Skip to content
macOS Artifact Parsing Tool (mac_apt)
Forensics & Incident Response
A Python‑based DFIR framework for parsing macOS and iOS artifacts from disk images, live systems, backups, and various collection formats.
Python
·
Latest v1.29.0 · 3mo ago
Security brief →
Features
-
Cross‑platform operation without pyobjc dependencies
-
Supports multiple input formats (E01, VMDK, AFF4, DMG, SPARSEIMAGE, split DD, Velociraptor collections, etc.)
-
Exports artifacts in XLSX, CSV, TSV, JSONL and SQLite for downstream analysis
Security Response History
1 CVE
| CVE |
Severity |
Disclosed |
Patched (this tool) |
vs Ecosystem Median |
|
CVE-2023-4863
KEV
|
high
CVSS 8.8
|
2023-09-13
|
2026-01-14
|
2y 4mo / median 2y 4mo
|
v1.29.0
New feature
·
Notable features
- UAC collections support
- Typedstream iMessage parsing
- Big Sur APFS fixes
v1.28.11
Bug fix
·
macOS forensics tool receives bug fixes and performance optimizations with improved exception handling for slightly corrupted disk images.
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
About
Languages
Python
·
Kaitai Struct
·
Shell
View on GitHub
Homepage
Install & Platforms
Platforms
macos
linux
windows
arm64
Search tools, categories, lists, and users
Use ↑↓ to navigate, Enter to open, Esc to close
No results for ""
⌘K to open
↑↓ navigate
⏎ open