mac_apt Logo

mac_apt

0
Free
Visit Website

mac_apt is a DFIR (Digital Forensics and Incident Response) tool designed to process Mac computer full disk images or live machines, extracting data and metadata crucial for forensic investigations. It is a Python-based framework with plugins for processing various artifacts like Safari internet history, network interfaces, and recently accessed files. Additionally, mac_apt now includes ios_apt for handling iOS images. It is cross-platform, supports multiple image formats, provides outputs in XLSX, CSV, TSV, and SQLite, and can handle compressed files. The tool also features native HFS and APFS parsing, reads Spotlight database and Unified Logging files, and supports macOS Big Sur sealed volumes.

FEATURES

ALTERNATIVES

IE10Analyzer can parse and recover records from WebCacheV01.dat, providing detailed information and conversion capabilities.

A portable volatile memory acquisition tool for Linux.

A library to access the Extensible Storage Engine (ESE) Database File (EDB) format used in various Windows applications.

Advanced computer forensics software with efficient features.

Open source Python library for NTFS analysis

A Python-based engine for automatic creation of timelines in digital forensic analysis

wxHexEditor is a free hex editor / disk editor with various data manipulation operations and visualization functionalities.

Visually inspect regex matches in binary data/text with YARA and regular expressions, displaying matched bytes and surrounding context.

CyberSecTools logoCyberSecTools

Explore the largest curated directory of cybersecurity tools and resources to enhance your security practices. Find the right solution for your domain.

Copyright © 2024 - All rights reserved