February 2026
Intermediate to advanced
456 pages
17h 3m
English
This section covers some general forensic techniques to use on macOS systems. In the preceding sections, you learned about the macOS operating system, and you learned where to look for important logs, which is a valuable step in any forensic investigation. Now, you will learn a variety of forensic techniques.
One of the most fundamental steps in forensics is to create a bit-level copy of the suspect drive. If the suspect drive uses macOS, all the techniques you know from Linux or Windows can still be used. You can utilize the dd command along with netcat to make a forensic copy. You can also use the imaging tools within EnCase or Forensic Toolkit. However, macOS provides another way to make a forensically ...
Read now
Unlock full access