How to Examine an Apple Device
Many forensics tools do a wonderful job of extracting data from Windows machines, but are less effective in macOS. OSForensics version 4.0 will include macOS artifacts in its “recent history.” But, to examine the directories mentioned in this chapter, or to execute the BASH commands, you may need more than these tools can provide.
One technique is to create a copy of the forensic image and to mount it as a read-only virtual machine (VM). It is critical that you mount it as read-only. There are various instructions that can be found on the internet for converting a forensic image to a VM (such as a VMWare or Oracle Virtual box VM). However, the forensic tool Forensic Explorer (http://www.forensicexplorer.com/) will ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access