• 设为首页
  • 点击收藏
  • 手机版
    手机扫一扫访问
    迪恩网络手机版
  • 关注官方公众号
    微信扫一扫关注
    公众号

ydkhatri/MacForensics: Scripts to process macOS forensic artifacts

原作者: [db:作者] 来自: 网络 收藏 邀请

开源软件名称(OpenSource Name):

ydkhatri/MacForensics

开源软件地址(OpenSource Url):

https://github.com/ydkhatri/MacForensics

开源编程语言(OpenSource Language):

Python 100.0%

开源软件介绍(OpenSource Introduction):

MacForensics

Repository of scripts for processing various artifacts from macOS (formerly OSX).

Artifact Script Name Description
Darwin folders darwin_path_generator.py DARWIN_USER_ folders name generation algorithm (those seemingly random folder names under /var/folders/)
Deserialize NSKeyedArchive plists Deserializer/deserializer.py
Deserializer/deserializer.exe
Converts NSKeyedArchive plists to normal (human-readable) plists (Code + compiled exe for windows)
Domain (Active Directory) Domain_Info/Read_ConfigProfiles.py Reads user profile information for AD domain users from the ConfigProfiles.binary file
DotUnderscore ._ files DotUnderscore_macos.bt An 010 template for parsing extended attribute files that begin with ._
Ktx to Png convertor IOS_KTX_TO_PNG/ios_ktx2png.py
IOS_KTX_TO_PNG/ios_ktx2png.exe
Convert ios created KTX texture images (like app snapshots) to PNG (Code + compiled exe for windows)
Notifications macNotifications.py Parse Mac Notifications db
Office reg file Read_OfficeRegDB.py Parse MS Office created sqlite db (microsoftRegistrationDB.reg)



鲜花

握手

雷人

路过

鸡蛋
该文章已有0人参与评论

请发表评论

全部评论

专题导读
上一篇:
Shaneee/AMD-High-Sierra-XNU: AMD CPU Support for macOS High Sierra发布时间:2022-08-18
下一篇:
mre/timelapse: 发布时间:2022-08-18
热门推荐
阅读排行榜

扫描微信二维码

查看手机版网站

随时了解更新最新资讯

139-2527-9053

在线客服(服务时间 9:00~18:00)

在线QQ客服
地址:深圳市南山区西丽大学城创智工业园
电邮:jeky_zhao#qq.com
移动电话:139-2527-9053

Powered by 互联科技 X3.4© 2001-2213 极客世界.|Sitemap