IT FORENSICS · macOS
IT Forensics for macOS – Conducting technically sound investigations of Mac systems
Whether following a security incident, in the event of suspected unauthorised access, as part of legal proceedings or for an internal company investigation: Due to their architecture – the APFS file system, Apple Silicon or Intel hardware, encryption, sandboxing and authorisation mechanisms – Mac devices running macOS place particular demands on an IT forensic investigation.
We place particular emphasis on ensuring that backups are tailored to the specific Mac model and chip, on employing a transparent methodology, and on cross-checking key findings using multiple forensic tools.
BASICS OF MACOS FORENSICS
How a forensic examination of macOS systems is carried out
We secure and examine Mac devices regardless of model or chip – from Apple Silicon to Intel-based Macs, with or without the T2 Security Chip. System logs, user accounts, network and browser traces, and app data are analysed depending on the specific case, and key findings are cross-checked using a range of forensic tools.
OUR APPROACH
This is how your examination will be carried out
A transparent process – from the initial enquiry to the handover of the report.
TYPICAL QUESTIONS
When is a forensic examination of macOS systems advisable?
- ✔File systems, encryption and system states (APFS, FileVault)
- ✔System logs and activity history
- ✔Device security based on Mac model and chip
- ✔System security and protection mechanisms (Secure Enclave)
- ✔User accounts, login and system usage
- ✔Network and external devices
- ✔Browsers, communication and cloud services
- ✔Methodology, validation and quality assurance
LIMITATIONS & CONCLUSION
What you should know
We examine Mac devices running macOS in the event of security incidents, suspected unauthorised access, as part of legal proceedings or internal company investigations. Our services include, amongst other things, model-specific backups, the analysis of APFS, system logs, user accounts and network traces, as well as cross-checking key findings using multiple forensic tools.
If the incident affects not just individual devices but the organisation’s infrastructure, this overview continues as follows: Investigation of a cyber attack.
CUSTOMER REVIEWS
What our customers say
4.8 out of 5 stars on Trustpilot · 54 reviews
“The highest standards of professionalism, prompt service and excellent communication. They made the seemingly impossible a reality. This is what genuine customer service is all about – unrivalled in Germany!”
idalein
Verified review on Trustpilot
“Very helpful advice, excellent responsiveness and communication. My problem was completely resolved and the lost data was recovered. I’m very satisfied and, of course, relieved!”
Layla Pankratz
Verified review on Trustpilot
“My problem was sorted out professionally and quickly; everyone I spoke to was always friendly, and I can still get in touch if I have any questions – I’m very grateful for that!”
a woman from Cologne
Verified review on Trustpilot
Enquire now – free initial consultation
Do you need assistance with the forensic examination of a Mac? LanCologne backs up and examines macOS systems in a manner appropriate to the model, ensuring that the process is reproducible and documented to a standard that stands up in court.
RELATED TOPICS
You might also be interested in
FREQUENTLY ASKED QUESTIONS
Frequently Asked Questions
Click on a question to see the answer.