01 · Acquisition & Triage
macOS Forensic Acquisition: Live vs Dead-Box Triage
How to acquire evidence from a Mac: live vs dead-box, FileVault, Full Disk Access, SIP, order of volatility, and triage with Aftermath, mac_apt and UAC.
macOS DFIR field reference
Where macOS keeps its evidence, how to collect it without breaking it, and how to turn Unified Logs, FSEvents, KnowledgeC, TCC and launchd into one defensible story.
/evidence-map
Six areas cover the questions every Mac investigation asks: how to collect, what ran, what changed on disk, what the user did, how it persisted, and what it was allowed to touch.
Collect a Mac without losing evidence: Aftermath, mac_apt, UAC and Apple Silicon.
2 guides
Query tracev3 logs for logins, sudo, SSH, installs, Gatekeeper and TCC prompts.
1 guide
Read APFS timestamps, mount local snapshots and replay file-system change history.
2 guides
KnowledgeC, Biome, Spotlight and Safari: what the user opened, when and for how long.
3 guides
Trace downloads through quarantine and Gatekeeper, then hunt LaunchAgents and login items.
2 guides
See which apps were granted Full Disk Access, screen recording or accessibility, and what the keychain reveals.
2 guides
/guides
01 · Acquisition & Triage
How to acquire evidence from a Mac: live vs dead-box, FileVault, Full Disk Access, SIP, order of volatility, and triage with Aftermath, mac_apt and UAC.
02 · Unified Logs
Investigate macOS Unified Logs: tracev3 and uuidtext storage, log show predicates, logarchive collection, private redaction, retention and offline parsing.
03 · APFS, Snapshots & FSEvents
How the macOS .fseventsd logs record file creation, deletion and rename events, how to parse them, and how to estimate dates without per-record timestamps.
04 · User Activity
Where knowledgeC.db and Biome store app usage, focus and device state on macOS, how to query ZOBJECT with correct time conversion, and what Biome changed.
06 · TCC & Keychain
Analyze macOS TCC.db privacy permissions: access table columns, service names, auth_value meanings, MDM grants, SIP protection and unified log evidence.
05 · Execution & Persistence
Find and analyze macOS persistence: LaunchAgents, LaunchDaemons, launchctl, Background Task Management (sfltool dumpbtm), cron, periodic and profiles.
/method
Every guide starts from the file on disk: path, format, epoch and the question it answers.
macOS changes artifacts between releases. Guides flag what moved, what was renamed and what to verify on your target.
Collection, parsing and detection only. No exploit code, no bypass recipes, no credential theft.
/glossary
Short definitions of the terms you will meet in every macOS case.