DFIR artifact catalog (6,554 artifacts, LOL/LOFL binaries, abusable sites) plus the normalized report vocabulary the SecurityRonin analyzer fleet shares — offline Rust library + 4n6query CLI
-
Updated
Sep 15, 2026 - Rust
DFIR artifact catalog (6,554 artifacts, LOL/LOFL binaries, abusable sites) plus the normalized report vocabulary the SecurityRonin analyzer fleet shares — offline Rust library + 4n6query CLI
Useful tools for (not only) digital forensics
An open-source forensic parser for Apple Intelligence Report JSON files.
Static and basic dynamic forensics on MacOS apps. See if bundled with telemetry, permissions requested and preview updates before they land
Digital forensics and incident response (DFIR) reference: evidence handling, memory/disk forensics workflows, and chain-of-custody procedures for enterprise investigations
macOS DFIR Forensics Platform — Flask-based web platform that ingests collector ZIPs and disk images (DD/RAW/E01/AFF/DMG), parses 30+ artifact categories, and produces searchable evidence + PDF incident reports with optional Ollama / OpenAI analysis.
macOS DFIR Artifact Collector — single-file, zero-dependency, modular collection script with selective module execution and supply-chain IOC sweeps.
AI-native MCP server for natural-language cyber incident investigation and triage across Windows, Linux, and macOS artifacts, plus Volatility3 memory forensics and Hashcat. Mount evidence, parse artifacts, trace lateral movement, correlate IOCs, and generate reports through conversation.
Comprehensive modular forensic analysis tool for macOS with real-time system analysis, memory forensics, network investigation, and automated HTML/JSON reporting. Features 8 specialized modules for cybersecurity professionals and incident response teams. Forensic macOS
To associate your repository with the macos-forensics topic, visit your repo's landing page and select "manage topics."