IT Forensics · macOS

Forensic analysis of macOS disk images

macOS disk images can provide relevant technical evidence as part of a macOS investigation. Examine DMG and other disk image files, as well as any available mount and usage traces. Their presence, integration and actual usage are assessed separately.

Enquire without obligation

To ensure a robust assessment, existing artefacts are not considered in isolation. Configuration, technical condition and verifiable activity must be distinguished from one another and correlated with independent traces.

Why LanCologne?

Since its foundation, LanCologne has specialised in professional IT forensics. Our staff have decades of experience in the field of information technology and assist companies, solicitors, private individuals and, on a regular basis, the courts in the technical investigation of complex digital matters.

The examination is, as a matter of principle, carried out exclusively on a forensic copy, a forensic image or a data source captured in a technically equivalent manner that preserves the integrity of the evidence. The original evidence remains unchanged and is stored in a manner that preserves its integrity.

Our services

We back up and examine the artefacts relevant to „macOS Disk Images“ on forensic working copies. Their origin, location, time references, file system context and technical conditions are documented.

Statements are made only insofar as they are technically supported by the specific, verified data set. The operating system version and artefact-specific characteristics are taken into account in the interpretation.

Typical areas of application

Judicial and non-judicial expert reports
Incident Response and Breach Investigations
Reconstruction of user and system activities
Investigation of security-related configurations
Investigation into possible manipulation
Temporal correlation with other macOS artefacts
Technical evidence preservation and traceable documentation

This is how the forensic investigation is carried out

The relevant data set is first recorded in a manner that preserves its evidential integrity and hashed. Further analysis is carried out on a working copy. The artefacts relevant to the case are then identified, evaluated in a structured manner and correlated with independent traces.

Timestamps, configuration states and logs are assessed according to their actual technical significance. Findings and interpretation are clearly distinguished from one another.

Why is this area of investigation relevant to forensics?

Examine DMG and other disk image files, as well as any available mount and usage traces. The presence, mounting and actual usage are assessed separately.

The specific set of digital traces depends, amongst other things, on the version of macOS, the hardware platform, system settings, the length of time the data has been retained, and any changes made in the meantime. The absence of a single artefact is therefore not, in itself, automatic proof of innocence.

Frequently Asked Questions

What forensic considerations are there regarding „macOS Disk Images“?
We back up and examine the artefacts relevant to „macOS disk images“ on forensic working copies. The origin, storage location, time references, file system context and technical conditions are documented. Conclusions are drawn only to the extent that they are technically supported by the specific data set that has been secured. The operating system version and artefact-specific characteristics are taken into account during interpretation.
How does such a forensic investigation work in practice?
The relevant data set is first captured in a manner that preserves its evidential integrity and hashed. Further analysis is carried out on a working copy. The artefacts relevant to the case are then identified, evaluated in a structured manner and correlated with independent evidence. Timestamps, configuration states and logs are assessed according to their actual technical significance. Findings and interpretation are clearly separated from one another.
What is the forensic significance of the findings in this area?
Examine DMG and other disk image files, as well as any available mount and usage traces. The presence, integration and actual use of these are assessed separately. The specific evidence found depends, amongst other things, on the macOS version, hardware platform, system settings, retention period and any changes made in the meantime. The absence of a single artefact is therefore not, in principle, automatic negative evidence.
Are assumptions presented as confirmed findings in such an investigation?
No. The results of technical investigations are presented only to the extent that they are supported by the data actually available. Assumptions that cannot be substantiated are not presented as confirmed findings.

🔗 Related topics

LanCologne – macOS Forensics in Cologne

Do you require a professional investigation into „macOS disk images“? LanCologne can assist you with the creation of admissible evidence and a technically verifiable analysis.

Get in touch now