Skip to content

Commit 9b717ee

Browse files
committed
2026-03-16
1 parent 87fa585 commit 9b717ee

13 files changed

Lines changed: 5880 additions & 323 deletions

BTM-Analyzer.ps1

Lines changed: 34 additions & 34 deletions
Original file line numberDiff line numberDiff line change
@@ -4,7 +4,7 @@
44
# @copyright: Copyright (c) 2025 Martin Willing. All rights reserved. Licensed under the MIT license.
55
# @contact: Any feedback or suggestions are always welcome and much appreciated - mwilling@lethal-forensics.com
66
# @url: https://lethal-forensics.com/
7-
# @date: 2025-11-20
7+
# @date: 2026-03-16
88
#
99
#
1010
# ██╗ ███████╗████████╗██╗ ██╗ █████╗ ██╗ ███████╗ ██████╗ ██████╗ ███████╗███╗ ██╗███████╗██╗ ██████╗███████╗
@@ -28,7 +28,7 @@
2828
#
2929
#
3030
# Tested on Windows 10 Pro (x64) Version 22H2 (10.0.19045.6456) and PowerShell 5.1 (5.1.19041.6456)
31-
# Tested on Windows 10 Pro (x64) Version 22H2 (10.0.19045.6456) and PowerShell 7.5.4
31+
# Tested on Windows 10 Pro (x64) Version 22H2 (10.0.19045.6456) and PowerShell 7.5.5
3232
#
3333
#
3434
#############################################################################################################################################################################################
@@ -342,7 +342,7 @@ Write-Output "[Info] SHA256 Hash: $SHA256"
342342
$InputSize = Get-FileSize((Get-Item "$LogFile").Length)
343343
Write-Output "[Info] Total Input Size: $InputSize"
344344

345-
# Count rows of CSV (w/ thousands separators)
345+
# Count rows of TXT (w/ thousands separators)
346346
[int]$TotalLines = 0
347347
$Reader = New-Object IO.StreamReader "$LogFile"
348348
while($Reader.ReadLine() -ne $null){ $TotalLines++ }
@@ -367,9 +367,9 @@ ForEach ($Object in $Objects) {
367367
}
368368

369369
# User ID's (UID)
370-
# -2 = Appears to be a composite covering most Machgrount Items
371-
# 0 = root
372-
# 501 = primary admin user
370+
# -2 = Appears to be a composite covering most Background Items
371+
# 0 = Root
372+
# 501 = Primary Admin User
373373

374374
# List all UIDs
375375
# dscl . -list /Users UniqueID
@@ -588,8 +588,8 @@ Footer
588588
# SIG # Begin signature block
589589
# MIIrywYJKoZIhvcNAQcCoIIrvDCCK7gCAQExCzAJBgUrDgMCGgUAMGkGCisGAQQB
590590
# gjcCAQSgWzBZMDQGCisGAQQBgjcCAR4wJgIDAQAABBAfzDtgWUsITrck0sYpfvNR
591-
# AgEAAgEAAgEAAgEAAgEAMCEwCQYFKw4DAhoFAAQUOpZyU2AmLj6299THFqk4AN3P
592-
# Mv6ggiUEMIIFbzCCBFegAwIBAgIQSPyTtGBVlI02p8mKidaUFjANBgkqhkiG9w0B
591+
# AgEAAgEAAgEAAgEAAgEAMCEwCQYFKw4DAhoFAAQUeaXfYn6IjFEEB8gT4ibf9hi/
592+
# sdWggiUEMIIFbzCCBFegAwIBAgIQSPyTtGBVlI02p8mKidaUFjANBgkqhkiG9w0B
593593
# AQwFADB7MQswCQYDVQQGEwJHQjEbMBkGA1UECAwSR3JlYXRlciBNYW5jaGVzdGVy
594594
# MRAwDgYDVQQHDAdTYWxmb3JkMRowGAYDVQQKDBFDb21vZG8gQ0EgTGltaXRlZDEh
595595
# MB8GA1UEAwwYQUFBIENlcnRpZmljYXRlIFNlcnZpY2VzMB4XDTIxMDUyNTAwMDAw
@@ -791,33 +791,33 @@ Footer
791791
# Z28gUHVibGljIENvZGUgU2lnbmluZyBDQSBSMzYCEQCMQZ6TvyvOrIgGKDt2Gb08
792792
# MAkGBSsOAwIaBQCgeDAYBgorBgEEAYI3AgEMMQowCKACgAChAoAAMBkGCSqGSIb3
793793
# DQEJAzEMBgorBgEEAYI3AgEEMBwGCisGAQQBgjcCAQsxDjAMBgorBgEEAYI3AgEV
794-
# MCMGCSqGSIb3DQEJBDEWBBRj3baSlfpetKAlhOmmn5D0lLt+3jANBgkqhkiG9w0B
795-
# AQEFAASCAgAIMzJbj6ZweU6PRfKHCady2ptfDQvVOl0ZjAacisRBR+hetgcMX40u
796-
# C4PJBmUei/VXI4w8BbDd6CE0zqlVV3kJfoN8xbyEbK9aAi3q6+yhEISLUWoFk2s9
797-
# QrjjMP6+jpSMpid0QRXmAlKRTms48bGjzdBsWy4d4IjQS22tFXr2pjaqCPp0F+DN
798-
# 8tRPU2tWwmmINDcg9A2MxVrioKUZ2g/YSdIXRkuFh08iVLvySDkcaDyqHPgoPL2G
799-
# 1c/63VYhFnyVx6OviBxCK+Q4G2iZGacBX3UScZSwiL0WsW/A1hvTg21gFlvc1qTP
800-
# VW/CmKf4tTPKKH23LSG1RUGY+AWxFkvYBoldkZ1LJl5Z9njmR362inisNjCbk1bY
801-
# XaEvpuEQA1sOllpVq0tEC1c7BhKZnotX8+YN722RX+rS6iFwhY+2McQKrZGgBjOh
802-
# lN5WR5yG8faBvM/qp4QSLzJI6OcT0/zjQX335uizEvgd0suBmU0gYd7CJxh0fJsf
803-
# Iac2uTgQkNNwnoPaqFw7j5Va2960BVtpvO5C+/mF31kEgKMESkHC9LRaSP1/L1+D
804-
# TdfL3/IjupdLWkpNPtzZS08lrKjbEskWYC2uXO+swjnENIyonpSDI4S5U4Tgq2xg
805-
# Ah0EBy1o3Q1MROgZmNw/astxosEwnHud6wTcSCy24g/8Rk6Py9WCsaGCAyMwggMf
794+
# MCMGCSqGSIb3DQEJBDEWBBS+txLCjf7/xTkouF4j0dLGvCUXyzANBgkqhkiG9w0B
795+
# AQEFAASCAgB79BbH6eB1xjCfGmeDb5FSmbItakPMHqeIjtNQI1vji3qCj8GId5Eo
796+
# +YoXhGGVaVfB6c+TdScqUpkLCYU0XqgHPZzjbI9X91LhiPBh1P6BBW3Gx34FqVCs
797+
# OqyOKy/nGjbSaPB0Hl7LxuGUTcgxJmDFYjTdZMtzAycyzwGhq5wfHm7ssTUK2xKs
798+
# uhAItkBwjb1nYB5gW6GHWOdK1kZBkIaYXq3nauSCgTXHqxjLHFi2lte1BB9YvBGZ
799+
# v6kTz4qM8a8KBv0x5QQ3WMI2sWqOuRVkgc9ZNQh5REgAVgllhtezAppCMDBan0L4
800+
# pyL7S47K3G9MKMDbSmbz93B4IL0oRbHpp6z5+NWsHCoZuJlscuDe4ByLFMwTmTzw
801+
# pHJla5ycTZTg+bCLtatO2IAmHYim4A7WLoSGySbYuu7QgRpXrfyEQhOWeFPiVYa9
802+
# wnKoJj3G5Emd2766Lod8GQsHGj2YuLgrbHTQ5IP8zSONV13XHFLXTCIWWt3YSJi6
803+
# kWRZ71+2gd3Z8PrHQs5oCwVicpA5UQCO8JaBwlu0dO+XLnk2NtN2W5yDwhECR2xv
804+
# ZzsU11uyvBGpndiVuigi0PmbbV+fjcUqWWqcPfWlLdWrGD5iCfY8tI6HVkvU3G3s
805+
# 7CZ/3aaBBSzX6QJT85BjI1Zj33yB1Si7Ta/GuNFoc4APzwJyGFhS0KGCAyMwggMf
806806
# BgkqhkiG9w0BCQYxggMQMIIDDAIBATBqMFUxCzAJBgNVBAYTAkdCMRgwFgYDVQQK
807807
# Ew9TZWN0aWdvIExpbWl0ZWQxLDAqBgNVBAMTI1NlY3RpZ28gUHVibGljIFRpbWUg
808808
# U3RhbXBpbmcgQ0EgUjM2AhEApCk7bh7d16c0CIetek63JDANBglghkgBZQMEAgIF
809-
# AKB5MBgGCSqGSIb3DQEJAzELBgkqhkiG9w0BBwEwHAYJKoZIhvcNAQkFMQ8XDTI1
810-
# MTEyMDA2NTgzNFowPwYJKoZIhvcNAQkEMTIEMIrf3XLNVAUG2kct9US1UXLohH7R
811-
# UPhIrZijiPcCpGkP8uNbja9ZOp24j9Ivg0+RvDANBgkqhkiG9w0BAQEFAASCAgDE
812-
# V2TkyhF5OkB4N0i8ZW8okqH5nTCVszwOYhpAjm9LYAQ5jHnTlYvMFsvVF4r97txT
813-
# MtROjmlQ3+Y2/vq5HnmKcaKLuCaH6klz12mVEe8dZjsjBv9MduGNwov3g6LYnxWS
814-
# /92CVjt7HHraon+DLRWsc/j0IVWVSI9GzxKF4Vjd4OtA+1aYkL/kWbYr738Fxbpr
815-
# x1cwLR9esBTsLad5eiYmwBHz3Ok4HGUBWi7sF/Q4HuVneNZiQtWLRLpa0GOpaVK6
816-
# j+VFqe8fNal/X7f8T7+NCyTMlCFh48bR10vDAZzOnmOskk7Vq6g5YzFQVZFlhqRp
817-
# vRViVrOcGwurWy0LX7y8JtZAaDgYBfLOzyfN3BFZt1rWP0W1x8UNrUWtSl7+wqrv
818-
# +a42s8MaMVo2Rq6pB4TYiuo4KZYERIcvn3bladIThdGZKAnGBX/PvhhRAcZO0eB0
819-
# jNIJHIE4JrsFO+797wLXdCZv5tRtdStJy53k3/SCgkUhbgLidEGCtSe1pCydAS1V
820-
# 6vmosTbdICamH63pQv3cv4q8uO/HybUz0nxVScNI63eTl5mJDVs4DWMh7FLlTE4L
821-
# ae/GAHKR/kWAOz+Vj0OBzRMg6o5D+KGgArHcSDBg7eeixHdmbiJEmOe5KdKBgFUv
822-
# A6MLTQx9Ji32lMl6PDJ1DxVQ6jH/lq9SixTwZR+8YQ==
809+
# AKB5MBgGCSqGSIb3DQEJAzELBgkqhkiG9w0BBwEwHAYJKoZIhvcNAQkFMQ8XDTI2
810+
# MDMxNjA2NDQ1NFowPwYJKoZIhvcNAQkEMTIEMOGdnsWwhLxaeXThoy/6alNbbsnf
811+
# PDFGXa+6xj0NMBN4e7c8hTVJZyuHglibRp2pyjANBgkqhkiG9w0BAQEFAASCAgBm
812+
# 9+SG0SHlaOcv7TPgLO9JtEwjfanuAY5W72BBohhM9GvLVqTtPMgAS9I9HLIWmb58
813+
# NGBb+zpQs4UbOZcuY9bohM+JuOttBxjt8/720cPBODMR0HMdE466Vno4CDixRQgA
814+
# HTAYhY2kfSBtz3xBLRNxlk/xMyjEMGzo2tvcnu9QzLZLyNTea+nxDSyJtj1KeQbe
815+
# 66uCMzv0ajHSNq38EK9w+6M+aPkKNsk8GY3XInJ3mAaMaFro64eO7rks6xfDHNQi
816+
# mB16XHoQZTZxVTA6rIuHbCR+UhVRhx5k8/vgr35iMBeFYDxU+OwRBaeMSXjduwAL
817+
# yiJYlQMeEHhqg2Mp0vWukfQ8G4qLlhOthQovC2qOHDUZMI/+exQRIqNYVZcY/RJ4
818+
# 76ZYQPuwC1bJaog8oTBgn+Io5LNGHHZuz0gB/4CHYeqzlSMDAEZZBlPLu0e9LyVY
819+
# /qxvXECuns3a1cdd5/J4r8LsY/MD6T7rPJbKm+sya7Du/6/JXWX1ISrNIz71le20
820+
# +JnERjhP2hxDU7jazSnqVusDnCXDued3QmISesvWahlFTgVAd7kXI2v9IY1bDZL/
821+
# zj7Ls/R/yck/y3C4tEvq4SfVilw64lKm2fbFwwtLuU+qBB1dt42LUSLnMfzB81xO
822+
# T3dxWkqlMtR8aH5U9barGvXi31r+ACoCsKYFLGvM4Q==
823823
# SIG # End signature block

CHANGELOG.md

Lines changed: 10 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -2,14 +2,22 @@
22

33
All changes to the MacOS-Analyzer-Suite will be documented in this file.
44

5+
## [1.2.0] - 2026-03-16
6+
### Added
7+
- KnockKnock-Analyzer
8+
- VirusTotal-Analyzer
9+
10+
### Fixed
11+
- Minor fixes and improvements
12+
513
## [1.1.0] - 2025-11-20
614
### Added
715
- BTM-Analyzer
816
- DSStore-Analyzer
917
- Storyline-Analyzer (Aftermath)
1018
- Timeline-Analyzer (Aftermath)
1119

12-
## Fixed
20+
### Fixed
1321
- Minor fixes and improvements
1422

1523
## [1.0.0] - 2025-11-10
@@ -19,5 +27,5 @@ All changes to the MacOS-Analyzer-Suite will be documented in this file.
1927
- TCC-Analyzer
2028
- XProtect-Analyzer
2129

22-
## Changed
30+
### Changed
2331
- CHANGELOG.md

Config.json

Lines changed: 8 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -7,5 +7,13 @@
77
"BackgroundColor": "50,60,220",
88
"FontColor": "White"
99
}
10+
],
11+
"VirusTotal": [
12+
{
13+
"Name": "VirusTotal CLI - API Key",
14+
"URL": "https://www.virustotal.com/#/join-us --> Join the community for free",
15+
"Note": "Please insert your API Key here (Default: api_key)",
16+
"APIKey": "api_key"
17+
}
1018
]
1119
}

DSStore-Analyzer.ps1

Lines changed: 33 additions & 33 deletions
Original file line numberDiff line numberDiff line change
@@ -1,10 +1,10 @@
11
# DSStore-Analyzer v0.1
22
#
33
# @author: Martin Willing
4-
# @copyright: Copyright (c) 2025 Martin Willing. All rights reserved. Licensed under the MIT license.
4+
# @copyright: Copyright (c) 2026 Martin Willing. All rights reserved. Licensed under the MIT license.
55
# @contact: Any feedback or suggestions are always welcome and much appreciated - mwilling@lethal-forensics.com
66
# @url: https://lethal-forensics.com/
7-
# @date: 2025-11-20
7+
# @date: 2026-03-16
88
#
99
#
1010
# ██╗ ███████╗████████╗██╗ ██╗ █████╗ ██╗ ███████╗ ██████╗ ██████╗ ███████╗███╗ ██╗███████╗██╗ ██████╗███████╗
@@ -37,7 +37,7 @@
3737
#
3838
#
3939
# Tested on Windows 10 Pro (x64) Version 22H2 (10.0.19045.6456) and PowerShell 5.1 (5.1.19041.6456)
40-
# Tested on Windows 10 Pro (x64) Version 22H2 (10.0.19045.6456) and PowerShell 7.5.4
40+
# Tested on Windows 10 Pro (x64) Version 22H2 (10.0.19045.6456) and PowerShell 7.5.5
4141
#
4242
#
4343
#############################################################################################################################################################################################
@@ -55,7 +55,7 @@
5555
5656
Note: The subdirectory 'DSStore-Analyzer' is automatically created.
5757
58-
.PARAMETER Path
58+
.PARAMETER InputDir
5959
Specifies the path to the input directory.
6060
6161
.EXAMPLE
@@ -303,7 +303,7 @@ Write-Output ""
303303

304304
# Header
305305
Write-Output "DSStore-Analyzer v0.1 - Automated Forensic Analysis of DS_Store Files for DFIR"
306-
Write-Output "(c) 2025 Martin Willing at Lethal-Forensics (https://lethal-forensics.com/)"
306+
Write-Output "(c) 2026 Martin Willing at Lethal-Forensics (https://lethal-forensics.com/)"
307307
Write-Output ""
308308

309309
# Analysis date (ISO 8601)
@@ -684,8 +684,8 @@ Footer
684684
# SIG # Begin signature block
685685
# MIIrywYJKoZIhvcNAQcCoIIrvDCCK7gCAQExCzAJBgUrDgMCGgUAMGkGCisGAQQB
686686
# gjcCAQSgWzBZMDQGCisGAQQBgjcCAR4wJgIDAQAABBAfzDtgWUsITrck0sYpfvNR
687-
# AgEAAgEAAgEAAgEAAgEAMCEwCQYFKw4DAhoFAAQUV5dMx0Qv8fEKEUYmERscuIwG
688-
# HTCggiUEMIIFbzCCBFegAwIBAgIQSPyTtGBVlI02p8mKidaUFjANBgkqhkiG9w0B
687+
# AgEAAgEAAgEAAgEAAgEAMCEwCQYFKw4DAhoFAAQUVvbi0VEnzktMWa6kF9LbjC1N
688+
# dqaggiUEMIIFbzCCBFegAwIBAgIQSPyTtGBVlI02p8mKidaUFjANBgkqhkiG9w0B
689689
# AQwFADB7MQswCQYDVQQGEwJHQjEbMBkGA1UECAwSR3JlYXRlciBNYW5jaGVzdGVy
690690
# MRAwDgYDVQQHDAdTYWxmb3JkMRowGAYDVQQKDBFDb21vZG8gQ0EgTGltaXRlZDEh
691691
# MB8GA1UEAwwYQUFBIENlcnRpZmljYXRlIFNlcnZpY2VzMB4XDTIxMDUyNTAwMDAw
@@ -887,33 +887,33 @@ Footer
887887
# Z28gUHVibGljIENvZGUgU2lnbmluZyBDQSBSMzYCEQCMQZ6TvyvOrIgGKDt2Gb08
888888
# MAkGBSsOAwIaBQCgeDAYBgorBgEEAYI3AgEMMQowCKACgAChAoAAMBkGCSqGSIb3
889889
# DQEJAzEMBgorBgEEAYI3AgEEMBwGCisGAQQBgjcCAQsxDjAMBgorBgEEAYI3AgEV
890-
# MCMGCSqGSIb3DQEJBDEWBBRsCJ31zbVsE8L82l/TvVNZplrKMzANBgkqhkiG9w0B
891-
# AQEFAASCAgC8A0T26eVqKZGDdIVhXop86GPwuzWMwcnpVicCGLO6aI5MU15cz4C2
892-
# 3SQmfAthoW2Phjwg/HtQkaQVfB+QmyDxK+w+Ihnl0s3AiCKx4LPx4JkzuElQHooL
893-
# uuOo2C98Htkt9skQY3deojo5VHsC483QUtMQUMI8W9LmzYDVLOgKVgGM5NZcpjyG
894-
# eaqYCbUgAk6wDqg6mDwc24BEbyRIqQh09BrASR5Sbx2xLcjvKw1iGKtWYo13LoJZ
895-
# PpWK9PTRbXfFjUL89tkZjJo82aazQoCPL4LR50JguuY/MskSjqyJGW4lSME+6jVA
896-
# rKtD+MRv8cJpJeljhjcsEypNJWpOe9fQVAoUX/hlMhGv3oPJ18eh1r0E4ZOR88fz
897-
# 9HyfW1nrmN3/NwITnD+Fv8avL8sODMsmV3csaiCQRoEkn+xZdL0D241zO2y7UcyE
898-
# 9xO9ryQhdE5mPembD5RfXAMcGMWK4HYOYS5YzRmt5YYT3EwyWZU4QTpz+dtJvJc5
899-
# G9Ah4/AQhEBOqAVBgUQZB39oiANfsBIuaBIBubaXBCW5G00e7XHG5/e0waQ7Jwcg
900-
# JBvuSQV56iqiJPlTZ7tI3dY2KlfTWyWXzySC7oTKh1cvSkIeuL105lVjfgUD/IOT
901-
# DiVrLK+PP/6iLMKlJVA/+UxZ79gbxMEm+XeM+3186/8Y3gKyXGdIrKGCAyMwggMf
890+
# MCMGCSqGSIb3DQEJBDEWBBTRGF2kdz6eE5jx9XjyeuCcq6AL3jANBgkqhkiG9w0B
891+
# AQEFAASCAgAmLh2ixje5Ssqr5iuUdQFMPiGPj64kDoXrKZrs1hLGalidHvDLLzRp
892+
# Bjr7Koo8VlnV6eItjQzsDrROngfib5KveJnSykQDOL1RJ3UenpgDSXu/X7IXrcAq
893+
# vS9k8gnbh7Vuu6BfvQo5USEBKgFRcGcIQVvwEMtFfO4Ka/YbT6t6t4fswhhKkOuR
894+
# AgFoJ3wvaZGbY4BDV+o2cGn1vttx7j2xBiM7grxEWlF4pQ/utMsNZOsanLvXCuC8
895+
# QAVL3M9z2qMrqVr1hB8D1sfFV62HjtP31OHlMioDYsJ18zLDmKTfuGDmpb/b/eN0
896+
# KK9RJx7hk1WtlMGPyLUC6rl2WxfeygUV8C8GHlgVZloLmsi6+0NYbmCSc9uicMtL
897+
# XH1+4OiLU2gYhtt8VnX6ry2eIiOfE8cmf3RxRtxyhA3x0KJDp6pjYEUzr01hy3aO
898+
# CvaWMZlQlbDB1ZLqsU8gNzFwcswATP9ONPNlYWW+BJoWTPBt9lpmmN5PhtFluYyU
899+
# LtTA8XiTBU+E08NoxwubqXwMqIc3nAqU/01R6Av6RoHN/DEKUhUKrwwjRn0OlMDM
900+
# TR63LNkFykM2L+POxIfYewwWrkYb5pFsoBWNOWcTW8T4X/088oH0xklzp44SYlxc
901+
# iohe+9LcJDQq8FHmk0OZXSZxZLcZRw8l79WYJj9IBLH4B6NqsMU1laGCAyMwggMf
902902
# BgkqhkiG9w0BCQYxggMQMIIDDAIBATBqMFUxCzAJBgNVBAYTAkdCMRgwFgYDVQQK
903903
# Ew9TZWN0aWdvIExpbWl0ZWQxLDAqBgNVBAMTI1NlY3RpZ28gUHVibGljIFRpbWUg
904904
# U3RhbXBpbmcgQ0EgUjM2AhEApCk7bh7d16c0CIetek63JDANBglghkgBZQMEAgIF
905-
# AKB5MBgGCSqGSIb3DQEJAzELBgkqhkiG9w0BBwEwHAYJKoZIhvcNAQkFMQ8XDTI1
906-
# MTEyMDA2MTcyN1owPwYJKoZIhvcNAQkEMTIEMNKPv9G0l6WYxfzUc/JDpSg7Ofpy
907-
# 3DWB9u2Lpqi1Q2wpJY8wjgRCVX7e/scgQywqhTANBgkqhkiG9w0BAQEFAASCAgBh
908-
# EQAYwVCnNJZKiFpvlfRYu/R6kRernh8i1iaRN49vEiYfa0+Qg6aR6vC+w0jOXISo
909-
# PihFpjV9wMaF8A3maNU8Vn8SufbJiQKieTOAEnEYfpemsDOfk5V4O1TuQfG10kEL
910-
# K/BuKqlUsmTUOjHegB+rb9akj54wBeFcl4I1bLkzyum/dNQ9XmSmiTYTos4wA2cO
911-
# TAY5X8R7iQM+UyfmpgOtwgt9WAPOtGLJKXMS28hLfIgSxx+P3RKcUAqNIq/bsYXV
912-
# 3RL+XBxxvpuQ3c1YwMSA00oVQItOgTmFIr2mxR3Vpl10eXQ6JP7u5lynLJZZDxxy
913-
# lTm66cj1h6tR7q0r9Z7jKyusR8eVbK7vX9ONELEnMk0iWy6a9sDHpTssTjq3gh6n
914-
# ZgxJhje1JyXmuflVmBulKbP4fP91HIHZYPLXWv72vw7EmmOZEWe5ZRvk0VJn2V3r
915-
# zNMeAdBmDEfdLQBxI6I4jHzT4gdjHnC21D7Amk4xAst/jRQZbaD3bitGJ19Uj4qO
916-
# N2ulSxA1QPJc0tArjC0mHRdKrRS3ZXfoIWvkPmxj1cSYFJ62TF8iEf2HJPIIEVCw
917-
# puiBbW1ADE1Os0kWahnAcxjRyEAvp7C6nHUB+Q3THLzWMo2gzaVJN+wfnc6/xoau
918-
# Hg3hD3EoQSlvIWupMlXcjYZyy5qPgREnLfmB1KZkFw==
905+
# AKB5MBgGCSqGSIb3DQEJAzELBgkqhkiG9w0BBwEwHAYJKoZIhvcNAQkFMQ8XDTI2
906+
# MDMxNjA2NDQ1N1owPwYJKoZIhvcNAQkEMTIEMDP3ZbIcI2JN42k3gnVxki+q9WbD
907+
# qYis5SplXdlu4zCwLAF8oFOEpWDtrxSe6lrVOzANBgkqhkiG9w0BAQEFAASCAgCs
908+
# YgAQRJj14XsfR256A0o3oXsDgOPTC7yYwd0nA7ZBaSzFNrS3XLj42GKie8MIehoN
909+
# moyvq45plIx3DzV+py3BSYOQYO8PFDRdDOWzYyJzTJ0yj0HzvvNaIPYwgHWxqLHz
910+
# /ox0JCrB/JSVgw0fpTqb8w+iXSeBA2hO1+mTgTfkM1BDhDYFR7KQ3w8jJGsn2CyG
911+
# axBQTOwLNTzkpcz5csgRMkUlRKsKFeFU86aIdOheAl8KKszNFKc2y506Gr8Guu16
912+
# 93hu7WRktGcPGNtHkPXyhK4hnl2YWQL291w/gzNDZtHwRIhBKb32pK5Sm6shlUc8
913+
# sLM5h4Fm37HavajGQ2uihgNvsq2/WNk0OGXDgQd0SF1xOJOp+Xf/xZwTgRR1QPJn
914+
# 3BrGR6Yah9IzAD4jstsLqeiWRDmORj4Lcm9riRu5ZUx/KRvwtjrNdAowSsAryT1G
915+
# /Cl7TmqghEoZ9S0Sahsepz470LzOvTx2VnZhPTCZxgpYrPzis//C45I4x/vyEFUb
916+
# Dx4VEH1p+gqX9fyJkhU7ydJkJpA2LwBuVdlXJQ2SkGjf8kx2oxoAiTesDtfXnvvI
917+
# TfugQSvNvviKxcdaKfqkLUYUqk5QmODcLO1y7TYBV2SAyJw1lUUau/9fxMwdN1pe
918+
# CeSNFjm6l7V2rrHVoPBN6+lOaQIrVLfibdMHVwfN2w==
919919
# SIG # End signature block

FSEvents-Analyzer.ps1

Lines changed: 32 additions & 32 deletions
Original file line numberDiff line numberDiff line change
@@ -1,10 +1,10 @@
11
# FSEvents-Analyzer v0.1
22
#
33
# @author: Martin Willing
4-
# @copyright: Copyright (c) 2025 Martin Willing. All rights reserved. Licensed under the MIT license.
4+
# @copyright: Copyright (c) 2026 Martin Willing. All rights reserved. Licensed under the MIT license.
55
# @contact: Any feedback or suggestions are always welcome and much appreciated - mwilling@lethal-forensics.com
66
# @url: https://lethal-forensics.com/
7-
# @date: 2025-11-20
7+
# @date: 2026-03-16
88
#
99
#
1010
# ██╗ ███████╗████████╗██╗ ██╗ █████╗ ██╗ ███████╗ ██████╗ ██████╗ ███████╗███╗ ██╗███████╗██╗ ██████╗███████╗
@@ -43,7 +43,7 @@
4343
#
4444
#
4545
# Tested on Windows 10 Pro (x64) Version 22H2 (10.0.19045.6456) and PowerShell 5.1 (5.1.19041.6456)
46-
# Tested on Windows 10 Pro (x64) Version 22H2 (10.0.19045.6456) and PowerShell 7.5.4
46+
# Tested on Windows 10 Pro (x64) Version 22H2 (10.0.19045.6456) and PowerShell 7.5.5
4747
#
4848
#
4949
#############################################################################################################################################################################################
@@ -314,7 +314,7 @@ Write-Output ""
314314

315315
# Header
316316
Write-Output "FSEvents-Analyzer v0.1 - Automated Forensic Analysis of FSEvents Logs for DFIR"
317-
Write-Output "(c) 2025 Martin Willing at Lethal-Forensics (https://lethal-forensics.com/)"
317+
Write-Output "(c) 2026 Martin Willing at Lethal-Forensics (https://lethal-forensics.com/)"
318318
Write-Output ""
319319

320320
# Analysis date (ISO 8601)
@@ -1392,8 +1392,8 @@ Footer
13921392
# SIG # Begin signature block
13931393
# MIIrywYJKoZIhvcNAQcCoIIrvDCCK7gCAQExCzAJBgUrDgMCGgUAMGkGCisGAQQB
13941394
# gjcCAQSgWzBZMDQGCisGAQQBgjcCAR4wJgIDAQAABBAfzDtgWUsITrck0sYpfvNR
1395-
# AgEAAgEAAgEAAgEAAgEAMCEwCQYFKw4DAhoFAAQUZni9NYhv1OlkbCzUKt5L0jcB
1396-
# SsyggiUEMIIFbzCCBFegAwIBAgIQSPyTtGBVlI02p8mKidaUFjANBgkqhkiG9w0B
1395+
# AgEAAgEAAgEAAgEAAgEAMCEwCQYFKw4DAhoFAAQUeCP4g4qpKiKnt34nmXpT4Uvn
1396+
# UdGggiUEMIIFbzCCBFegAwIBAgIQSPyTtGBVlI02p8mKidaUFjANBgkqhkiG9w0B
13971397
# AQwFADB7MQswCQYDVQQGEwJHQjEbMBkGA1UECAwSR3JlYXRlciBNYW5jaGVzdGVy
13981398
# MRAwDgYDVQQHDAdTYWxmb3JkMRowGAYDVQQKDBFDb21vZG8gQ0EgTGltaXRlZDEh
13991399
# MB8GA1UEAwwYQUFBIENlcnRpZmljYXRlIFNlcnZpY2VzMB4XDTIxMDUyNTAwMDAw
@@ -1595,33 +1595,33 @@ Footer
15951595
# Z28gUHVibGljIENvZGUgU2lnbmluZyBDQSBSMzYCEQCMQZ6TvyvOrIgGKDt2Gb08
15961596
# MAkGBSsOAwIaBQCgeDAYBgorBgEEAYI3AgEMMQowCKACgAChAoAAMBkGCSqGSIb3
15971597
# DQEJAzEMBgorBgEEAYI3AgEEMBwGCisGAQQBgjcCAQsxDjAMBgorBgEEAYI3AgEV
1598-
# MCMGCSqGSIb3DQEJBDEWBBRvmGdMO/4+uN1rth1HhPB+vGBCNzANBgkqhkiG9w0B
1599-
# AQEFAASCAgA++da0DVSikQBlMtvt5IPLxNkEcwLKe6EwCLLFKK/GDU2pOR6z8Yqn
1600-
# RzxDSKlDGxEAIghCmrFiz+7EFcw7ddmJC4GqbmCsfC6KpmDqY0RYs9VdPCWuAqq6
1601-
# 8AHgjWb2UyabVa02LYt/U50II2Z+bwGjw9B9W4myBPxOjhcHrEFN83asUNdYzQOa
1602-
# 1YbbOo/IUHYiaDci8UwAOaT6gXGQykgt/rTtHy3nFQGRfwkkxjTT+MpAf+NC4kqJ
1603-
# +4dcFVEUs+065PuU7lxrY1wNEgfwEmKAytiwAwp3yQli8ghRF95ZtegHb1INGocP
1604-
# 8aCJgGS82r/LjBsEREgGm1zQk9Bm66oeFPsrWLvuFSO3RBgjqOXJpAsuxHZNsWl1
1605-
# Fn1s7KeGyb4htuuVr6iDppffzXccUEuDILZcS/WztXURZlRm7vGqpPPMhx56wzJy
1606-
# UnQ/OhmFdFjUXqELpPIquZRoKzWpT+Ju+aqvdLZLMwE3nx9sp7nj7ID8vr97iqWR
1607-
# XvYLX+rO8K+3HBc4QQeyW2UOMIaaM0ztJeBMAuXJPRxAbnZjLKxLsiV7Zul56KEg
1608-
# ZREk/JR4wks8SAYxyTktGbD6ODgcyrsfn91bM1s+WVVkGnuauKBmh9CUUoLBxOAc
1609-
# jqWEwg30BPwUTqaSwjTCbxAkznCqHrSq24QweEZPmXLxzb0s4fWXOqGCAyMwggMf
1598+
# MCMGCSqGSIb3DQEJBDEWBBQwH3rAYkdtxcX23d/cCkTh/dQN+DANBgkqhkiG9w0B
1599+
# AQEFAASCAgAmzfqTTOqUSGv5Zd+HYTMoCRUOkTXp6MPSNneZWtIE6KKzB5QsmlW3
1600+
# CZF8QDzayuDHoEmTpYpiBw9xDpdwLQDXf07iaGPcm3otK7MS09qxO4ieSWXEBTKM
1601+
# uVH5CmIk3W1dIxSybON05dyIaKcsfCX4WRU3oj+qfD1ZOBDFnPO2vg8xZOWR8NJH
1602+
# p6Dq67P1euX/cr/o5U5yZNXCY45PnRX1md3Yg5/nYdIN6KGS2iF0p58SVSIg04De
1603+
# dyCKvdcEBc4Ptv4rb0S/R7F/rsMpnm0ZPifYrkWVQ0T9DFoUqoqvAnLtrFAvST/+
1604+
# Uj01FmGohkiaQj39Mf9AMNqGlMXGFsEjMvdAwGK59U7bKsxtfrQm+eNZgucI+c7I
1605+
# 17PtI71iWP8JyWF3v/no3w02qZbJLuqZzZ9suqc1guruhypYK5FVxXoatpdiRwN5
1606+
# NGzJzxEBZxpi9Lt6ECfSZMv2Uv4+958s0yXO95qtaAfxKsCzRk7lkpoDSU0bVg9C
1607+
# t3+Hph+3FLZt3KeJWWOKvOROZdXjaakV5NwEp43NA/4vb592/XuzzlcJygL0E6RR
1608+
# tSAJvUMPKGVcNN/06GZbT0SZguiTMlEvJdoBSxq9rAiFD6300IZyhlOAb7ovjE5c
1609+
# FRftXksAsIE/hVKgEK4RIjfpkabCsgG4sHUo4QvGBeDX1yZZ+BpZtaGCAyMwggMf
16101610
# BgkqhkiG9w0BCQYxggMQMIIDDAIBATBqMFUxCzAJBgNVBAYTAkdCMRgwFgYDVQQK
16111611
# Ew9TZWN0aWdvIExpbWl0ZWQxLDAqBgNVBAMTI1NlY3RpZ28gUHVibGljIFRpbWUg
16121612
# U3RhbXBpbmcgQ0EgUjM2AhEApCk7bh7d16c0CIetek63JDANBglghkgBZQMEAgIF
1613-
# AKB5MBgGCSqGSIb3DQEJAzELBgkqhkiG9w0BBwEwHAYJKoZIhvcNAQkFMQ8XDTI1
1614-
# MTEyMDA2MTczMFowPwYJKoZIhvcNAQkEMTIEMLYKzW7LjBZ0WZQ3lQF+tJZ8/7zt
1615-
# jXkDC2prFaqOHhTSK8Uk19xD6GihPfDa9RSQljANBgkqhkiG9w0BAQEFAASCAgAY
1616-
# lIjWc2GGjn2deq3KFO4TkoFWFiqPB7gZ5ytNTG2GSMVeVkqgZ9k+nJ6Qb6nq8wjL
1617-
# Pbr//y9ZvQ4vMDl1l4NTZ3gMtsnzxPpebcfOwSj0YvaLnXZhPmL053VKIns1z/7c
1618-
# JxhIP+o9zRLMFUf7GrLHsL/UYan/Lw0/47jCL+MZUDqWluTa7ZH9rWiMGceGhX2A
1619-
# 61KDk6Q+e1e9IwOdYN61A8cSfomKrLa4QuDqlF1UBi6rfYTJXFU0VVrQL9f9agBu
1620-
# OeR0haVtgkccoqsPTLG3jpiSk4zMY8peGXdzmueSn1wVo/ydhodR0Eu8PyvRgWkp
1621-
# kfoEX2dmuTEiLopj1ngQ3Dk6ag//uuU4mJhKGAfXPGJQ+84DcCVCnYWXVSRP9o/4
1622-
# vFBe6nEFgo0jjZwqdUbEff7ROQvFBcjt1GL6gvsEpzQi1/A79nmBPXaJVqddvJXB
1623-
# bDWuxPBcxkx6mcRRHyeElxKvfTLT+iOyb2Yjir8dkpJ+955c6Qzhs8Wp+/B4uM7z
1624-
# 1AeIx3VT6vhZi/fcuUbq+/Ojr9sPIwnARduamfgTvX4vj2OGybI9c9T+sjY37ehI
1625-
# ghUPOm5JvMlu3HfObfJNw9FFPVyMQ1D3TrDwKfHqsP3EqbTQO9Fc+kxwI8kCpIsp
1626-
# wpMZq99UoZgSD7XrN0XmDAUOib4qXUk6iZW6vyO3Ag==
1613+
# AKB5MBgGCSqGSIb3DQEJAzELBgkqhkiG9w0BBwEwHAYJKoZIhvcNAQkFMQ8XDTI2
1614+
# MDMxNjA2NDUwMVowPwYJKoZIhvcNAQkEMTIEMN06MXNY5cRdTlTD8L7oxCw2j2Te
1615+
# dZllJ0u5rPEhBS6/rVMGQaydWwjqJrPiA2+VLTANBgkqhkiG9w0BAQEFAASCAgAF
1616+
# BJ75Cmw2a5Qfu79/3++zaAozGNLoLiJ6tFHJFt29ZhkfwXkInpRNIbxZdjIkQlRZ
1617+
# +BR/w4FwkGuxE81d77bpE2XtGbMpzszT7xeJYy/K1ALUsGvWjjHaVpWrqTWmYzeC
1618+
# yhStQ6PobbOeZHTq0qjuqbT1t7sQZO8dUJJWrSY/wci3qutE4NR2UttM3XDVELPy
1619+
# WsVjg9/+5R7zJArDJEmTtYlzVT/2jkO4w+tm0vOpd3/f0MeWJHZqeKmrhhuDE9BO
1620+
# Jwvc9yl/7juV3rkRRih+TL+WY2dlGXt+HoC6ETofbLU7V8L427TI4aRya9U4myZ3
1621+
# 82To56kMiH6pVzwnJcpdckXSvZUBNblegYJUnUdrxcJ6kCgG+ReGw3EQirOTapYZ
1622+
# HzC2BlQ3aM1rdqOidud4Sf0eCDfVh46fiepGepBc8LEHwB9VOc9Sl4iDAF+/bp1T
1623+
# HRlpUSF6vZ0piIncGuBByycQbsOgEipzy9UCYrmOu0JqFFuDAQ3MQWutxx2G1l2X
1624+
# zEqiJJd/4nkGUebPI6/xYiVAflFFlw5VUSFsZL9Nm0LCr4274mhXVt/jhmQ5gqho
1625+
# 8nqCLwMeHIMAf4OXrAaqlwOlvERZ8X052DsJIv3DwC81SiwzA/haQZX1xFyuz4IH
1626+
# O3fZ0tBVesO3ZqGMO5aDkI8QFGwU27c3xYglli9ECA==
16271627
# SIG # End signature block

0 commit comments

Comments
 (0)