IT Forensics · macOS

Forensic analysis of FileVault – assessing the encryption status and access options

FileVault protects data on a Mac through encryption. On Macs with Apple Silicon or the Apple T2 Security Chip, data is already encrypted using hardware-based encryption; FileVault adds an extra layer of protection by linking access to the user’s login credentials or appropriate recovery mechanisms. On older Intel-based Macs without a T2 chip, the technical situation is different and must be assessed separately.

Enquire without obligation

FileVault is particularly relevant to forensic analysis because the encryption and unlock status directly determine which data is accessible on a seized or handed-over system. FileVault is not an activity artefact and, on its own, does not provide any information about who created or used specific files.

Why LanCologne?

Since its foundation, LanCologne has specialised in professional IT forensics. Our staff have decades of experience in the field of information technology and assist companies, solicitors, private individuals and, on a regular basis, the courts in the technical investigation of complex digital matters.

The examination is, as a matter of principle, carried out exclusively on a forensic copy, a forensic image or a data source captured in a technically equivalent manner that preserves the integrity of the evidence. The original evidence remains unchanged and is stored in a manner that preserves its integrity.

Our services

We document the observable encryption status, the hardware platform, existing APFS structures and the access requirements relevant to the collection of evidence in a manner that preserves its integrity. User and recovery context are assessed only within the scope of the information that is actually available and lawfully provided.

In the case of systems that are currently running or have been unlocked, the current access status is documented with particular care, as a subsequent change in status could significantly alter the options for recording this information.

Typical areas of application

Assessment of FileVault and encryption status
Planning forensic data collection
Analysis of Apple Silicon, T2 and older Intel systems
Mapping of encrypted APFS volumes
Incident Response and Preservation of Evidence
Documentation of recovery and user context
Judicial and non-judicial expert reports

This is how the forensic investigation is carried out

First, the model, processor platform and storage structure are documented. The system is then checked to determine which APFS volumes are present and to what extent they are accessible. The investigation is carried out without making any unnecessary changes to the original system.

The specific procedure depends largely on whether the Mac was handed over whilst switched off, switched on, logged in or already unlocked. These states are strictly distinguished in the documentation because they affect the technically feasible backup methods.

Why is this area of investigation relevant to forensics?

FileVault is one of the key components of a modern macOS data preservation process. Particular attention must be paid to hardware-based key mechanisms and the current device status, especially on Apple Silicon and T2 systems.

From a forensic perspective, it is therefore not only crucial to establish that „FileVault is active“, but also to document precisely the platform, the encryption status and the access rights available at the time the backup was made.

Frequently Asked Questions

Is an Apple Silicon Mac encrypted even if FileVault is not enabled?+
Apple describes Apple Silicon as featuring hardware-based data encryption. FileVault enhances this protection by additionally linking access to the user’s or recovery login credentials.
Can FileVault affect the forensic backup?+
Yes. The encryption and unlock status can be a decisive factor in determining which data is technically accessible.
Should Intel, T2 and Apple Silicon Macs be treated the same?+
No. The hardware platform and security architecture must be taken into account when developing a security strategy.
Does FileVault reveal anything about user activity?+
No. FileVault is primarily an encryption and access control mechanism.

LanCologne – macOS Forensics in Cologne

Do you require a professional forensic examination of a FileVault-protected Mac? LanCologne can assist you with the evidence-secure acquisition of data and a technically verifiable analysis.

Get in touch now