macOS Forensics Mcp Server

by x746b

337 downloads Not rated yet
GitHub

About

MCP (Model Context Protocol) server for macOS Digital Forensics and Incident Response (DFIR).

Explore

- Structured queries instead of raw text searches
- Automatic timestamp normalization (Mac Absolute Time → UTC)
- Pre-built security event detection patterns
- Cross-artifact correlation and timeline building
- Pagination to prevent context overflow
- Artifact discovery to determine available data

Setting up with Highlight

This MCP is not yet compatible with Highlight’s one-click setup. However, you can still use it with Highlight by following these steps:

  1. Download and install Highlight from highlightai.com/download
  2. Navigate to the plugins tab and select "Add Custom Plugin"
  3. Configure the plugin with the settings below
    Plugin Name macOS Forensics Mcp Server
    Command (node, npx, python, etc.)

    Please refer to the README for specific instructions on how to obtain API keys or other required environment variables.

  4. Enable "Start Automatically" if you want the plugin to start when Highlight launches

From the repository

``bash
cd /opt/macOS/mac_forensics-mcp

uv venv
uv pip install -e .


Add to
~/.claude/settings.json (user-level) or .claude/settings.json (project-level):

json
{
"mcpServers": {
"mac-forensics": {
"command": "/opt/macOS/mac_forensics-mcp/.venv/bin/python",
"args": ["-m", "mac_forensics_mcp.server"],
"env": {}
}
}
}
``

MAC_FORENSICS_UNIFIEDLOG_ITERATOR_PATH

`/opt/macOS/unifiedlog_iterator`

MAC_FORENSICS_FSEPARSER_PATH

`/opt/macOS/FSEventsParser/FSEParser_V4.1.py`

MAC_FORENSICS_SPOTLIGHT_PARSER_PATH

`/opt/macOS/spotlight_parser/spotlight_parser.py`

External forensic tools can be configured via environment variables. If not set, defaults to /opt/macOS/ paths.

| Environment Variable | Default | Description |
|---------------------|---------|-------------|
| MAC_FORENSICS_UNIFIEDLOG_ITERATOR_PATH | /opt/macOS/unifiedlog_iterator | Path to unifiedlog_iterator binary |
| MAC_FORENSICS_FSEPARSER_PATH | /opt/macOS/FSEventsParser/FSEParser_V4.1.py | Path to FSEParser script |
| MAC_FORENSICS_SPOTLIGHT_PARSER_PATH | /opt/macOS/spotlight_parser/spotlight_parser.py | Path to spotlight_parser script |

Example with custom paths:

``json
{
"mcpServers": {
"mac-forensics": {
"command": "/opt/macOS/mac_forensics-mcp/.venv/bin/python",
"args": ["-m", "mac_forensics_mcp.server"],
"env": {
"MAC_FORENSICS_UNIFIEDLOG_ITERATOR_PATH": "/custom/path/unifiedlog_iterator",
"MAC_FORENSICS_FSEPARSER_PATH": "/custom/path/FSEParser.py",
"MAC_FORENSICS_SPOTLIGHT_PARSER_PATH": "/custom/path/spotlight_parser.py"
}
}
}
}
``

Claude Desktop / Cursor

Paste into your MCP client config file to install this server.

{
    "mcpServers": {
        "macos forensics mcp server": {
            "mac-forensics": {
                "command": "/opt/mac_forensics-mcp/.venv/bin/python",
                "args": [
                    "-m",
                    "mac_forensics_mcp.server"
                ],
                "env": []
            }
        }
    }
}

McpServers

{
    "mac-forensics": {
        "command": "/opt/mac_forensics-mcp/.venv/bin/python",
        "args": [
            "-m",
            "mac_forensics_mcp.server"
        ],
        "env": []
    }
}
MCP (Model Context Protocol) server for macOS Digital Forensics and Incident Response (DFIR).

Overview

This MCP server provides structured forensic analysis tools for macOS triage collections, reducing context overhead when investigating incidents with LLMs. Key Benefits: - Structured queries instead of raw grep through massive files - Automatic timestamp normalization (Mac Absolute Time → UTC) - Pre-built security event detection patterns - Cross-artifact correlation and timeline building - Pagination to avoid context overflow - Artifact discovery to know what's available 23 tools covering: Unified Logs, FSEvents, Spotlight, Plists, SQLite databases, Extended Attributes, System Logs, and more.

Installation

```bash cd /opt/macOS/mac_forensics-mcp
No reviews yet — be the first

Sign in to leave a review

Use Google, GitHub, or an email account so ratings stay tied to real people.

Email sign in

No reviews posted yet.