Useful tools for (not only) digital forensics
-
Updated
Jul 21, 2026
Useful tools for (not only) digital forensics
DFIR artifact catalog (6,554 artifacts, LOL/LOFL binaries, abusable sites) plus the normalized report vocabulary the SecurityRonin analyzer fleet shares — offline Rust library + 4n6query CLI
An open-source forensic parser for Apple Intelligence Report JSON files.
Static and basic dynamic forensics on MacOS apps. See if bundled with telemetry, permissions requested and preview updates before they land
macOS DFIR Artifact Collector — single-file, zero-dependency, modular collection script with selective module execution and supply-chain IOC sweeps.
Digital forensics and incident response (DFIR) reference: evidence handling, memory/disk forensics workflows, and chain-of-custody procedures for enterprise investigations
macOS DFIR Forensics Platform — Flask-based web platform that ingests collector ZIPs and disk images (DD/RAW/E01/AFF/DMG), parses 30+ artifact categories, and produces searchable evidence + PDF incident reports with optional Ollama / OpenAI analysis.
AI-native MCP server for natural-language cyber incident investigation and triage across Windows, Linux, and macOS artifacts, plus Volatility3 memory forensics and Hashcat. Mount evidence, parse artifacts, trace lateral movement, correlate IOCs, and generate reports through conversation.
Comprehensive modular forensic analysis tool for macOS with real-time system analysis, memory forensics, network investigation, and automated HTML/JSON reporting. Features 8 specialized modules for cybersecurity professionals and incident response teams. Forensic macOS
To associate your repository with the macos-forensics topic, visit your repo's landing page and select "manage topics."