03 · APFS, Snapshots & FSEvents
APFS Snapshots and Timestamps: A Forensic Guide for macOS
How APFS volumes, firmlinks, local snapshots and nanosecond timestamps work on macOS, and how to use them to build timelines and spot timestomping.
In-depth macOS forensics guides: artifacts, locations, parsing, SQL and investigative pitfalls.
03 · APFS, Snapshots & FSEvents
How APFS volumes, firmlinks, local snapshots and nanosecond timestamps work on macOS, and how to use them to build timelines and spot timestomping.
01 · Acquisition & Triage
How Apple Silicon changes Mac forensics: Secure Enclave, always-on storage encryption, Share Disk, boot security policy, SSV and acquisition strategy.
03 · APFS, Snapshots & FSEvents
How the macOS .fseventsd logs record file creation, deletion and rename events, how to parse them, and how to estimate dates without per-record timestamps.
06 · TCC & Keychain
Understand macOS keychains for DFIR: login and System keychains, the data protection keychain, iCloud Keychain, metadata value and legal limits.
04 · User Activity
Where knowledgeC.db and Biome store app usage, focus and device state on macOS, how to query ZOBJECT with correct time conversion, and what Biome changed.
05 · Execution & Persistence
Find and analyze macOS persistence: LaunchAgents, LaunchDaemons, launchctl, Background Task Management (sfltool dumpbtm), cron, periodic and profiles.
01 · Acquisition & Triage
How to acquire evidence from a Mac: live vs dead-box, FileVault, Full Disk Access, SIP, order of volatility, and triage with Aftermath, mac_apt and UAC.
02 · Unified Logs
Investigate macOS Unified Logs: tracev3 and uuidtext storage, log show predicates, logarchive collection, private redaction, retention and offline parsing.
05 · Execution & Persistence
Decode the com.apple.quarantine xattr, query QuarantineEventsV2, and use spctl, codesign and unified logs to trace downloads and Gatekeeper decisions.