Mac Basics
It is important that you have a working understanding of the macOS operating system before attempting forensics. As with Linux, however, it is common for forensic examiners not to have a good working knowledge of macOS systems. The reason for this is simple: Most people have more exposure to Windows than to macOS. In fact, it is not uncommon to have a forensic examiner who may have never even used an Apple device. However, that is a very bad approach to forensics. It may also lead to that examiner’s opinions being ruled inadmissible (i.e., a Daubert Challenge, as described in chapter 1). Therefore, this section first shows you the history of the macOS and then discusses the operating system fundamentals. This will establish a baseline ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access