OS X Auditor Logo

OS X Auditor

0
Free
Visit Website

OS X Auditor is a free Mac OS X computer forensics tool that parses and hashes various artifacts on the system, including kernel extensions, system agents, users' files, installed applications, Safari and browser history, social and email accounts, WiFi access points, and more. It also checks for suspicious keywords in .plist files, verifies file reputation with Team Cymru's MHR, VirusTotal, and local databases, and aggregates logs into a zipball.

FEATURES

ALTERNATIVES

A collection of PowerShell modules for artifact gathering and reconnaissance of Windows-based endpoints.

A tool for creating compact Linux memory dumps compatible with popular debugging tools.

A PowerShell-based incident response and live forensic data acquisition tool for Windows hosts.

Automated tool for parsing Windows registry hives and extracting valuable information for forensic analysis.

Hindsight is a free tool for analyzing web artifacts from Google Chrome/Chromium browsers and presenting the data in a timeline for forensic analysis.

Developing APIs to access memory on industrial control system devices.

Forensics tool for exploring offline Docker filesystems.

An anti-forensic Linux Kernel Module kill-switch for USB ports.

PINNED