-
Notifications
You must be signed in to change notification settings - Fork 91
Open
Description
We need a parser for the Apple Unified Logs.
Mandiant already built one in Rust: https://github.com/mandiant/macos-UnifiedLogs. It looks like this will be bigger parser. Not sure how big and if we should implement this as a seperate dissect.unifiedlog or more like the Windows scheduled task plugin.
More reading:
https://cloud.google.com/blog/topics/threat-intelligence/reviewing-macos-unified-logs/
https://github.com/libyal/dtformats/blob/main/documentation/Apple%20Unified%20Logging%20and%20Activity%20Tracing%20formats.asciidoc
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
No labels