(2) Sleuth Kit
(3) mft2csv
(4) analyzeMFT (https://github.com/dkovar/analyzeMFT)
(5) plaso
- https://github.com/log2timeline/plaso
- https://github.com/log2timeline/plaso/wiki/Dependencies-Mac-OS-X#pyparsing
DO THE FOLLOWING !!!!
Remove an outdated version of pyparsing distributed by Max OS X:
"sudo rm /System/Library/Frameworks/Python.framework/Versions/2.7/Extras/lib/python/pyparsing*"
(7) volatility mftparser ( http://volatility-labs.blogspot.sg/2013/05/movp-ii-24-reconstructing-master-file.html )
- Timestamp ( http://www.epochconverter.com/ )
No comments:
Post a Comment