소개
This tool serves as an MCP server designed to streamline macOS Digital Forensics and Incident Response (DFIR) investigations. It offers structured forensic analysis capabilities for macOS triage collections, significantly reducing the contextual overhead typically encountered when using large language models (LLMs). With 23 specialized tools, it facilitates the analysis of Unified Logs, FSEvents, Spotlight, Plists, SQLite databases, Extended Attributes, and System Logs, enhancing the speed and accuracy of incident investigations.