OSXCollector Logo

OSXCollector

0
Free
Updated 11 March 2025
Visit Website

OSXCollector is a forensic evidence collection & analysis toolkit for OSX. The collection script runs on a potentially infected machine and outputs a JSON file that describes the target machine. OSXCollector gathers information from plists, SQLite databases, and the local file system. Armed with the forensic collection, an analyst can answer questions like: Is this machine infected? How'd that malware get there? How can I prevent and detect further infection? Yelp automates the analysis of most OSXCollector runs, converting its output into an easily readable and actionable summary of just the suspicious stuff. Check out OSXCollector Output Filters project to learn how to make the most of the automated OSXCollector output analysis. osxcollector.py is a single Python file that runs without any dependencies on a standard OSX machine, making it really easy to run collection on any machine - no fussing with brew, pip, config files, or environment variables. Just copy the single file onto the machine and run it: sudo osxcollector.py is all it takes. $ sudo osxcollector.py Wrote 35394 lines. Output in osx

FEATURES

SIMILAR TOOLS

Automated tool for parsing Windows registry hives and extracting valuable information for forensic analysis.

Belkasoft offers cybersecurity solutions, training, and tools for businesses, law enforcement, and academia.

A Python-based engine for automatic creation of timelines in digital forensic analysis

A free, open-source file data recovery software that can recover lost files from hard disks, CD-ROMs, and digital camera memory.

Custom built application for asynchronous forensic data presentation on an Elasticsearch backend, with upcoming features like Docker-based installation and new UI rewrite in React.

Free software for extracting Microsoft cabinet files, supporting all features and formats of Microsoft cabinet files and Windows CE installation files.

Digital investigation tool for extracting forensic data from computers and managing investigations.

A script to assist in creating templates for VirtualBox to enhance VM detection evasion.

Second-order subdomain takeover scanner

CyberSecTools logoCyberSecTools

Explore the largest curated directory of cybersecurity tools and resources to enhance your security practices. Find the right solution for your domain.

Operated by:

Mandos Cyber • KVK: 97994448

Netherlands • contact@mandos.io

VAT: NL005301434B12

Copyright © 2025 - All rights reserved