Skip to content
KitploitKITPLOIT
도구익스플로잇블로그
Log in
제출
도구익스플로잇블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

··피드·문의·개인정보·© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
ma2tl — mac_apt의 분석 결과 DB를 사용하는 macOS 포렌식 타임라인 생성기 | Kitploit
도구/GitHubGitHub/mnrkbys/ma2tl
ForensicsDigital Forensics
GitHubmnrkbys/ma2tl

ma2tl

mac_apt의 분석 결과 DB를 사용하는 macOS 포렌식 타임라인 생성기

저장소 보기
957133년 전Kitploit 검토 완료

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
공유

ma2tl (mac_apt에서 타임라인으로)

이것은 mac_apt의 분석 결과 DB에서 macOS 포렌식 타임라인을 생성하는 DFIR 도구입니다.

요구 사항

  • Python 3.7.0 이상
  • pytz
  • tzlocal
  • xlsxwriter

설치

% git clone https://github.com/mnrkbys/ma2tl.git

사용법

% python ./ma2tl.py -h
usage: ma2tl.py [-h] [-i INPUT] [-o OUTPUT] [-ot OUTPUT_TYPE] [-s START] [-e END] [-t TIMEZONE] [-l LOG_LEVEL] plugin [plugin ...]

Forensic timeline generator using mac_apt analysis results. Supports only SQLite DBs.

positional arguments:
  plugin                Plugins to run (space separated).

optional arguments:
  -h, --help            show this help message and exit
  -i INPUT, --input INPUT
                        Path to a folder that contains mac_apt DBs.
  -o OUTPUT, --output OUTPUT
                        Path to a folder to save ma2tl result.
  -ot OUTPUT_TYPE, --output_type OUTPUT_TYPE
                        Specify the output file type: SQLITE, XLSX, TSV (Default: SQLITE)
  -s START, --start START
                        Specify start timestamp. (ex. 2021-11-05 08:30:00)
  -e END, --end END     Specify end timestamp.
  -t TIMEZONE, --timezone TIMEZONE
                        Specify Timezone: "UTC", "Asia/Tokyo", "US/Eastern", etc (Default: System Local Timezone)
  -l LOG_LEVEL, --log_level LOG_LEVEL
                        Specify log level: INFO, DEBUG, WARNING, ERROR, CRITICAL (Default: INFO)

The following 4 plugins are available:
    FILE_DOWNLOAD       Extract file download activities.
    PERSISTENCE         Extract persistence settings.
    PROG_EXEC           Extract program execution activities.
    VOLUME_MOUNT        Extract volume mount/unmount activities.
    ----------------------------------------------------------------------------
    ALL                 Run all plugins

생성된 타임라인 예시

시나리오 타임라인

참고 사항

안타깝게도 최신 버전의 mac_apt는 Unified Logs 파일을 올바르게 구문 분석할 수 없습니다. 따라서 helper tools에서 생성한 데이터베이스로 UnifiedLogs.db를 교체해야 합니다.

발표

이 도구는 Japan Security Analyst Conference 2022 (JSAC2022)에서 발표되었습니다.

슬라이드는 아래에서 확인할 수 있습니다:

  • 일본어 버전
  • 영어 버전

작성자

Minoru Kobayashi

라이선스

MIT

도구 다운로드