macOS Artifact Parsing Tool (mac_apt)
Forensics & Incident ResponseA Python‑based DFIR framework for parsing macOS (and iOS) artifacts and extracting forensic data
Features
- Cross‑platform operation without pyobjc dependency
- Supports multiple disk image formats (E01, VMDK, AFF4, DMG, SPARSEIMAGE, etc.)
- Exports analysis results in XLSX, CSV, TSV, JSONL and SQLite
Security Response History
1 CVE| CVE | Severity | Disclosed | Patched (this tool) | vs Ecosystem Median |
|---|---|---|---|---|
| CVE-2023-4863 KEV |
high
CVSS 8.8
|
2023-09-13 | 2026-01-14 | 2y 4mo / median 2y 4mo |
Recent releases
View all 3 releases →
v1.29.0
New feature
Notable features
- UAC collections support
- Typedstream iMessage parsing
- Big Sur APFS fixes
v1.28.11
Bug fix
macOS forensics tool receives bug fixes and performance optimizations with improved exception handling for slightly corrupted disk images.
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Install & Platforms
Platforms
macos
linux
windows
arm64