From e5637704ba6eff28157016358a36ae8857683810 Mon Sep 17 00:00:00 2001 From: "Yogesh Khatri (@swiftforensics)" Date: Sun, 7 Jan 2018 00:11:05 -0500 Subject: [PATCH] Added mac_apt under OSX category --- README.md | 1 + 1 file changed, 1 insertion(+) diff --git a/README.md b/README.md index 85fcb43..6170212 100644 --- a/README.md +++ b/README.md @@ -130,6 +130,7 @@ A curated list of tools and resources for security incident response, aimed to h ### OSX Evidence Collection * [Knockknock](https://github.com/synack/knockknock) - Displays persistent items(scripts, commands, binaries, etc.) that are set to execute automatically on OSX +* [mac_apt - macOS Artifact Parsing Tool](https://github.com/ydkhatri/mac_apt) - Plugin based forensics framework for quick mac triage that works on live machines, disk images or individual artifact files * [OSX Auditor](https://github.com/jipegit/OSXAuditor) - OSX Auditor is a free Mac OS X computer forensics tool * [OSX Collector](https://github.com/yelp/osxcollector) - An OSX Auditor offshoot for live response