Get started
Community vs Pro
Two binaries, one architecture. Pick the right one for the engagement.
What's the same
- The core orchestrator, evidence container format, and chain-of-custody log.
- The plugin interface, manifest schema, and source abstraction (live + image).
- CLI surface and exit codes.
macforandmacfor-proare flag-compatible.
Community (2 plugins)
The open-source macfor binary is meant as a working reference: a small, high-value plugin set that exercises every subsystem (text parsers, SQLite, plist, multi-user collection, the full evidence container).
- Safari Browser —
browser.safari - Shell History —
shell.history
Pro (29 plugins)
macfor-pro bundles every community plugin plus the full investigative collection — messaging apps, system telemetry, forensic deep-dives, and binary-format parsers (LevelDB, SQLCipher, SEGB, JSONLZ4, tracev3, …).
Apple Mail
mail.appleApple Notes
notes.appleBluetooth Devices
devices.bluetoothCalendar & Reminders
pim.calendarContacts (AddressBook)
contacts.addressbookCoreAnalytics
system.coreanalyticsDiscord
app.discordDropbox
cloudstorage.dropboxEvernote
productivity.evernoteFacebook Messenger Desktop
messaging.fbmessengerFaceTime
facetime.appleFirefox Browser
browser.firefoxFSEvents Journal
filesystem.fseventsGoogle Chrome Browser
browser.chromeKeychain Metadata
system.keychainMessages (iMessage/SMS/RCS)
messages.applePattern of Life
system.patternoflifePersistence Mechanisms
system.persistenceQuarantine Events
system.quarantineQuick Look Thumbnails
system.quicklookScreen Time
system.screentimeSignal Desktop
messaging.signalSlack Desktop
communication.slackSpotlight Metadata
system.spotlightTCC Database
system.tccTelegram Desktop
messaging.telegramUnified Logs
system.unifiedlogsWhatsApp Desktop
messaging.whatsappWiFi Known Networks
network.wifiPicking a binary
- Triage / IR scoping. Either works. Community is enough if you only need shell history and Safari context.
- Full investigation. Pro. You will want messaging (Signal, Messages, WhatsApp, Telegram, Slack, Discord), TCC, persistence, FSEvents, Unified Logs, and pattern-of-life.
- Air-gapped enterprise. Pro. License activation supports offline mode; contact macfor.io for procurement.
Pricing and licensing live on macfor.io/pricing.