mac-robber
« Back to VersTracker
Description:
Digital investigation tool
Type: Formula  |  Tracked Since: Dec 28, 2025
Links: Homepage  |  formulae.brew.sh
Category: Security
Tags: forensics investigation hfs+ macos security
Install: brew install mac-robber
About:
MacRobber is a digital investigation tool designed to collect allocated file metadata from a Mac OS X system. It parses the HFS+ filesystem to extract critical data like file names, sizes, and timestamps, outputting it in a format easily imported into a database. This facilitates timeline analysis and data correlation during forensic examinations.
Key Features:
  • Extracts allocated file metadata from HFS+ volumes
  • Outputs data in a database-friendly format (SQLite/CSV)
  • Preserves critical timestamps (MACB) for forensic analysis
  • Command-line interface for scripting and automation
Use Cases:
  • Creating a timeline of file system activity during an incident response
  • Performing forensic analysis on seized Mac OS X hardware
  • Automating data collection for system integrity monitoring
Alternatives:
  • fls – Part of The Sleuth Kit; offers cross-platform support and handles multiple filesystems, whereas MacRobber is specialized for HFS+.
  • The Sleuth Kit (Autopsy) – Provides a comprehensive GUI and suite of tools, while MacRobber is a lightweight, command-line specific utility.
Version History
Detected Version Rev Change Commit
Sep 16, 2025 2:40am 0 VERSION_BUMP ff4f3675
Sep 13, 2024 7:45pm 0 VERSION_BUMP 2f5c89d2