IT Forensics · macOS

Forensic analysis of APFS volume groups – correctly mapping system and user data

Modern macOS systems use APFS volume groups to logically separate system components from user data that is subject to change. Apple describes the boot volume as a volume group consisting, amongst other things, of a system volume and an associated data volume. The system volume contains the system files required for boot-up and Apple’s own system components, whilst the data volume holds mutable content such as user files, installed applications and other writable areas.

Enquire without obligation

This distinction is of central importance in macOS forensics. An analysis must not assume that all relevant information is contained within a single volume. Rather, the related volumes, their roles and their relationships to one another must be correctly identified and documented before files, directories and other artefacts are technically assessed.

Why LanCologne?

Since its foundation, LanCologne has specialised in professional IT forensics. Our staff have decades of experience in the field of information technology and assist companies, solicitors, private individuals and, on a regular basis, the courts in the technical investigation of complex digital matters.

The examination is, as a matter of principle, carried out exclusively on a forensic copy, a forensic image or a data source captured in a technically equivalent manner that preserves the integrity of the evidence. The original evidence remains unchanged and is stored in a manner that preserves its integrity.

Our services

We identify APFS containers, the volumes they contain and their roles within the macOS volume structure. In particular, we examine which volumes belong to a system volume group and how the system and data volumes are logically linked. Depending on the system, pre-boot, recovery and VM volumes may also be present; these are classified separately as part of the investigation.

Relevant content is not considered in isolation from a single volume. Instead, technical mapping takes place across the entire APFS structure. This enables paths, user directories, installed applications, system components and other data to be correctly assigned to the relevant volume and its function.

Typical areas of application

Forensic analysis of modern macOS boot volumes
Mapping of system and user data
Reconstruction of file system structures according to macOS-Updates
Analysis of FileVault-protected systems following successful evidence-preserving acquisition
Investigation of incident response cases on macOS
Assessment of system tampering and persistence mechanisms
Judicial and non-judicial expert reports

This is how an analysis of APFS volume groups is carried out

Once the data storage device or the macOS system has been securely acquired as evidence, the APFS container structure is first identified. The existing volumes, their roles and their UUID-based mappings are then documented. In the case of a macOS system installation, a check is carried out to determine which volumes together form a volume group and which other auxiliary volumes are present within the container.

Only then does the actual artefact analysis begin. Files and directories are analysed, taking into account their actual volume affiliation. With macOS 11 and later, it must also be borne in mind that the system volume is typically booted from a snapshot. The results are correlated with other macOS artefacts, and all technical findings are documented in a transparent manner.

Why are APFS volume groups important from a forensic perspective?

The separation between system and data volumes changes the way in which modern macOS systems must be examined forensically. Directories that appear to the user as a single, unified file tree may, technically speaking, be located on different APFS volumes. Without knowledge of the volume group structure, there is therefore a risk of misattributing data or failing to capture all relevant content.

In addition, other APFS volumes fulfil various roles. Amongst other things, Apple describes pre-boot, VM and recovery volumes, each with their own specific functions. For a robust analysis, these roles must be distinguished. A volume group is therefore not a single artefact, but a fundamental component of the macOS storage architecture that influences the correct interpretation of numerous other traces.

Frequently Asked Questions

What is an APFS volume group?+
A volume group combines several logical APFS volumes, which are used together as a coherent system structure. In macOS, the boot volume group typically consists of a system volume and a data volume.
What is the difference between a system volume and a data volume?+
The system volume contains the system files required for macOS and is particularly well protected in recent versions. The data volume contains modifiable data such as user files, installed applications and other writable areas.
What other APFS volumes might there be?+
Depending on the system, there may be, amongst others, pre-boot, recovery and VM volumes. Their specific availability and use must be assessed on a case-by-case basis.
Why isn’t it enough simply to examine the volume of data?+
Depending on the issue at hand, information from the system volume, preboot, recovery or other APFS structures may also be relevant. The full picture only becomes clear once all the related volumes have been analysed together.

LanCologne – macOS Forensics in Cologne

Do you require a professional analysis of an APFS volume group or a modern macOS system? LanCologne can assist you with the forensically sound backup of digital evidence, as well as the traceable mapping and analysis of system, data and other APFS volumes.

Get in touch now