macOS Triage Analysis — SIFT Workstation Runbook

Community

Reconstruct macOS activity fast with artifacts.

Authorrjonhaas
Version1.0.0
Installs0

System Documentation

What problem does it solve?

This runbook reduces the time and uncertainty of macOS DFIR triage by guiding analysts through consistent artifact-only collection triage and timeline reconstruction from a macOS triage package.

Core Features & Use Cases

  • Artifact-first parsing with mac_apt: Use mac_apt artifact-only plugins to extract structured evidence such as browser history, downloads, quarantine events, persistence locations, TCC permissions, and application activity from a live-collected triage directory.
  • Unified Log reconstruction: Parse macOS Unified Log archives into JSONL and use targeted searches to determine whether specific app launches succeeded or were blocked by security policy.
  • SQLite/CoreData timestamp normalization: Run focused SQLite queries against macOS databases (including correct CoreData epoch conversion) to produce analyst-ready CSV timelines.

Quick Start

Ask Claude Code to run the macOS triage runbook by opening the case directory and invoking the investigation flow for the macOS host so it can start phase 0 log parsing immediately and then extract high-value artifacts like Safari, TCC, quarantine events, and persistence.

Dependency Matrix

Required Modules

None required

Components

Standard package

💻 Claude Code Installation

Recommended: Let Claude install automatically. Simply copy and paste the text below to Claude Code.

Please help me install this Skill:
Name: macOS Triage Analysis — SIFT Workstation Runbook
Download link: https://github.com/rjonhaas/SIFTics/archive/main.zip#macos-triage-analysis-sift-workstation-runbook

Please download this .zip file, extract it, and install it in the .claude/skills/ directory.
View Source Repository

Agent Skills Search Helper

Install a tiny helper to your Agent, search and equip skill from 471,000+ vetted skills library on demand.