Aftermath is an open-source incident response framework for macOS. It offers a standardized, modular collection engine to help security teams gather and analyze forensic data—such as persistence mechanisms, system configuration, and file system metadata—after a compromise. With a focus on speed and automated evidence gathering, it streamlines the triage process for digital forensics and incident response (DFIR) professionals.