When it comes to the forensic investigation of Apple devices, a Keychain analysis is of particular importance. Not only does Keychain contain passwords from websites and applications, but it can also provide computer forensics with access to the same user’s … Read more
Staying Ahead of Mac Investigations with Apple Forensic Training
BlackBag’s Apple® Forensic Investigations (AF1) class focuses on evidence artifacts rather than parsed data. The idea is that attendees learn how to verify data found during analysis. The course prepares examiners to understand what the data is saying; how the … Read more
How To Parse AirDrop Artifacts In Magnet AXIOM
Hey everyone, Trey Amick from Magnet Forensics here. Today we’re going to be looking at a new set of artifacts specific to Mac investigations, which will be released as part of the AXIOM 3.8 release.
Today we’re going to be … Read more
How To Boot Scan A Mac With APFS And FileVault 2
Hi, I’m Rich Frawley and I’m the Digital Forensic Specialist with ADF Solutions. Today we are going to conduct a boot scan of a MacBook Air that has APFS and FileVault 2 enabled.
At this point you have decided on … Read more
How To Acquire Data From A Mac Using MacQuisition
Justin Matsuhara, Solutions Engineer, BlackBag Technologies
Stephanie Thompson, Solutions Engineer, BlackBag Technologies
Depending on the digital forensic imaging tool you have available, creating a forensic image of a Mac computer can be either an anxiety-creating situation, or as … Read more
Apple iPhone Forensics: Significant Locations
by Patrick Siewert, Principal Consultant, Pro Digital Forensic Consulting
I recently attended a conference of civil litigators in Virginia. During the cocktail hour and after a very interactive CLE presentation on “Leveraging Data in Insurance Fraud Investigations”, I was talking … Read more