Suggested Essential...
 
Notifications
Clear all

Suggested Essential Mac Forensic Tools for LE

6 Posts
5 Users
0 Reactions
687 Views
(@peeler)
New Member
Joined: 17 years ago
Posts: 3
Topic starter  

Morning All,

Just getting into examining Macs using EnCase 6.19.4 (The EnC 7 Licence is firmly in the bottom draw), Emailchemy and a Mini-Mac. I have recently completed GS's Mac Course (which was excellent by the way but has not tempted me to have another go with EnC 7).

I was looking for some feedback on what tools others are using to examine Macs that might improve/enhance my first fumbling steps into the field.

Any/All Comments and suggestions welcome


   
Quote
 dill
(@dill)
Eminent Member
Joined: 15 years ago
Posts: 39
 

FTK is very good for examining the OSX operating system.
Although, you can download a free PLIST reader for windows.


   
ReplyQuote
(@peeler)
New Member
Joined: 17 years ago
Posts: 3
Topic starter  

Thanks for the reply Dill, I have requested funding for the software and training but that is likely to be a big fat no. No-one else in the office has had any FTK training since V1.x as it fell into disrepute with V2 which came out as I arrived hence I have no training what so ever with FTK.

I have the Windows Plist reader, scalpel and photorec but always interested to find out what everyone else is using.


   
ReplyQuote
rayp
 rayp
(@rayp)
Eminent Member
Joined: 16 years ago
Posts: 42
 

For LE I would also recommend MacMarshal from ATC-NY. It is free for LE and they will provide free training on how to use it. I was MacMarshal before FTK3 came out to process Macs. ATC-NY also has another great free LE tool called P2PMarshal for processing P2P cases.


   
ReplyQuote
nlpd120
(@nlpd120)
Trusted Member
Joined: 15 years ago
Posts: 96
 

File Juicer. http//echoone.com/filejuicer/forensics

Sumuri's Paladin (Intel versions get both v1 and 2). www.sumuri.com

Forward Discovery's Raptor (PowerPC version). www.forwarddiscovery.com/Raptor

I'll second MacMarshal. www.macmarshal.com

MacOSX
Learn terminal command line specifically with regards to obtaining disk information, hashing, imaging, show hidden files, and disk arbitration.

Be familiar with Sudo use in the command line.

Be familiar with Inspector/GetInfo

Hopefully your training covered these.

Be sure to check out www.appleexaminer.com and the websites listed above.

Regards,

Chris Currier


   
ReplyQuote
(@ro63rt-sm1th)
New Member
Joined: 13 years ago
Posts: 4
 

+1 on www.appleexaminer.com

Consider looking at the products and training available from BlackBag Technologies (www.blackbagtech.com) and MacForensicsLab (www.macforensicslab.com).


   
ReplyQuote
Share: