This is your work, valued
DFIR wizard (in hibernation!)
mac_apt. macOS (& ios) Artifact Parsing Tool
1.1kMacForensics. Scripts to process macOS forensic artifacts
213OneDrive. OneDrive log .ODL reader
168spotlight_parser. Read and extract data from macOS spotlight databases
134UnifiedLogReader. A parser for Unified logging tracev3 files
100blackboxprotobuf. Blackbox protobuf is a library for decoding and modifying arbitrary protobuf messages without the protobuf type definition.
42nska_deserialize. NSKeyedArchive plist deserializer
29APFS_010. 010 template for apfs
27Appx-Analysis. Scripts and tools created for appx analysis talk (Magnet summit 2019)
19pyliblzfse. Python bindings for LZFSE
18Presentations. Slides and material from my conference presentations
16jarp. Just Another broken Registry Parser (JARP)
16macOS_FE. Tools for macOS Forensic Bootable media
16spotlight_queries. Queries for parsed spotlight database in sqlite
13Android. Android forensics related scripts
9awesome-forensics. A curated list of awesome forensic analysis tools and resources
9Powershell_Basics. A collection of PowerShell tutorials and simple scripts to get people started
6010_Templates. 010 editor templates for parsing various formats
4Bash_Basics.
4macosac. Forensic Artifact Collection Tool for macOS
3