Airdrop Forensics

I am working on a case to gather evidence for a file that was sent via Airdrop to another computer.   The environment does not have any DLP client installed on the device. All we have is the file and the hostname in the metadata of the file.   We believe that the hostname was changed when the file was sent over as we are unable to see that hostname from the client's SIEM.  Any MAC Forensic expert can give guidance on how I can find the Mac Address of the sender from the receiver device?   Thanks in advance. 


Posted : 13/12/2021 1:17 am