August 2017
Intermediate to advanced
336 pages
11h 39m
English
One of the first steps in any forensic examination should be to check the logs. Remember that logs are very important when examining a Windows or a Linux computer. They are just as important when examining a Macintosh computer. This section examines the Macintosh logs and what is contained in them.
The name of this log should suggest that it is a general repository for a lot of information. The naming structure should also seem familiar. Remember that Mac OS X is based on FreeBSD, so seeing file structures similar to Linux should be no surprise.
This directory has many logs in it. The /var/log/daily.out contains data on all mounted volumes, including the dates they were mounted. This is very important in ...
Read now
Unlock full access