AutoMacTC is a modular forensic triage collection framework for macOS that accesses various forensic artifacts, parses them, and presents them in formats suitable for analysis. It can be run against live systems or dead disks, requires Python 3.9 or earlier, and is compatible with macOS major releases 10.11 through 11.2.3 as well as the M1 processor. It supports triage against mounted disk images from macOS 10.11 through 10.15 systems.
FEATURES
EXPLORE BY TAGS
SIMILAR TOOLS
Web interface for the Volatility Memory Analysis framework with advanced features.
DMG2IMG is a tool for converting Apple compressed dmg archives to standard image disk files with support for zlib, bzip2, and LZFSE compression.
A tool for collecting and analyzing screenshots from remote desktop protocols, web applications, and VNC connections.
Exterro is a data risk management platform that optimizes e-discovery, digital forensics, and cybersecurity compliance operations.
Developing APIs to access memory on industrial control system devices.
Customizable live OS constructor tool for remote forensics and incident response.
A reliable end-to-end DFIR solution for boosting cyber incident response and forensics capacity.
LiME is a Linux Memory Extractor tool for acquiring volatile memory from Linux and Linux-based devices, including Android, with features like full memory captures and minimal process footprint.
PINNED

Mandos
Fractional CISO service that helps B2B companies implement security leadership to win enterprise deals, achieve compliance, and develop strategic security programs.

Checkmarx SCA
A software composition analysis tool that identifies vulnerabilities, malicious code, and license risks in open source dependencies throughout the software development lifecycle.

Orca Security
A cloud-native application protection platform that provides agentless security monitoring, vulnerability management, and compliance capabilities across multi-cloud environments.

DryRun
A GitHub application that performs automated security code reviews by analyzing contextual security aspects of code changes during pull requests.