IT Forensics · macOS
Forensic analysis of APFS snapshots – examining previous file system states
APFS supports snapshots as read-only images of an APFS volume at a specific point in time. Snapshots can therefore represent previous states of the file system without creating a complete second copy of all the data. macOS utilises snapshot mechanisms in connection with Time Machine and system functions, amongst other things.
Existing snapshots can be extremely valuable for forensic analysis, as files or metadata may still be visible in an earlier state. However, a snapshot is not a guaranteed archive: its availability, lifespan and content depend on system usage, storage management and the specific mechanism used to create it.
Why LanCologne?
Since its foundation, LanCologne has specialised in professional IT forensics. Our staff have decades of experience in the field of information technology and assist companies, solicitors, private individuals and, on a regular basis, the courts in the technical investigation of complex digital matters.
The examination is, as a matter of principle, carried out exclusively on a forensic copy, a forensic image or a data source captured in a technically equivalent manner that preserves the integrity of the evidence. The original evidence remains unchanged and is stored in a manner that preserves its integrity.
Our services
We identify existing APFS volumes and snapshots, document snapshot names and technically available timestamps, and compare relevant file system states with one another.
When dealing with specific issues, we check whether files, directories or metadata are present in a snapshot that have been modified or are no longer visible in the current state. The results are correlated with FSEvents, Time Machine and other file system artefacts.
Typical areas of application
This is how the forensic investigation is carried out
Once the data has been securely backed up, APFS containers, volumes and existing snapshots are catalogued. Where possible, relevant snapshots are analysed in read-only mode and compared with the current state of the file system.
In this process, the snapshot from which a finding originates is precisely documented. An object present in a snapshot is not interpreted, without further verification, as evidence that it remained unchanged or was actively used at a different point in time.
Why is this area of investigation relevant to forensics?
APFS snapshots can reveal states that are no longer directly present in the current file system. This is particularly valuable in the context of deletions, modifications and incident response investigations.
However, their reliability depends on the specific snapshot. Not every time period is covered, and not all deleted information is retained by a snapshot.
Frequently Asked Questions
🔗 Related topics
LanCologne – macOS Forensics in Cologne
Do you need a professional analysis of existing APFS snapshots? LanCologne can help you create legally admissible backups and carry out traceable comparisons of previous file system states.
Related to this topic
- Forensic analysis of APFS volume groups – correctly mapping system and user data
- Forensic analysis of FileVault – assessing the encryption status and access options
- Forensic analysis of the Secure Enclave – correctly assessing hardware-based security mechanisms
- Forensic analysis of FSEvents – reconstructing file system changes on macOS