Hi, I’m Rich Frawley and I’m the Digital Forensic Specialist with ADF Solutions. Today we are going to conduct a boot scan of a MacBook Air that has APFS and FileVault 2 enabled.
At this point you have decided on a search profile or profiles to use and and prepared your collection key.
When conducting a boot scan, Digital Evidence Investigator is forensically sound. This means that no changes are made to the target media.
Prior to conducting a boot scan, establish how many USB ports are available and determine if the four-port USB hub is required. Two ports are required in order to complete a scan: one for the collection key and one for the authentication key. Once the scan has started, the authentication key can be removed.