Parse forensic artifacts on a MacOS system. This program does not currently analyze live systems, only disk images. So you will need to mount a disk image of a MacOS system before running this.
Current features:
System Artifacts:
- Bluetooth devices
- Last login
- Network Interfaces
User Artifacts:
- Recent Items
- Bash and Zsh History
- Trash
Internet Artifacts:
- History
- Downloads
- Bookmarks
- Login Data
Spotlight-V100 Parsing
More to come.