Static and basic dynamic forensics on MacOS apps. See if bundled with telemetry, permissions requested and preview updates before they land
-
Updated
Jun 22, 2026 - Swift
Static and basic dynamic forensics on MacOS apps. See if bundled with telemetry, permissions requested and preview updates before they land
Useful tools for (not only) digital forensics
DFIR artifact catalog (6,554 artifacts, LOL/LOFL binaries, abusable sites) plus the normalized report vocabulary the SecurityRonin analyzer fleet shares — offline Rust library + 4n6query CLI
An open-source forensic parser for Apple Intelligence Report JSON files.
macOS DFIR Artifact Collector — single-file, zero-dependency, modular collection script with selective module execution and supply-chain IOC sweeps.
macOS DFIR Forensics Platform — Flask-based web platform that ingests collector ZIPs and disk images (DD/RAW/E01/AFF/DMG), parses 30+ artifact categories, and produces searchable evidence + PDF incident reports with optional Ollama / OpenAI analysis.
Comprehensive modular forensic analysis tool for macOS with real-time system analysis, memory forensics, network investigation, and automated HTML/JSON reporting. Features 8 specialized modules for cybersecurity professionals and incident response teams. Forensic macOS
Add a description, image, and links to the macos-forensics topic page so that developers can more easily learn about it.
To associate your repository with the macos-forensics topic, visit your repo's landing page and select "manage topics."