免費的Mac OS X計算機取證工具:OSX Auditor

jopen 10年前發布 | 22K 次閱讀 安全相關 OSX Auditor

OSX Auditor是一個免費的Mac OS X計算機取證工具,這個工具顯示分析內核擴展、用戶下載的文件等等,然后是提取用戶的隔離文件、訪問歷史等等,最后就可以確認文件的可信度。

OS X Auditor parses and hashes the following artifacts on the running system or a copy of a system you want to analyze:

  • the kernel extensions
  • the system agents and daemons
  • the third party's agents and daemons
  • the old and deprecated system and third party's startup items
  • the users' agents
  • the users' downloaded files
  • the installed applications

It extracts:

  • the users' quarantined files
  • the users' Safari history, downloads, topsites, LastSession, HTML5 databases and localstore
  • the users' Firefox cookies, downloads, formhistory, permissions, places and signons
  • the users' Chrome history and archives history, cookies, login data, top sites, web data, HTML5 databases and local storage
  • the users' social and email accounts
  • the WiFi access points the audited system has been connected to (and tries to geolocate them)

費的Mac OS X計算機取證工具:OSX Auditor

項目主頁:http://www.baiduhome.net/lib/view/home/1410838226945

 本文由用戶 jopen 自行上傳分享,僅供網友學習交流。所有權歸原作者,若您的權利被侵害,請聯系管理員。
 轉載本站原創文章,請注明出處,并保留原始鏈接、圖片水印。
 本站是一個以用戶分享為主的開源技術平臺,歡迎各類分享!