IT Forensics · macOS

Analysing APFS evidence using Belkasoft X

Belkasoft X unterstützt laut Hersteller macOS-Datenquellen und APFS und kann Computerabbilder sowie zahlreiche Artefakttypen analysieren. Dadurch eignet es sich als zusätzliche unabhängige Analyseplattform in Mac-Fällen.

Enquire without obligation

This point is particularly important for Apple computers, as their hardware and security architecture have changed significantly in recent years. An older Intel-based iMac, an Intel-based Mac with a T2 Security Chip and a current Mac Studio with Apple Silicon cannot be treated according to the same technical approach. APFS, Secure Enclave, FileVault and the respective system state determine which data is accessible and which backup method causes the least disruption.

Belkasoft-Ergebnisse werden bei zentralen Befunden mit nativen Mac-Werkzeugen, RECON LAB, X-Ways oder manueller Analyse gegengeprüft. Unterschiedliche Parser können unterschiedliche Ergebnisse liefern.

Why LanCologne?

LanCologne does not examine Apple computers according to a standardised, one-size-fits-all approach, but rather on the basis of the specific hardware and security architecture. Our staff have decades of experience in information technology and many years of practical experience in IT forensics. We assist companies, solicitors and private individuals, as well as regularly supporting courts and public authorities, in the technical investigation of digital matters.

The investigation is generally carried out on a forensic copy, a forensic image or a data source captured in a technically equivalent manner that preserves the integrity of the evidence. The original evidence is either left unchanged or, where technically unavoidable alterations have been made, these are transparently documented and the evidence is stored in a manner that preserves its integrity.

Our working methods and the tools we use

Our investigation does not begin by launching an analysis programme, but by gathering evidence. The device, model, serial number or inventory reference, connection status, visible system status and any peripheral devices are documented. A decision is then made as to whether the system must remain switched off, whether live data capture is appropriate, or whether a recovery, target disk or share disk procedure is technically justifiable.

The next step is to define the backup strategy. We distinguish between block-level mapping, logical backups and targeted triage. The choice does not depend on convenience, but on the hardware generation, FileVault, the APFS structure, the available unlock status and the specific issue to be investigated. Where technically possible, we work in read-only mode. Any unavoidable changes to the system’s state during live or recovery procedures are explicitly logged.

The backup created is documented using hash values. The actual analysis is not carried out on the original, but on a working copy or a verified proof image. This allows parsers, searches or custom utilities to be used without continuously altering the original evidence.

Belkasoft X setzen wir als zusätzliche Analyse- und Korrelationsplattform ein. Der Hersteller unterstützt macOS-Quellen, APFS sowie verschiedene Imageformate und stellt fallweite Such-, Timeline- und Analysefunktionen bereit. Für zentrale Befunde bleibt die Rückprüfung gegen die ursprüngliche Datenquelle beziehungsweise ein zweites Werkzeug Bestandteil unseres Workflows.

For readers unfamiliar with the subject, one point is particularly important: a forensic programme does not automatically „find“ the truth. It reads data structures and interprets them according to known rules. If Apple changes a database or a metadata format with a new version of macOS, a parser may respond incompletely or incorrectly. That is why, when dealing with crucial findings, we check which file, database or file system structure the result originates from, and whether a second technical approach confirms the same findings.

That is also why we use several tools. RECON LAB can analyse Apple-specific structures natively on macOS; Belkasoft X offers a different perspective on artefacts and correlations; X-Ways enables highly detailed file system and raw data checks. If independent analyses agree, this increases the robustness of the findings. If they do not agree, the cause is investigated rather than simply selecting the most convenient match.

Typical areas of application

Judicial and non-judicial expert reports
Preservation of evidence from iMac, Mac mini, Mac Studio, MacBook and Mac Pro
Analysis of Apple Silicon, T2 and older Intel systems
Incident Response and Malware Investigations
Analysis of APFS, user, application and system artefacts
Reconstruction of file, user and network activity
Cross-checking the results of automatic parsers
Analysis of deleted, historical or only indirectly visible traces
Documentation for courts, solicitors, businesses and public authorities

This is how the forensic investigation is carried out

1Collection of evidence and documentation of the condition

The Apple device is first clearly identified and documented either by photograph or in writing. We note whether it is switched on or off, logged in, locked or connected to external storage devices. This information may prove crucial later on.

2Technical classification

The chip generation, macOS version, APFS structure, FileVault and relevant security mechanisms are determined. Only then can the appropriate capture method be identified.

3Secure storage that preserves evidence

The backup method is chosen so that as few changes as possible are made to the original. Depending on the situation, RECON ITR can be used for imaging or triage on modern Macs. Other situations require Apple Recovery, Target Disk Mode on Intel-based systems, or Share Disk on Apple Silicon-based systems. Every step is logged.

4Integrity check

Images or logical backups that are created are given unique names, assigned hash values and verified. Analysis and search operations are then carried out on working copies.

5Multi-stage evaluation

RECON LAB, Belkasoft X and X-Ways are combined depending on the specific problem. Where possible, an important result is not derived from a single parser view alone.

6Manual validation

If an artefact is particularly relevant to the evidence, unusual, or only partially supported by standard software, we manually examine raw data, database structures, metadata or file system information. Where necessary, we use our own tools.

7Report and reference to evidence

In the end, we do more than simply list the results displayed by a tool. We explain the technical basis for the findings, what conclusions can be drawn, and where the limitations lie.

Why is this area of investigation relevant to forensics?

Belkasoft X unterstützt laut Hersteller macOS-Datenquellen und APFS und kann Computerabbilder sowie zahlreiche Artefakttypen analysieren. Dadurch eignet es sich als zusätzliche unabhängige Analyseplattform in Mac-Fällen.

The forensic value lies not solely in the volume of data found, but in its origin and reliability. A file name, a timestamp or a database entry can be misleading without context. That is why we document how an artefact may have come into being, what alternative explanations exist and what further evidence supports the findings.

Belkasoft-Ergebnisse werden bei zentralen Befunden mit nativen Mac-Werkzeugen, RECON LAB, X-Ways oder manueller Analyse gegengeprüft. Unterschiedliche Parser können unterschiedliche Ergebnisse liefern.

On modern Macs in particular, attempts at a „traditional“ disk analysis may also fail due to technical limitations. Hardware-based encryption, Secure Enclave, FileVault and APFS clearly illustrate why it is so important to carry out a proper backup before the actual analysis begins. Errors made at this stage cannot always be reversed later on.

Frequently Asked Questions

Was ist bei „APFS-Beweismittel mit Belkasoft X analysieren“ forensisch zu beachten?
Unsere Untersuchung beginnt nicht mit dem Start eines Analyseprogramms, sondern mit der Beweismittelaufnahme. Gerät, Modell, Serien- beziehungsweise Inventarbezug, Anschlusszustand, sichtbarer Systemzustand und vorhandene Peripherie werden dokumentiert. Danach wird entschieden, ob das System ausgeschaltet bleiben muss, ob eine Live-Erfassung sinnvoll ist oder ob ein Recovery-, Target-Disk- beziehungsweise Share-Disk-Verfahren fachlich vertretbar ist. Im nächsten Schritt wird die Sicherungsstrategie festgelegt. Dabei unterscheiden wir zwischen blockorientierter Abbildung, logischer Sicherung und gezielter Triage. Die Wahl hängt nicht von Bequemlichkeit ab, sondern von Hardwaregeneration, FileVault, APFS-Struktur, verfügbarem Entsperrzustand und der konkreten Beweisfrage. Wo technisch möglich, wird schreibgeschützt gearbeitet. Unvermeidbare Zustandsänderungen bei Live- oder Recovery-Maßnahmen werden ausdrücklich protokolliert. Die erzeugte Sicherung wird mit Hashwerten dokumentiert. Die eigentliche Analyse erfolgt nicht auf dem Original, sondern auf einer Arbeitskopie beziehungsweise einem verifizierten Beweisabbild. So können Parser, Suchläufe oder eigene Hilfsprogramme eingesetzt werden, ohne das Originalbeweismittel fortlaufend zu verändern. Belkasoft X setzen wir als zusätzliche Analyse- und Korrelationsplattform ein. Der Hersteller unterstützt macOS-Quellen, APFS sowie verschiedene Imageformate und stellt fallweite Such-, Timeline- und Analysefunktionen bereit. Für zentrale Befunde bleibt die Rückprüfung gegen die ursprüngliche Datenquelle beziehungsweise ein zweites Werkzeug Bestandteil unseres Workflows. Für einen fachfremden Leser ist dabei ein Punkt besonders wichtig: Ein Forensikprogramm „findet“ nicht automatisch die Wahrheit. Es liest Datenstrukturen und interpretiert sie nach bekannten Regeln. Ändert Apple mit einer neuen macOS-Version eine Datenbank oder ein Metadatenformat, kann ein Parser unvollständig oder falsch reagieren. Deshalb prüfen wir bei entscheidenden Befunden, aus welcher Datei, Datenbank oder Dateisystemstruktur das Ergebnis stammt und ob ein zweiter technischer Weg denselben Sachverhalt bestätigt. Das ist auch der Grund, warum wir mehrere Werkzeuge einsetzen. RECON LAB kann Apple-spezifische Strukturen nativ unter macOS auswerten; Belkasoft X bietet eine andere Artefakt- und Korrelationssicht; X-Ways ermöglicht sehr detaillierte Dateisystem- und Rohdatenprüfungen. Stimmen unabhängige Auswertungen überein, erhöht das die Belastbarkeit. Stimmen sie nicht überein, wird die Ursache untersucht und nicht einfach der bequemste Treffer ausgewählt.
How does such a forensic investigation work in practice?
1. Collection of evidence and documentation of the device’s condition The Apple device is first uniquely identified and documented either photographically or in writing. We note whether it is switched on or off, logged in, locked or connected to external storage devices. This information may prove crucial later on. 2 Technical assessment The chip generation, macOS version, APFS structure, FileVault and relevant security mechanisms are determined. Only then can the appropriate acquisition method be determined. 3 Forensically sound backup The backup method is selected to ensure that as little as possible is altered on the original device. Depending on the case, RECON ITR can be used for imaging or triage of modern Macs. Other situations require Apple Recovery, Target Disk Mode for Intel-based systems, or Share Disk for Apple Silicon-based systems. Every step is logged. 4 Integrity check: Images or logical backups created are uniquely named, assigned hash values and verified. Analysis and searches are then carried out on working copies. 5 Multi-stage analysis RECON LAB, Belkasoft X and X-Ways are combined depending on the specific requirements. Where possible, a key finding is not based on a single parser view alone. 6 Manual Validation If an artefact is particularly relevant to the evidence, unusual, or only partially supported by standard software, we manually examine raw data, database structures, metadata or file system information. Where necessary, we use our own tools. 7 Report and evidence reference Ultimately, we do not merely list what a tool has displayed. We explain which technical source underpins the finding, what conclusion is permissible and where the limitations lie.
What is the forensic significance of the findings in this area?
Belkasoft X unterstützt laut Hersteller macOS-Datenquellen und APFS und kann Computerabbilder sowie zahlreiche Artefakttypen analysieren. Dadurch eignet es sich als zusätzliche unabhängige Analyseplattform in Mac-Fällen. Der forensische Wert liegt nicht allein in der Menge gefundener Daten, sondern in deren Herkunft und Belastbarkeit. Ein Dateiname, ein Zeitstempel oder ein Datenbankeintrag kann ohne Kontext missverständlich sein. Deshalb dokumentieren wir, wie ein Artefakt entstanden sein kann, welche Alternativerklärungen bestehen und welche weiteren Spuren den Befund stützen. Belkasoft-Ergebnisse werden bei zentralen Befunden mit nativen Mac-Werkzeugen, RECON LAB, X-Ways oder manueller Analyse gegengeprüft. Unterschiedliche Parser können unterschiedliche Ergebnisse liefern. Gerade auf modernen Macs kann außerdem der Versuch einer „klassischen“ Datenträgeranalyse an technischen Grenzen scheitern. Hardwaregebundene Verschlüsselung, Secure Enclave, FileVault und APFS machen deutlich, warum eine fachgerechte Sicherung vor der eigentlichen Analyse so wichtig ist. Fehler in dieser Phase können später nicht immer rückgängig gemacht werden.
Are assumptions presented as confirmed findings in such an investigation?
No. The results of technical investigations are presented only to the extent that they are supported by the data actually available. Assumptions that cannot be substantiated are not presented as confirmed findings.

LanCologne – macOS Forensics in Cologne

Sie benötigen eine professionelle Untersuchung zu „APFS-Beweismittel mit Belkasoft X analysieren“? LanCologne unterstützt Sie bei der beweissicheren Sicherung, mehrstufigen Auswertung und nachvollziehbaren Dokumentation. Entscheidend ist dabei nicht, möglichst viele automatische Treffer zu erzeugen, sondern technisch belastbare und überprüfbare Beweise zu sichern.

Get in touch now