macOS forensic acquisition made simple
The main features of lazza/fuji are: Acquisition and Imaging, Data Acquisition.
Open-source alternatives to lazza/fuji include: ufrisk/pcileech — pcileech is a toolkit for executing DMA attacks, analyzing PCIe bus traffic, performing kernel patching, and… prosch88/ufade — Extract files from Apple devices on Windows, Linux and MacOS. Mostly a wrapper for pymobiledevice3. Creates… microsoft/avml — AVML - Acquire Volatile Memory for Linux. velocidex/velociraptor — Velociraptor is a digital forensics and incident response platform, endpoint detection and response system, and… forensicanalysis/artifactcollector — 🧭 The artifactcollector is a customizable agent to collect forensic artifacts on any Windows, macOS or Linux system. silv3rhorn/artifactextractor — Extract common Windows artifacts from source images and VSCs.
pcileech is a toolkit for executing DMA attacks, analyzing PCIe bus traffic, performing kernel patching, and conducting remote volatile memory forensics. It functions as a hardware memory acquisition tool and a PCIe DMA attack framework designed to read and write remote system memory via direct hardware interfaces. The project provides capabilities for capturing and displaying raw transaction layer packets from the PCIe bus and mounting live RAM as local drives for analysis. It enables the modification of system memory signatures and the execution of shellcode or implants within the kernel wi
🧭 The artifactcollector is a customizable agent to collect forensic artifacts on any Windows, macOS or Linux system
Extract files from Apple devices on Windows, Linux and MacOS. Mostly a wrapper for pymobiledevice3. Creates iTunes-style backups and "advanced logical backups"