Repository navigation
Support for Mac artefact filetypes #175
Description
Activity
Thre is nothing preventing Chainsaw from supporting Mac logs it is just that no one has added the file parsers to Chainsaw to handle them. Currently Chainsaw supports:
- esedb
- hve
- evtx
- json
- mft
- xml
To handle Mac artefacts it would probably need parsers for plist, bplist, sqlite, unifiedlogs. Depending on what Mac artefacts are to be consumed.
- addedenhancementNew feature or requestNew feature or requestgood first issueGood for newcomersGood for newcomers
on Aug 19, 2024 - added a commit that references this issue
on Aug 19, 2024 ^ Ignore the above commit, I linked the wrong issue.
Hi @alexkornitzer, looking at this with fresh eyes given your earlier scoping comment (plist, bplist, sqlite, unifiedlogs).
Each of those is pretty different in scope. plist (XML + binary, via the
plistcrate) feels like a long weekend's work, sqlite is a few days once a generic table-row container exists, and unifiedlogs is its own multi-week project. So this issue as a whole is umbrella-shaped, not a single PR.Would you be open to splitting it into per-format tickets so the
good first issuelabel can sit on a genuinely small one? Happy to take a stab at plist first if you'd like, since it covers a useful slice of macOS persistence on its own (LaunchAgents, LoginItems, plist-based services).Sure, feel free to create issues that link to this issue, so let me kill off the GFI label and you can create any issues you want for things you wish to work on. So maybe just make a
plistissue to start if that is what you would like to work on next?
I appreciate that chainsaw was written to support evtx files, but is there any way to also support Mac logs too? Or has anyone ever run across a tool like chainsaw for Mac?