IT Forensics · macOS
Forensic analysis of FileVault – assessing the encryption status and access options
FileVault protects data on a Mac through encryption. On Macs with Apple Silicon or the Apple T2 Security Chip, data is already encrypted using hardware-based encryption; FileVault adds an extra layer of protection by linking access to the user’s login credentials or appropriate recovery mechanisms. On older Intel-based Macs without a T2 chip, the technical situation is different and must be assessed separately.
FileVault is particularly relevant to forensic analysis because the encryption and unlock status directly determine which data is accessible on a seized or handed-over system. FileVault is not an activity artefact and, on its own, does not provide any information about who created or used specific files.
Why LanCologne?
Since its foundation, LanCologne has specialised in professional IT forensics. Our staff have decades of experience in the field of information technology and assist companies, solicitors, private individuals and, on a regular basis, the courts in the technical investigation of complex digital matters.
The examination is, as a matter of principle, carried out exclusively on a forensic copy, a forensic image or a data source captured in a technically equivalent manner that preserves the integrity of the evidence. The original evidence remains unchanged and is stored in a manner that preserves its integrity.
Our services
We document the observable encryption status, the hardware platform, existing APFS structures and the access requirements relevant to the collection of evidence in a manner that preserves its integrity. User and recovery context are assessed only within the scope of the information that is actually available and lawfully provided.
In the case of systems that are currently running or have been unlocked, the current access status is documented with particular care, as a subsequent change in status could significantly alter the options for recording this information.
Typical areas of application
This is how the forensic investigation is carried out
First, the model, processor platform and storage structure are documented. The system is then checked to determine which APFS volumes are present and to what extent they are accessible. The investigation is carried out without making any unnecessary changes to the original system.
The specific procedure depends largely on whether the Mac was handed over whilst switched off, switched on, logged in or already unlocked. These states are strictly distinguished in the documentation because they affect the technically feasible backup methods.
Why is this area of investigation relevant to forensics?
FileVault is one of the key components of a modern macOS data preservation process. Particular attention must be paid to hardware-based key mechanisms and the current device status, especially on Apple Silicon and T2 systems.
From a forensic perspective, it is therefore not only crucial to establish that „FileVault is active“, but also to document precisely the platform, the encryption status and the access rights available at the time the backup was made.
Frequently Asked Questions
🔗 Related topics
LanCologne – macOS Forensics in Cologne
Do you require a professional forensic examination of a FileVault-protected Mac? LanCologne can assist you with the evidence-secure acquisition of data and a technically verifiable analysis.
Related to this topic
- Forensic analysis of the Secure Enclave – correctly assessing hardware-based security mechanisms
- Forensic analysis of FSEvents – reconstructing file system changes on macOS
- Forensic analysis of Time Machine snapshots – Investigating previous file states on macOS
- Forensic analysis of the macOS KnowledgeC database