Scripts to process OSX forensic artifacts
Switch branches/tags
Nothing to show
Clone or download
Fetching latest commit…
Cannot retrieve the latest commit at this time.
Permalink
Failed to load latest commit information.
Domain_Info
README.md
Read_OfficeRegDB.py
darwin_path_generator.py
macNotifications.py

README.md

MacForensics

Repository of scripts for processing various artifacts from macOS (formerly OSX).

Script Name Description
Read_OfficeRegDB.py Parse MS Office created sqlite db (microsoftRegistrationDB.reg)
macNotifications.py Parse Mac Notifications db
darwin_path_generator.py DARWIN_USER_ folders name generation algorithm (those seemingly random folder names under /var/folders/)
Domain_Info/Read_ConfigProfiles.py Reads user profile information for AD domain users from the ConfigProfiles.binary file