Company
About macfor
The story behind macfor and our mission to improve macOS forensics.
Our Mission
macfor exists to make macOS forensics accessible, reliable, and forensically sound. We believe that high-quality forensic tools shouldn't require enterprise budgets, and that the forensic community benefits when core tools are open source.
The Problem We Solve
For years, the digital forensics industry has treated macOS as an afterthought. Windows tools dominate the market, and Mac support often means basic file system browsing without understanding macOS-specific artifacts.
Meanwhile, Mac adoption continues to grow—in enterprises, creative industries, and among security-conscious users. When incidents occur on these systems, investigators are often left with inadequate tools or manual collection processes.
Our Approach
macfor takes a different approach:
macOS-First Design
Every artifact parser is built specifically for macOS. We don't port Windows code or make assumptions based on other operating systems. We study Apple's documentation, reverse-engineer undocumented formats, and test across macOS versions.
Open Source Foundation
The macfor Collector Community Edition is open source under the MIT license. This means:
- Anyone can inspect the code to understand exactly what's collected
- The forensic community can contribute improvements
- Researchers can extend macfor for their specific needs
- No vendor lock-in for evidence format
Commercial Sustainability
We fund development through macfor Professional and Enterprise editions, which add advanced artifact support and priority support. This hybrid model ensures:
- Core functionality remains free and open
- Revenue funds ongoing development
- Enterprise users get the support they need
- The project remains sustainable long-term
Our Team
macfor was founded by forensic practitioners who experienced the macOS tooling gap firsthand. Our team combines deep macOS expertise with software engineering experience from leading technology companies.
We're a small, focused team based in Australia, working to build the best macOS forensic tools in the world.
Our Values
Forensic Integrity
Evidence integrity is non-negotiable. We never cut corners that could compromise the admissibility or reliability of collected evidence.
Transparency
Our open source code, documented methodology, and public roadmap ensure you always know what macfor does and where it's headed.
Community
We actively engage with the forensic community through GitHub, Discord, and industry events. Your feedback shapes our development priorities.
Continuous Improvement
macOS evolves constantly, and so do we. Regular updates ensure macfor supports the latest artifacts and macOS versions.
Contact Us
- General inquiries: hello@macfor.io
- Security issues: security@macfor.io
- GitHub: github.com/macforensics/macfor
- Discord: Join our community
- Twitter: @macforensics