framework (ESF) in real time.

AutoMacTC

Modular, automated forensic triage collection framework designed to access various forensic artifacts on macOS, parse them, and present them in formats viable for analysis.

In 2 lists

Untitled Goose Tool

Assists incident response teams by exporting cloud artifacts from Azure/AzureAD/M365 environments in order to run a full investigation despite lacking in logs ingested by a SIEM.