IT Forensics · macOS
Forensic analysis of the APFS file system – the foundation of modern macOS investigations
The Apple File System (APFS) has been the default file system for modern Mac systems since macOS 10.13. It was developed for flash and SSD storage and supports, amongst other things, copy-on-write metadata, space sharing, clones, snapshots and encryption. From a forensic perspective, an understanding of the APFS structure is therefore essential for the proper examination of current macOS systems.
On bootable Macs, an APFS container has typically consisted of several logically related volumes since macOS 10.15. In addition to the system and data volumes, there may also be pre-boot, recovery and VM volumes, amongst others. Since macOS 11, the operating system has routinely booted from a snapshot of the system volume. This architecture must be taken into account during backup and analysis, as user-modifiable data and protected system components are no longer stored together in a single traditional file system volume.
An APFS analysis is not limited to individual files. Container and volume structures, volume roles, snapshots, file system metadata, timestamps and the relationship to other macOS artefacts are all assessed together. In the case of encrypted systems, FileVault, Secure Enclave-bound key mechanisms and the specific device generation must also be taken into account. Statements regarding the recoverability of deleted content must be made with caution and on a case-by-case basis, particularly in the case of SSDs, due to encryption, TRIM and storage areas that have already been overwritten.
Why LanCologne?
Since its foundation, LanCologne has specialised in professional IT forensics. Our staff have decades of experience in the field of information technology and assist companies, solicitors, private individuals and, on a regular basis, the courts in the technical investigation of complex digital matters.
The examination of macOS systems is always carried out exclusively on a forensic copy or a forensic image. The original evidence remains unchanged and is stored in a manner that preserves its evidential integrity.
Our services
We analyse APFS containers and volumes, volume roles, file system metadata, existing APFS snapshots, and the logical relationship between the system volume and the data volume. Depending on the device, macOS version and data situation, relevant structures are correlated with user, system, application and log data. Where FileVault is active, we first assess whether, and under which legally and technically permissible conditions, access to the encrypted user data is possible. The aim is to carry out a traceable technical reconstruction based on artefacts that actually exist.
Typical areas of application
This is how an APFS forensic examination is carried out
Once the data storage medium or the technically accessible forensic data source has been securely acquired, the APFS structure is first determined. This involves documenting containers, volumes, volume roles, encryption status and any existing snapshots. The relevant file system information is then correlated with other macOS artefacts. Depending on the Mac model and security configuration, the method of data collection can vary considerably; in particular, Apple Silicon and T2 systems require an assessment of the available access options before user data can be examined. All investigation steps and technical limitations are documented in a transparent manner.
Why is APFS analysis so important?
On current Mac systems, APFS forms the technical basis for storing operating system, user and application data. The division into volume groups, snapshots and modern encryption mechanisms differs significantly from older HFS+ systems. A misinterpretation of these structures can lead to incorrect conclusions regarding timing or content. For this reason, APFS artefacts are not analysed in isolation, but are always evaluated in conjunction with the relevant macOS logs, user artefacts and application data.
Frequently Asked Questions
LanCologne – macOS Forensics in Cologne
Do you require a professional forensic analysis of a Mac system or an APFS volume? LanCologne can assist you with the legally admissible preservation of digital evidence and the traceable analysis of relevant macOS and APFS artefacts.
Related to this topic
- Forensic analysis of APFS snapshots – examining previous file system states
- Forensic analysis of APFS volume groups – correctly mapping system and user data
- Forensic analysis of FileVault – assessing the encryption status and access options
- Forensic analysis of the Secure Enclave – correctly assessing hardware-based security mechanisms