puffyCid / artemis

A cross platform forensic parser written in Rust!

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

Support parsing macOS Spotlight

puffyCid opened this issue · comments

What new feature do you think would be cool to add to artemis?
Currently artemis supports parsing the Windows Search database. It could be cool to also support parsing the macOS Spotlight database.

Describe the solution you'd like
macOS Spotlight database contains similar information as the Windows Search database. Adding support for Spotlight could be useful for investigations

Additional context
Spotlight is a pretty complex database and is composed of multiple files.
Some references: