03 · APFS, Snapshots & FSEvents
APFS Snapshots and Timestamps: A Forensic Guide for macOS
How APFS volumes, firmlinks, local snapshots and nanosecond timestamps work on macOS, and how to use them to build timelines and spot timestomping.
Ausführliche Leitfäden zur macOS-Forensik: Artefakte, Speicherorte, Auswertung, SQL und typische Fallstricke.
Leitfäden erscheinen zuerst auf Englisch. Übersetzungen folgen; bis dahin finden Sie hier die englischen Originale.
03 · APFS, Snapshots & FSEvents
How APFS volumes, firmlinks, local snapshots and nanosecond timestamps work on macOS, and how to use them to build timelines and spot timestomping.
01 · Sicherung & Triage
How Apple Silicon changes Mac forensics: Secure Enclave, always-on storage encryption, Share Disk, boot security policy, SSV and acquisition strategy.
03 · APFS, Snapshots & FSEvents
How the macOS .fseventsd logs record file creation, deletion and rename events, how to parse them, and how to estimate dates without per-record timestamps.
06 · TCC & Schlüsselbund
Understand macOS keychains for DFIR: login and System keychains, the data protection keychain, iCloud Keychain, metadata value and legal limits.
04 · Benutzeraktivität
Where knowledgeC.db and Biome store app usage, focus and device state on macOS, how to query ZOBJECT with correct time conversion, and what Biome changed.
05 · Ausführung & Persistenz
Find and analyze macOS persistence: LaunchAgents, LaunchDaemons, launchctl, Background Task Management (sfltool dumpbtm), cron, periodic and profiles.
01 · Sicherung & Triage
How to acquire evidence from a Mac: live vs dead-box, FileVault, Full Disk Access, SIP, order of volatility, and triage with Aftermath, mac_apt and UAC.
02 · Unified Logs
Investigate macOS Unified Logs: tracev3 and uuidtext storage, log show predicates, logarchive collection, private redaction, retention and offline parsing.
05 · Ausführung & Persistenz
Decode the com.apple.quarantine xattr, query QuarantineEventsV2, and use spctl, codesign and unified logs to trace downloads and Gatekeeper decisions.
04 · Benutzeraktivität
Analyze Safari History.db, Downloads.plist, bookmarks and session files on macOS, plus Chrome and Firefox locations, epochs and SQL queries.
04 · Benutzeraktivität
How to use the Spotlight index, mdls, mdfind and com.apple.metadata xattrs to recover download origins, usage counts and file history on macOS.
06 · TCC & Schlüsselbund
Analyze macOS TCC.db privacy permissions: access table columns, service names, auth_value meanings, MDM grants, SIP protection and unified log evidence.