Never Ending Security

It starts all here

OSXCollector – Forensic OSX

OSXCollector is a forensic evidence collection & analysis toolkit for OSX.

Forensic Collection
The collection script runs on a potentially infected machine and outputs a JSON file that describes the target machine. OSXCollector gathers information from plists, SQLite databases and the local file system.

Forensic Analysis
Armed with the forensic collection, an analyst can answer the question like:

Is this machine infected?
How’d that malware get there?
How can I prevent and detect further infection?

Yelp automates the analysis of most OSXCollector runs converting OSXCollector output into an easily readable and actionable summary of just the suspicious stuff.

More Info:

Leave a Reply

Please log in using one of these methods to post your comment: Logo

You are commenting using your account. Log Out / Change )

Twitter picture

You are commenting using your Twitter account. Log Out / Change )

Facebook photo

You are commenting using your Facebook account. Log Out / Change )

Google+ photo

You are commenting using your Google+ account. Log Out / Change )

Connecting to %s