mac_apt Logo

mac_apt

0
Free
Visit Website

mac_apt is a DFIR (Digital Forensics and Incident Response) tool designed to process Mac computer full disk images or live machines, extracting data and metadata crucial for forensic investigations. It is a Python-based framework with plugins for processing various artifacts like Safari internet history, network interfaces, and recently accessed files. Additionally, mac_apt now includes ios_apt for handling iOS images. It is cross-platform, supports multiple image formats, provides outputs in XLSX, CSV, TSV, and SQLite, and can handle compressed files. The tool also features native HFS and APFS parsing, reads Spotlight database and Unified Logging files, and supports macOS Big Sur sealed volumes.

FEATURES

ALTERNATIVES

A tool for extracting files from packet capture files with ease of use and extensibility for Python developers.

A powerful reverse engineering framework

Python script to parse macOS MRU plist files into human-friendly format

Dissect is a digital forensics & incident response framework that simplifies the analysis of forensic artefacts from various disk and file formats.

A command-line utility to show and change EXIF information in JPEG files

Python tool for remotely or locally dumping RAM of a Linux client for digital forensics analysis.

A software utility with forensic tools for smartphones, offering powerful data extraction and decoding capabilities.

Belkasoft offers cybersecurity solutions, training, and tools for businesses, law enforcement, and academia.