How to Examine a Mac
Many forensics tools do a wonderful job of extracting data from Windows machines, but are less effective in Macintosh. OSForensics version 4.0 will include Mac OS X artifacts in its recent history, but to examine the directories mentioned in this chapter, or to execute the Bash commands, you may need more than tools can provide.
One technique is to create a copy of the forensic image and then mount it as a read-only virtual machine (VM). It is critical that you mount it read only. You can find instructions on the Internet for converting a forensic image to a virtual machine (such as a VMWare or Oracle VirtualBox). However, the forensic tool Forensic Explorer (http://www.forensicexplorer.com) will mount forensic images ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access