IT Forensics · macOS

Forensic analysis of APFS snapshots – examining previous file system states

APFS supports snapshots as read-only images of an APFS volume at a specific point in time. Snapshots can therefore represent previous states of the file system without creating a complete second copy of all the data. macOS utilises snapshot mechanisms in connection with Time Machine and system functions, amongst other things.

Enquire without obligation

Existing snapshots can be extremely valuable for forensic analysis, as files or metadata may still be visible in an earlier state. However, a snapshot is not a guaranteed archive: its availability, lifespan and content depend on system usage, storage management and the specific mechanism used to create it.

Why LanCologne?

Since its foundation, LanCologne has specialised in professional IT forensics. Our staff have decades of experience in the field of information technology and assist companies, solicitors, private individuals and, on a regular basis, the courts in the technical investigation of complex digital matters.

The examination is, as a matter of principle, carried out exclusively on a forensic copy, a forensic image or a data source captured in a technically equivalent manner that preserves the integrity of the evidence. The original evidence remains unchanged and is stored in a manner that preserves its integrity.

Our services

We identify existing APFS volumes and snapshots, document snapshot names and technically available timestamps, and compare relevant file system states with one another.

When dealing with specific issues, we check whether files, directories or metadata are present in a snapshot that have been modified or are no longer visible in the current state. The results are correlated with FSEvents, Time Machine and other file system artefacts.

Typical areas of application

Analysis of previous file system states
Search for modified or deleted files
Comparison of the snapshot and the current volume
Incident Response and Tampering Investigations
Adding to file system timelines
Correlation with Time Machine and FSEvents
Judicial and non-judicial expert reports

This is how the forensic investigation is carried out

Once the data has been securely backed up, APFS containers, volumes and existing snapshots are catalogued. Where possible, relevant snapshots are analysed in read-only mode and compared with the current state of the file system.

In this process, the snapshot from which a finding originates is precisely documented. An object present in a snapshot is not interpreted, without further verification, as evidence that it remained unchanged or was actively used at a different point in time.

Why is this area of investigation relevant to forensics?

APFS snapshots can reveal states that are no longer directly present in the current file system. This is particularly valuable in the context of deletions, modifications and incident response investigations.

However, their reliability depends on the specific snapshot. Not every time period is covered, and not all deleted information is retained by a snapshot.

Frequently Asked Questions

What is an APFS snapshot?+
A read-only snapshot of the state of an APFS volume at a specific point in time.
Can a snapshot contain deleted files?+
If the file existed at the time the snapshot was taken, it may still be visible there under the right circumstances.
Are APFS snapshots the same as a full backup?+
No. Snapshots and backups serve different purposes and have different retention and storage characteristics.
Can a user’s action be proven on the basis of a snapshot alone?+
No. A file system state must be correlated with time, user and activity artefacts.

LanCologne – macOS Forensics in Cologne

Do you need a professional analysis of existing APFS snapshots? LanCologne can help you create legally admissible backups and carry out traceable comparisons of previous file system states.

Get in touch now