IT Forensics · macOS
Forensic analysis of APFS volume groups – correctly mapping system and user data
Modern macOS systems use APFS volume groups to logically separate system components from user data that is subject to change. Apple describes the boot volume as a volume group consisting, amongst other things, of a system volume and an associated data volume. The system volume contains the system files required for boot-up and Apple’s own system components, whilst the data volume holds mutable content such as user files, installed applications and other writable areas.
This distinction is of central importance in macOS forensics. An analysis must not assume that all relevant information is contained within a single volume. Rather, the related volumes, their roles and their relationships to one another must be correctly identified and documented before files, directories and other artefacts are technically assessed.
Why LanCologne?
Since its foundation, LanCologne has specialised in professional IT forensics. Our staff have decades of experience in the field of information technology and assist companies, solicitors, private individuals and, on a regular basis, the courts in the technical investigation of complex digital matters.
The examination is, as a matter of principle, carried out exclusively on a forensic copy, a forensic image or a data source captured in a technically equivalent manner that preserves the integrity of the evidence. The original evidence remains unchanged and is stored in a manner that preserves its integrity.
Our services
We identify APFS containers, the volumes they contain and their roles within the macOS volume structure. In particular, we examine which volumes belong to a system volume group and how the system and data volumes are logically linked. Depending on the system, pre-boot, recovery and VM volumes may also be present; these are classified separately as part of the investigation.
Relevant content is not considered in isolation from a single volume. Instead, technical mapping takes place across the entire APFS structure. This enables paths, user directories, installed applications, system components and other data to be correctly assigned to the relevant volume and its function.
Typical areas of application
This is how an analysis of APFS volume groups is carried out
Once the data storage device or the macOS system has been securely acquired as evidence, the APFS container structure is first identified. The existing volumes, their roles and their UUID-based mappings are then documented. In the case of a macOS system installation, a check is carried out to determine which volumes together form a volume group and which other auxiliary volumes are present within the container.
Only then does the actual artefact analysis begin. Files and directories are analysed, taking into account their actual volume affiliation. With macOS 11 and later, it must also be borne in mind that the system volume is typically booted from a snapshot. The results are correlated with other macOS artefacts, and all technical findings are documented in a transparent manner.
Why are APFS volume groups important from a forensic perspective?
The separation between system and data volumes changes the way in which modern macOS systems must be examined forensically. Directories that appear to the user as a single, unified file tree may, technically speaking, be located on different APFS volumes. Without knowledge of the volume group structure, there is therefore a risk of misattributing data or failing to capture all relevant content.
In addition, other APFS volumes fulfil various roles. Amongst other things, Apple describes pre-boot, VM and recovery volumes, each with their own specific functions. For a robust analysis, these roles must be distinguished. A volume group is therefore not a single artefact, but a fundamental component of the macOS storage architecture that influences the correct interpretation of numerous other traces.
Frequently Asked Questions
LanCologne – macOS Forensics in Cologne
Do you require a professional analysis of an APFS volume group or a modern macOS system? LanCologne can assist you with the forensically sound backup of digital evidence, as well as the traceable mapping and analysis of system, data and other APFS volumes.
Related to this topic
- Forensic analysis of FileVault – assessing the encryption status and access options
- Forensic analysis of the Secure Enclave – correctly assessing hardware-based security mechanisms
- Forensic analysis of FSEvents – reconstructing file system changes on macOS
- Forensic analysis of Time Machine snapshots – Investigating previous file states on macOS