AutoMacTC Logo

AutoMacTC

0
Free
Visit Website

AutoMacTC is a modular forensic triage collection framework for macOS that accesses various forensic artifacts, parses them, and presents them in formats suitable for analysis. It can be run against live systems or dead disks, requires Python 3.9 or earlier, and is compatible with macOS major releases 10.11 through 11.2.3 as well as the M1 processor. It supports triage against mounted disk images from macOS 10.11 through 10.15 systems.

FEATURES

ALTERNATIVES

A powerful OSINT tool for creating custom templates for data extraction and analysis

Dump iOS Frequent Locations from StateModel#.archive files.

Tool for parsing NTFS journal files, $Logfile, and $MFT.

A library to access the Expert Witness Compression Format (EWF) for digital forensics and incident response.

A command-line tool for extracting detailed information from JPEG files, including image dimensions, compression, and metadata.

Toolkit for post-mortem analysis of Docker runtime environments using forensic HDD copies.

Anti-forensics tool for Red Teamers to erase footprints and test incident response capabilities.

A library to access and parse Windows NT Registry File (REGF) format.