Useful tools for (not only) digital forensics
-
Updated
Jul 21, 2026
Useful tools for (not only) digital forensics
DFIR artifact catalog (6,554 artifacts, LOL/LOFL binaries, abusable sites) plus the normalized report vocabulary the SecurityRonin analyzer fleet shares — offline Rust library + 4n6query CLI
Static and basic dynamic forensics on MacOS apps. See if bundled with telemetry, permissions requested and preview updates before they land
macOS DFIR Artifact Collector — single-file, zero-dependency, modular collection script with selective module execution and supply-chain IOC sweeps.
Digital forensics and incident response (DFIR) reference: evidence handling, memory/disk forensics workflows, and chain-of-custody procedures for enterprise investigations
macOS DFIR Forensics Platform — Flask-based web platform that ingests collector ZIPs and disk images (DD/RAW/E01/AFF/DMG), parses 30+ artifact categories, and produces searchable evidence + PDF incident reports with optional Ollama / OpenAI analysis.
An open-source forensic parser for Apple Intelligence Report JSON files.
Comprehensive modular forensic analysis tool for macOS with real-time system analysis, memory forensics, network investigation, and automated HTML/JSON reporting. Features 8 specialized modules for cybersecurity professionals and incident response teams. Forensic macOS
Add a description, image, and links to the macos-forensics topic page so that developers can more easily learn about it.
To associate your repository with the macos-forensics topic, visit your repo's landing page and select "manage topics."