Scripts to process OSX forensic artifacts
Switch branches/tags
Nothing to show
Clone or download
Fetching latest commit…
Cannot retrieve the latest commit at this time.
Failed to load latest commit information.


Repository of scripts for processing various artifacts from macOS (formerly OSX).

Script Name Description Parse MS Office created sqlite db (microsoftRegistrationDB.reg) Parse Mac Notifications db DARWIN_USER_ folders name generation algorithm (those seemingly random folder names under /var/folders/)
Domain_Info/ Reads user profile information for AD domain users from the ConfigProfiles.binary file