±Your Account
Membership:
New Today: 7
New Yesterday: 7
Overall: 24188
Visitors: 45±Latest Webinar
±Latest Articles
· Geo-tagging & Photo Tracking On iOS
· KS – an open source bash script for indexing data
· Mobile Device Geotags & Armed Forces
· Categorization of embedded system forensic collection methodologies
· Interpretation of NTFS Timestamps
· What are ‘gdocs’? Google Drive Data – part 2
· What are ‘gdocs’? Google Drive Data
· Bad Sector Recovery
· Forensic Artifact: Malware Analysis in Windows 8
· Windows 8: Important Considerations for Computer Forensics and Electronic Discovery
· KS – an open source bash script for indexing data
· Mobile Device Geotags & Armed Forces
· Categorization of embedded system forensic collection methodologies
· Interpretation of NTFS Timestamps
· What are ‘gdocs’? Google Drive Data – part 2
· What are ‘gdocs’? Google Drive Data
· Bad Sector Recovery
· Forensic Artifact: Malware Analysis in Windows 8
· Windows 8: Important Considerations for Computer Forensics and Electronic Discovery
±Follow Us
±Latest Jobs
Back to top
Skip to content
Skip to menu
Back to top
Back to main
Skip to menu
Go to page 1, 2 Next
Using a MacPro
Using a MacPro
Posted: Sat Apr 14, 2012 10:26 am
My agency just purchased a Mac Pro for Computer Forensics work. I am relatively new to OSx system and wanted to know what other examiners are using as analysis software. I currently use FTK and Encase as examination software and would like what is comparable to these two products for the Mac.
-

mrpumba - Senior Member
Re: Using a MacPro
Posted: Sat Apr 14, 2012 10:42 am
A very similar thread can be found at www.forensicfocus.com/...ic/t=8966/
-
ro63rt.sm1th - Newbie
Re: Using a MacPro
Posted: Sat Apr 14, 2012 5:06 pm
ro63rt.sm1th, I saw that link but that seems to mentioning examination of a Mac product. Although, I did see the link for Mac Forensics Labs, and will look into that further. Besides that, are there any others worth looking into that will run on the Mac OS?
-

mrpumba - Senior Member
Re: Using a MacPro
Posted: Sun Apr 15, 2012 5:43 am
Blackbagtech - Blacklight is pretty good.
For using Windows based tools install VirtualBox and you can load up the usual (XWays, etc.)
For using Windows based tools install VirtualBox and you can load up the usual (XWays, etc.)
-

binarychimp - Newbie
Re: Using a MacPro
Posted: Sun Apr 15, 2012 7:02 am
mrpumba:
If you are looking for forensic tools to run in the MacOS on your MacPro, I again refer to the posts in the other thread. You will need to research those tools to determine what systems they are capable of examining. Some, if not all, of the tools mentioned can be used for examining systems other than MacOS.
Alternatively, you can run Windows or other operating systems of your choice using bootcamp or a VM. This will allow you to install forensic tools that have not been ported to natively install on the MacOS (EnCase, FTK, X-Ways, etc).
I do not know who first made the connection, but I have found it to be very helpful...
When examining a Mac device, use a Mac and related tools to conduct the examination. Likewise with Windows or any other OS.
If you are looking for forensic tools to run in the MacOS on your MacPro, I again refer to the posts in the other thread. You will need to research those tools to determine what systems they are capable of examining. Some, if not all, of the tools mentioned can be used for examining systems other than MacOS.
Alternatively, you can run Windows or other operating systems of your choice using bootcamp or a VM. This will allow you to install forensic tools that have not been ported to natively install on the MacOS (EnCase, FTK, X-Ways, etc).
I do not know who first made the connection, but I have found it to be very helpful...
When examining a Mac device, use a Mac and related tools to conduct the examination. Likewise with Windows or any other OS.
-
ro63rt.sm1th - Newbie
Re: Using a MacPro
Posted: Sun Apr 15, 2012 7:34 pm
I have Blacklight and Mac Forensics Lab. I really like Blacklight, and it's much more user friendly. Also if you are LE you can get some free Mac tools through acesle.org and Mac Marshall.
-

darin2 - Newbie
Re: Using a MacPro
Posted: Tue Apr 17, 2012 7:39 am
Noted ro63rt.sm1th. darin2 I just picked up P2P and Mac Marshal, I'm working on the use of those programs. I will also check out Blacklight and see what that has to offer.
-

mrpumba - Senior Member
















