IT FORENSICS · macOS

IT Forensics for macOS – Conducting technically sound investigations of Mac systems

Whether following a security incident, in the event of suspected unauthorised access, as part of legal proceedings or for an internal company investigation: Due to their architecture – the APFS file system, Apple Silicon or Intel hardware, encryption, sandboxing and authorisation mechanisms – Mac devices running macOS place particular demands on an IT forensic investigation.

We place particular emphasis on ensuring that backups are tailored to the specific Mac model and chip, on employing a transparent methodology, and on cross-checking key findings using multiple forensic tools.

Specialising in macOS
Documentation admissible in court
GDPR-compliant processing
Experienced experts

BASICS OF MACOS FORENSICS

How a forensic examination of macOS systems is carried out

We secure and examine Mac devices regardless of model or chip – from Apple Silicon to Intel-based Macs, with or without the T2 Security Chip. System logs, user accounts, network and browser traces, and app data are analysed depending on the specific case, and key findings are cross-checked using a range of forensic tools.

OUR APPROACH

This is how your examination will be carried out

A transparent process – from the initial enquiry to the handover of the report.

1
We’ll clarify the issue and the Mac model in question – Apple Silicon or Intel, with or without the T2 Security Chip – as the backup options vary depending on the hardware.
2
The device is secured in accordance with the model and chip specifications; hash values ensure data integrity throughout.
3
Depending on the nature of the enquiry, we analyse the APFS file system and encryption, system logs, user accounts, or network and browser traces.
4
Key findings are cross-checked using a range of forensic tools and manual checks to provide further assurance of the results.
5
The findings are documented in a clear and comprehensive report that can be used by the courts, businesses or private individuals.

TYPICAL QUESTIONS

When is a forensic examination of macOS systems advisable?

  • File systems, encryption and system states (APFS, FileVault)
  • System logs and activity history
  • Device security based on Mac model and chip
  • System security and protection mechanisms (Secure Enclave)
  • User accounts, login and system usage
  • Network and external devices
  • Browsers, communication and cloud services
  • Methodology, validation and quality assurance

LIMITATIONS & CONCLUSION

What you should know

We examine Mac devices running macOS in the event of security incidents, suspected unauthorised access, as part of legal proceedings or internal company investigations. Our services include, amongst other things, model-specific backups, the analysis of APFS, system logs, user accounts and network traces, as well as cross-checking key findings using multiple forensic tools.

If the incident affects not just individual devices but the organisation’s infrastructure, this overview continues as follows: Investigation of a cyber attack.

CUSTOMER REVIEWS

What our customers say

4.8 out of 5 stars on Trustpilot · 54 reviews

★★★★★

“The highest standards of professionalism, prompt service and excellent communication. They made the seemingly impossible a reality. This is what genuine customer service is all about – unrivalled in Germany!”

idalein

Verified review on Trustpilot

★★★★★

“Very helpful advice, excellent responsiveness and communication. My problem was completely resolved and the lost data was recovered. I’m very satisfied and, of course, relieved!”

Layla Pankratz

Verified review on Trustpilot

★★★★★

“My problem was sorted out professionally and quickly; everyone I spoke to was always friendly, and I can still get in touch if I have any questions – I’m very grateful for that!”

a woman from Cologne

Verified review on Trustpilot

Enquire now – free initial consultation

Do you need assistance with the forensic examination of a Mac? LanCologne backs up and examines macOS systems in a manner appropriate to the model, ensuring that the process is reproducible and documented to a standard that stands up in court.

FREQUENTLY ASKED QUESTIONS

Frequently Asked Questions

Click on a question to see the answer.

Why is an understanding of the APFS file system fundamental to macOS forensics?

The Apple File System (APFS) has been the default file system for modern Mac systems since macOS 10.13. It was developed for flash and SSD storage and supports, amongst other things, copy-on-write metadata, space sharing, clones, snapshots and encryption. From a forensic perspective, an understanding of the APFS structure is therefore essential for the proper examination of current macOS systems.

How does FileVault affect the forensic examination of a Mac?

FileVault protects data on a Mac through encryption. On Macs with Apple Silicon or the Apple T2 Security Chip, data is already encrypted using hardware-based encryption; FileVault adds an extra layer of protection by linking access to the user’s login credentials or appropriate recovery mechanisms. On older Intel-based Macs without a T2 chip, the technical situation is different and must be assessed separately.

What role does the Secure Enclave play in macOS forensics?

The Secure Enclave is a security zone isolated from the main processor which handles key cryptographic tasks on Macs with Apple Silicon and on Intel-based Macs with the Apple T2 Security Chip. It has its own protection mechanisms and is involved, amongst other things, in the secure processing and storage of cryptographic keys. It is therefore particularly relevant to macOS forensics, especially in the case of encrypted internal storage volumes, FileVault and hardware-based access control mechanisms.

Why are macOS findings cross-checked using several forensic tools?

No single forensic programme provides comprehensive coverage of every macOS version, every artefact and every specific scenario. That is why, depending on the case, we cross-check key findings using RECON LAB, Belkasoft X, X-Ways and manual examinations.