This overview brings together all the questions and answers relating to IT forensics for macOS on LanCologne – from Apple Silicon and Intel Macs, through file systems, encryption and system configuration, to network, app and user data traces, as well as the forensic tools used. Click on a category to view the relevant questions.
Hardware models and backup methods
- Performing a forensic backup of an Apple Silicon Mac
- Performing a forensic backup of an Intel-based Mac without a T2 chip
- Performing a forensic backup of an Intel-based Mac with a T2 Security Chip
- Forensic backup and analysis of an iMac
- Forensic backup and analysis of a Mac mini
- Forensic backup and analysis of the Mac Studio
- Forensic backup and analysis of a MacBook Pro
- Forensic backup and analysis of a MacBook Air
- Forensic backup and analysis of the Mac Pro
- Using Apple Silicon Share Disk for forensic analysis
- Using Intel Target Disk Mode for forensic purposes
- Using macOS Recovery for forensic backup
- Performing a forensic backup of a running, unlocked Mac
- Transferring data from a switched-off Mac in a way that preserves evidence
- Performing a forensic backup of an encrypted Mac
- Backing up external Apple storage devices in a way that preserves evidence
- Verifying forensic Mac images using hash values
- Documenting the chain of custody for evidence relating to Mac computers
- Minimising write accesses during Mac investigations
Forensic tools and methodology
- Distinguishing between Mac triage and a full forensic analysis
- Carry out Mac acquisition using SUMURI RECON ITR
- Carrying out Mac triage using SUMURI RECON ITR
- Analysing macOS evidence using SUMURI RECON LAB
- Analysing Apple Extended Metadata with RECON LAB
- Analysing APFS evidence using Belkasoft X
- Correlate macOS timelines with Belkasoft X
- Conducting an in-depth analysis of APFS using X-Ways Forensics
- Check deleted Mac data using X-Ways Forensics
- Using X-Tensions for specialised Mac analyses
- Cross-check Mac findings using several forensic tools
- Using your own tools for rare macOS artefacts
- Correlating unified logs using your own tools
- Create a complete macOS timeline from multiple artefacts
- Identifying parser errors and false positives in Mac forensics
- Ensuring the reproducibility of a Mac study
- Documenting macOS forensics in a legally admissible manner
- Why Mac forensics requires several tools and manual examination
File systems, encryption and forensic backup
- Forensic analysis of the APFS file system – the foundation of modern macOS investigations
- Forensic analysis of APFS snapshots – examining previous file system states
- Forensic analysis of APFS volume groups – correctly mapping system and user data
- Forensic analysis of FileVault – assessing the encryption status and access options
- Forensic analysis of the Secure Enclave – correctly assessing hardware-based security mechanisms
- Forensic analysis of FSEvents – reconstructing file system changes on macOS
- Forensic analysis of Time Machine snapshots – Investigating previous file states on macOS
- Forensic analysis of the macOS KnowledgeC database
- Forensic analysis of Spotlight metadata – Evaluating indexed file and content information
- Manually cross-check APFS metadata
- Forensic analysis of external volumes on macOS
- Forensic analysis of macOS disk images
- In-depth forensic correlation of the macOS FSEvents history
- Forensic analysis of macOS extended attributes
Networking and Communication
- Forensic analysis of location services – technical assessment of a Mac’s location data
- Forensic analysis of significant locations – Properly categorising significant locations on macOS
- Forensic analysis of macOS Wi-Fi networks – reconstructing a Mac’s network connections
- Forensic analysis of macOS Bluetooth – technical classification of paired and detected devices
- Forensic analysis of macOS Network Extensions
- Forensic analysis of the macOS firewall
- Forensic analysis of macOS VPN artefacts
- Forensic analysis of macOS DNS and proxy configuration
- Forensic analysis of macOS screen sharing and remote management
- Forensic analysis of macOS iCloud Drive
- Forensic analysis of macOS AirDrop
- A forensic analysis of macOS Handoff and Continuity
- Forensic analysis of the macOS hosts file
- Forensic analysis of macOS network interfaces
- Forensic analysis of macOS DHCP artefacts
- Forensic analysis of macOS ARP and neighbour entries
- Forensic analysis of macOS printers and printing systems
- Forensic analysis of macOS CUPS artefacts
System and Security Configuration
- Forensic analysis of macOS Unified Logs – reconstructing system events and activities
- Forensic analysis of LaunchAgents and LaunchDaemons – Investigating persistence on macOS
- Forensic analysis of login items and background services – Reconstructing automatic programme launches
- Manually validate SQLite, WAL and SHM artefacts
- Manually validating Plist and NSKeyedArchiver data
- Forensic analysis of gatekeepers and quarantine – assessing the origin and execution of software
- Forensic analysis of XProtect – A technical assessment of Apple’s built-in malware protection
- Forensic analysis of macOS privacy permissions – assessing app access to protected resources
- Forensic analysis of Launch Services – evaluating app and document mappings on macOS
- Forensic analysis of macOS crash reports – investigating process crashes and diagnostic information
- Forensic analysis of macOS plist files – evaluating configurations and states
- Forensic Analysis of macOS SQLite Databases – Evaluating the Database, WAL and SHM Together
- Forensic analysis of the macOS Keychain
- Forensic analysis of macOS certificates and trust settings
- Forensic analysis of macOS configuration profiles
- Forensic analysis of macOS MDM artefacts
- Forensic analysis of macOS system extensions
- Forensic analysis of macOS kernel extensions
- Forensic analysis of the macOS TCC database
- Forensic analysis of the macOS privacy database for app permissions
- Forensic analysis of the macOS Quarantine Events database
- Forensic analysis of macOS download sources and ‘WhereFrom’ entries
Terminal, Shell, Scripting and Software Installation
- Forensic analysis of macOS Terminal artefacts
- Forensic analysis of macOS Zsh artefacts
- Forensic analysis of macOS Bash artefacts
- Forensic analysis of macOS sudo artefacts
- Forensic analysis of macOS Cron and recurring jobs
- Forensic analysis of macOS installer packages
- Forensic analysis of the macOS installation history
- Forensic analysis of macOS software update artefacts
- Forensic analysis of macOS App Store artefacts
- Forensic analysis of macOS Homebrew artefacts
- Forensic analysis of Python environments on macOS
- Forensic analysis of macOS Automator and Shortcuts
Apps, Finder and user data
- Forensic analysis of screen time – analysing app and website usage on macOS
- Forensic analysis of recent items – reconstructing evidence of recently used objects
- Forensic analysis of macOS user accounts – understanding user and account structures
- Forensic analysis of macOS login artefacts – reconstructing login and session processes
- Forensic analysis of Safari history – reconstructing web activity on macOS
- Forensic analysis of Safari downloads – investigating the origin of downloaded files
- Forensic analysis of the macOS Trash – examining deleted and moved files
- Forensic analysis of macOS USB devices – tracing external devices and storage media
- Forensic analysis of the macOS Messages app
- Forensic analysis of macOS Mail
- Forensic analysis of the macOS Calendar
- Forensic analysis of macOS Contacts
- Forensic analysis of macOS Notes
- Forensic analysis of macOS app bundles and code signing
- Forensic analysis of macOS Finder artefacts
- Forensic analysis of macOS .DS_Store files
- Forensic analysis of macOS alias files
- Forensic analysis of macOS bookmarks and security-scoped bookmarks
Other questions
- Forensic analysis of macOS shell history – investigating Terminal and command activities
- Forensic analysis of macOS SSH – Investigating remote login and key traces
- Forensic analysis of macOS app sandbox containers
- Forensic analysis of macOS Group Containers
- Forensic analysis of macOS Preferences and CFPreferences
- Forensic analysis of macOS NSUserDefaults artefacts
- Forensic analysis of macOS Saved Application State
- Forensic analysis of macOS Resume artefacts
- Forensic analysis of macOS QuickLook artefacts
- Forensic analysis of macOS thumbnail and preview caches
- Forensic analysis of the macOS Notification Centre