A Deep Dive into Apple Keychain Decryption

When it comes to the forensic investigation of Apple devices, a Keychain analysis is of particular importance. Not only does Keychain contain passwords from websites and applications, but it can also provide computer forensics with access to the same user’s… Read more

Staying Ahead of Mac Investigations with Apple Forensic Training

BlackBag’s Apple® Forensic Investigations (AF1) class focuses on evidence artifacts rather than parsed data. The idea is that attendees learn how to verify data found during analysis. The course prepares examiners to understand what the data is saying; how the… Read more

How To Parse AirDrop Artifacts In Magnet AXIOM

Hey everyone, Trey Amick from Magnet Forensics here. Today we’re going to be looking at a new set of artifacts specific to Mac investigations, which will be released as part of the AXIOM 3.8 release. Today we’re going to be… Read more

How To Boot Scan A Mac With APFS And FileVault 2

Hi, I’m Rich Frawley and I’m the Digital Forensic Specialist with ADF Solutions. Today we are going to conduct a boot scan of a MacBook Air that has APFS and FileVault 2 enabled. At this point you have decided on… Read more

How To Acquire Data From A Mac Using MacQuisition

Written by: Justin Matsuhara, Solutions Engineer, BlackBag Technologies Stephanie Thompson, Solutions Engineer, BlackBag Technologies Depending on the digital forensic imaging tool you have available, creating a forensic image of a Mac computer can be either an anxiety-creating situation, or as… Read more

Apple iPhone Forensics: Significant Locations

by Patrick Siewert, Principal Consultant, Pro Digital Forensic Consulting I recently attended a conference of civil litigators in Virginia. During the cocktail hour and after a very interactive CLE presentation on “Leveraging Data in Insurance Fraud Investigations”, I was talking… Read more