macOS Triage Analysis — SIFT Workstation Runbook
CommunityReconstruct macOS activity fast with artifacts.
Legal & Compliance#macos#incident response#artifact parsing#dfir triage#unified logs#tcc permissions#quarantine events
Authorrjonhaas
Version1.0.0
Installs0
System Documentation
What problem does it solve?
This runbook reduces the time and uncertainty of macOS DFIR triage by guiding analysts through consistent artifact-only collection triage and timeline reconstruction from a macOS triage package.
Core Features & Use Cases
- Artifact-first parsing with mac_apt: Use mac_apt artifact-only plugins to extract structured evidence such as browser history, downloads, quarantine events, persistence locations, TCC permissions, and application activity from a live-collected triage directory.
- Unified Log reconstruction: Parse macOS Unified Log archives into JSONL and use targeted searches to determine whether specific app launches succeeded or were blocked by security policy.
- SQLite/CoreData timestamp normalization: Run focused SQLite queries against macOS databases (including correct CoreData epoch conversion) to produce analyst-ready CSV timelines.
Quick Start
Ask Claude Code to run the macOS triage runbook by opening the case directory and invoking the investigation flow for the macOS host so it can start phase 0 log parsing immediately and then extract high-value artifacts like Safari, TCC, quarantine events, and persistence.
Dependency Matrix
Required Modules
None requiredComponents
Standard package💻 Claude Code Installation
Recommended: Let Claude install automatically. Simply copy and paste the text below to Claude Code.
Please help me install this Skill: Name: macOS Triage Analysis — SIFT Workstation Runbook Download link: https://github.com/rjonhaas/SIFTics/archive/main.zip#macos-triage-analysis-sift-workstation-runbook Please download this .zip file, extract it, and install it in the .claude/skills/ directory.
Agent Skills Search Helper
Install a tiny helper to your Agent, search and equip skill from 471,000+ vetted skills library on demand.