{"id":51699319,"url":"https://github.com/LETHAL-FORENSICS/MacOS-Analyzer-Suite","last_synced_at":"2026-08-04T14:00:30.835Z","repository":{"id":322439287,"uuid":"1089491638","full_name":"LETHAL-FORENSICS/MacOS-Analyzer-Suite","owner":"LETHAL-FORENSICS","description":"A collection of PowerShell scripts for analyzing macOS Forensic Artifacts","archived":false,"fork":false,"pushed_at":"2026-03-16T07:34:43.000Z","size":40897,"stargazers_count":23,"open_issues_count":0,"forks_count":2,"subscribers_count":1,"default_branch":"main","last_synced_at":"2026-03-16T19:10:52.340Z","etag":null,"topics":["apple","dfir","dfir-tools","digital-forensics","forensic-tools","incident-response","macos"],"latest_commit_sha":null,"homepage":"","language":"PowerShell","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"mit","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/LETHAL-FORENSICS.png","metadata":{"files":{"readme":"README.md","changelog":"CHANGELOG.md","contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":null,"maintainers":null,"copyright":null,"agents":null,"dco":null,"cla":null}},"created_at":"2025-11-04T12:18:11.000Z","updated_at":"2026-03-16T09:36:32.000Z","dependencies_parsed_at":null,"dependency_job_id":null,"html_url":"https://github.com/LETHAL-FORENSICS/MacOS-Analyzer-Suite","commit_stats":null,"previous_names":["lethal-forensics/macos-analyzer-suite"],"tags_count":3,"template":false,"template_full_name":null,"purl":"pkg:github/LETHAL-FORENSICS/MacOS-Analyzer-Suite","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/LETHAL-FORENSICS%2FMacOS-Analyzer-Suite","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/LETHAL-FORENSICS%2FMacOS-Analyzer-Suite/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/LETHAL-FORENSICS%2FMacOS-Analyzer-Suite/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/LETHAL-FORENSICS%2FMacOS-Analyzer-Suite/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/LETHAL-FORENSICS","download_url":"https://codeload.github.com/LETHAL-FORENSICS/MacOS-Analyzer-Suite/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/LETHAL-FORENSICS%2FMacOS-Analyzer-Suite/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":36277672,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-07-20T02:08:10.276Z","status":"online","status_checked_at":"2026-08-04T02:00:06.901Z","response_time":57,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["apple","dfir","dfir-tools","digital-forensics","forensic-tools","incident-response","macos"],"created_at":"2026-07-16T09:00:21.748Z","updated_at":"2026-08-04T14:00:30.830Z","avatar_url":"https://github.com/LETHAL-FORENSICS.png","language":"PowerShell","funding_links":[],"categories":["Challenges"],"sub_categories":["OS X Forensics"],"readme":"\u003cp align=\"center\"\u003e\u003ca href=\"https://github.com/PowerShell/PowerShell\"\u003e\u003cimg src=\"https://img.shields.io/badge/Language-Powershell-blue\" style=\"text-align:center;display:block;\"\u003e\u003c/a\u003e \u003cimg src=\"https://img.shields.io/badge/Operating System-Windows-blue\" style=\"text-align:center;display:block;\"\u003e \u003ca href=\"https://github.com/LETHAL-FORENSICS/MacOS-Analyzer-Suite/releases/latest\"\u003e\u003cimg src=\"https://img.shields.io/github/v/release/LETHAL-FORENSICS/MacOS-Analyzer-Suite?label=Release\" style=\"text-align:center;display:block;\"\u003e\u003c/a\u003e \u003cimg src=\"https://img.shields.io/badge/Maintenance%20Level-Actively%20Developed-brightgreen\" style=\"text-align:center;display:block;\"\u003e \u003cimg src=\"https://img.shields.io/badge/Digital%20Signature-Valid-brightgreen\" style=\"text-align:center;display:block;\"\u003e \u003ca href=\"https://x.com/LETHAL_DFIR\"\u003e\u003cimg src=\"https://img.shields.io/twitter/follow/LETHAL_DFIR?style=social\" style=\"text-align:center;display:block;\"\u003e\u003c/a\u003e\u003c/p\u003e  \n\n# MacOS-Analyzer-Suite\nA collection of PowerShell scripts for analyzing macOS Forensic Artifacts\n\n## The following MacOS Forensic Artifacts are supported yet:\n\n  * Aftermath Storyline \u0026#8594; Storyline-Analyzer\n  * Aftermath File Timeline \u0026#8594; Timeline-Analyzer\n  * BTM dump file(s) \u0026#8594; BTM-Analyzer\n  * .DS_Store file(s) \u0026#8594; DSStore-Analyzer\n  * File Hash Lists \u0026#8594; VirusTotal-Analyzer\n  * FSEvent Logs \u0026#8594; FSEvents-Analyzer\n  * KnockKnock Results \u0026#8594; KnockKnock-Analyzer (incl. VirusTotal-Analyzer)\n  * LSQuarantine database file(s) \u0026#8594; Quarantine-Analyzer\n  * TCC database file(s) \u0026#8594; TCC-Analyzer\n  * XProtect Behavioral Service database file(s) \u0026#8594; XProtect-Analyzer\n\n\u003cbr\u003e\n\n\u003e [!NOTE]\n\u003e MacOS-Analyzer-Suite includes all external tools by default.  \n\n## Prerequisites  \n1. Windows PowerShell 5.1 or newer.  \n\n## Setup  \n1. Download the latest version of the **MacOS-Analyzer-Suite** from the [Releases](https://github.com/LETHAL-FORENSICS/MacOS-Analyzer-Suite/releases/latest) section.\n2. Install [ImportExcel](https://github.com/dfinke/ImportExcel) PowerShell module to import/export Excel spreadsheets, without Excel.  \n\n   ```powershell\n   Install-Module -Name ImportExcel\n   ```  \n3. Install [Python 3](https://www.python.org/downloads/windows/) and add it to your PATH environment variable.\n4. Run the specific script in PowerShell (e.g. TCC-Analyzer.ps1). \n5. Optional: Edit `Config.json` to choose your own Excel color scheme. \n\n## Usage  \nOpen PowerShell and navigate to the directory containing e.g. TCC-Analyzer.ps1 and run the script with following command: `.\\TCC-Analyzer.ps1`\n\n![File-Browser](https://github.com/user-attachments/assets/0718a242-cae2-4236-b3d4-fd25e31fb8f5)  \n**Fig 1:** Select your TCC Database file     \n\nYou can skip the file selection dialog and provide the file path to your log file with following command:  \n`.\\TCC-Analyzer.ps1 -Path \"$env:USERPROFILE\\Desktop\\tcc_\u003cUSERNAME\u003e\"`  \n\nYou can specify the output directory with following command:   \n`.\\TCC-Analyzer.ps1 -Path \"H:\\macos-collector\\tcc_\u003cUSERNAME\u003e\" -OutputDir \"H:\\MacOS-Analyzer-Suite\"`  \n\n\u003e [!NOTE]\n\u003e Default output directory is `$env:USERPROFILE\\Desktop\\TCC-Analyzer`  \n\u003e The subdirectory 'TCC-Analyzer' is automatically created.  \n\n\u003cbr\u003e\n\n![FSEvents-Analyzer](https://github.com/user-attachments/assets/5b6446f4-9814-464c-bcd9-44e7869b498b)  \n**Fig 1:** FSEvents-Analyzer  \n\n![MessageBox](https://github.com/user-attachments/assets/e425e413-90ca-452d-af15-cc68922e7157)  \n**Fig 2:** MessageBox  \n\n![Quarantine-Analyzer](https://github.com/user-attachments/assets/73b68c19-87be-4f1e-9ca6-45fb939c484f)  \n**Fig 3:** Quarantine-Analyzer  \n\n![TCC-Analyzer](https://github.com/user-attachments/assets/142b76a0-d46c-40b3-8d29-574f7f8e3bb8)  \n**Fig 4:** TCC-Analyzer  \n\n![XProtect-Analyzer](https://github.com/user-attachments/assets/3a9cccb9-20cc-4f10-8b90-ca04034a331a)  \n**Fig 5:** XProtect-Analyzer  \n\n![XProtect-BehaviorService](https://github.com/user-attachments/assets/1aa06ba6-1385-48be-8eae-4160becde5af)  \n**Fig 6:** XProtect Behavior Service  \n\n![Bastion-Rules](https://github.com/user-attachments/assets/a5664093-eda5-4dea-bea3-e2dee857e8ac)  \n**Fig 7:** Bastion-Rules.xlsx (Stats)  \n\n![BTM-Analyzer](https://github.com/user-attachments/assets/eb989228-155f-4ea9-a2a0-3e2147f50386)  \n**Fig 8:** BTM-Analyzer (Background Task Management)  \n\n\u003e [!TIP]\n\u003e ```Aftermath Collection\\Persistence\\btm.txt``` or ```sudo sfltool dumpbtm \u003e ~/Desktop/btm.txt```  \n\n![BTM-XLSX](https://github.com/user-attachments/assets/872279fa-e388-44a1-ab8b-e23a971096b8)  \n**Fig 9:** BTM.xlsx  \n\n![DSStore-Analyzer](https://github.com/user-attachments/assets/8aa2f66b-3452-4df4-96dc-d889c0230237)  \n**Fig 10:** DSStore-Analyzer  \n\n![Storyline-Analyzer](https://github.com/user-attachments/assets/4850f2a3-a6d1-4924-b4b8-5067b3832e33)  \n**Fig 11:** Storyline-Analyzer  \n\n![Storyline-SQLite](https://github.com/user-attachments/assets/4bb3d24f-6580-494b-a767-4b2720796994)  \n**Fig 12:** Storyline-Analyze.db (SQLite database w/ Views)  \n\n![KnockKnock-Analyzer](https://github.com/user-attachments/assets/47456643-f5a2-4c76-aedf-2d6f69e83122)  \n**Fig 13:** KnockKnock-Analyzer (incl. VirusTotal-Analyzer)  \n\n![VirusTotal-Analyzer](https://github.com/user-attachments/assets/e93b8a32-70c2-43aa-8f55-aa6eae5cf133)  \n**Fig 14:** VirusTotal-Analyzer (Standalone)  \n\n![VirusTotal-Report](https://github.com/user-attachments/assets/24a5f964-38ad-41be-af21-a2082e1fb46a)  \n**Fig 15:** VirusTotal-Report.xlsx  \n\n## License\nThis project is licensed under the MIT License - see the [LICENSE](LICENSE) file for details.  \n\n## Feedback  \nFeel free to send comments and feedback to [github@lethal-forensics.com](mailto:github@lethal-forensics.com) or open an [issue](https://github.com/LETHAL-FORENSICS/MacOS-Analyzer-Suite/issues).\n\n## Links  \n[Aftermath by Jamf Threat Labs](https://github.com/jamf/aftermath)  \n[macos-collector by LETHAL-FORENSICS](https://github.com/LETHAL-FORENSICS/macos-collector)  \n[DB Browser for SQLite](https://sqlitebrowser.org/dl/)  \n[Arsenal Image Mounter (AIM)](https://arsenalrecon.com/products/arsenal-image-mounter)  \n[APFS for Windows by Paragon Software](https://www.paragon-software.com/home/apfs-windows/)  \n[VirusTotal CLI](https://github.com/VirusTotal/vt-cli)  \n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2FLETHAL-FORENSICS%2FMacOS-Analyzer-Suite","html_url":"https://awesome.ecosyste.ms/projects/github.com%2FLETHAL-FORENSICS%2FMacOS-Analyzer-Suite","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2FLETHAL-FORENSICS%2FMacOS-Analyzer-Suite/lists"}