IT Forensics · macOS
Forensic analysis of Time Machine snapshots – Investigating previous file states on macOS
Time Machine can create local snapshots of the start-up volume on Macs formatted with APFS. Apple states that these are created approximately every hour and are typically retained for around 24 hours. In addition, a snapshot of the last successful Time Machine backup may remain until the next storage space requirement arises; since macOS High Sierra, a further snapshot has also been created prior to the installation of a macOS Update.
In the field of forensics, such local snapshots can provide access to previous file states or versions. However, their existence and content are not guaranteed. Snapshots may be automatically deleted, particularly when storage space is required.
Why LanCologne?
Since its foundation, LanCologne has specialised in professional IT forensics. Our staff have decades of experience in the field of information technology and assist companies, solicitors, private individuals and, on a regular basis, the courts in the technical investigation of complex digital matters.
The examination is, as a matter of principle, carried out exclusively on a forensic copy, a forensic image or a data source captured in a technically equivalent manner that preserves the integrity of the evidence. The original evidence remains unchanged and is stored in a manner that preserves its integrity.
Our services
We identify existing local Time Machine snapshots, document their timestamps and assign them to the relevant APFS volume. Where technically feasible, we compare relevant files and directories with the current data set and other existing snapshots.
The study makes a clear distinction between local APFS snapshots and external or network-based Time Machine backups. Conclusions are drawn only on the basis of data sets that actually exist and have been analysed.
Typical areas of application
This is how the forensic investigation is carried out
Once the data has been securely captured, any existing APFS snapshots are catalogued and checked to see whether they can be assigned to Time Machine or another system purpose. Relevant snapshots are chronologically ordered and then compared with the current state of the file system.
This takes into account the fact that local Time Machine snapshots can be managed and deleted automatically. A missing snapshot is therefore not proof that Time Machine was not active at a particular point in time. Results are correlated with APFS metadata, FSEvents and other macOS artefacts.
Why is this artefact relevant from a forensic point of view?
Local Time Machine snapshots can provide an earlier version of files, even if the external backup volume is currently unavailable. This means that, in appropriate cases, they can serve as an additional source of historical data.
Their forensic value depends on the actual availability of the snapshots and the period under investigation. They do not constitute an infinitely comprehensive history and must not be equated with a permanent, external ‘time machine’ backup.
Frequently Asked Questions
🔗 Related topics
LanCologne – macOS Forensics in Cologne
Do you need a professional analysis of existing Time Machine snapshots? LanCologne can assist you with the creation of legally admissible backups and the traceable analysis of previous file states.