Skip to content

macOS Artifact Parsing Tool (mac_apt)

Forensics & Incident Response

A Python‑based DFIR framework for parsing macOS (and iOS) artifacts and extracting forensic data

Python Latest v1.33.2 · 6d ago Security brief →

Features

  • Cross‑platform operation without pyobjc dependency
  • Supports multiple disk image formats (E01, VMDK, AFF4, DMG, SPARSEIMAGE, etc.)
  • Exports analysis results in XLSX, CSV, TSV, JSONL and SQLite

Security Response History

1 CVE
CVE Severity Disclosed Patched (this tool) vs Ecosystem Median
CVE-2023-4863 KEV high
CVSS 8.8
2023-09-13 2026-01-14 2y 4mo / median 2y 4mo

Recent releases

View all 3 releases →
No immediate action
v1.33.2 New feature

Compressed DMG + Biome parser

v1.29.0 New feature
Notable features
  • UAC collections support
  • Typedstream iMessage parsing
  • Big Sur APFS fixes
v1.28.11 Bug fix

macOS forensics tool receives bug fixes and performance optimizations with improved exception handling for slightly corrupted disk images.

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

About

Stars
1,065
Forks
125
Languages
Python Kaitai Struct Shell

Install & Platforms

Platforms
macos linux windows arm64

Beta — feedback welcome: [email protected]