Notifications
Clear all
Topic starter
13/12/2021 1:17 am
Hi All,Â
I am working on a case to gather evidence for a file that was sent via Airdrop to another computer. Â The environment does not have any DLP client installed on the device. All we have is the file and the hostname in the metadata of the file. Â We believe that the hostname was changed when the file was sent over as we are unable to see that hostname from the client's SIEM. Â Any MAC Forensic expert can give guidance on how I can find the Mac Address of the sender from the receiver device? Â Thanks in advance.Â
Â