01 · Acquisition & Triage
Apple Silicon Forensics: What M-Series Macs Change
How Apple Silicon changes Mac forensics: Secure Enclave, always-on storage encryption, Share Disk, boot security policy, SSV and acquisition strategy.
01 · Acquisition & Triage
How Apple Silicon changes Mac forensics: Secure Enclave, always-on storage encryption, Share Disk, boot security policy, SSV and acquisition strategy.
06 · TCC & Keychain
Understand macOS keychains for DFIR: login and System keychains, the data protection keychain, iCloud Keychain, metadata value and legal limits.
05 · Execution & Persistence
Find and analyze macOS persistence: LaunchAgents, LaunchDaemons, launchctl, Background Task Management (sfltool dumpbtm), cron, periodic and profiles.
01 · Acquisition & Triage
How to acquire evidence from a Mac: live vs dead-box, FileVault, Full Disk Access, SIP, order of volatility, and triage with Aftermath, mac_apt and UAC.
02 · Unified Logs
Investigate macOS Unified Logs: tracev3 and uuidtext storage, log show predicates, logarchive collection, private redaction, retention and offline parsing.
05 · Execution & Persistence
Decode the com.apple.quarantine xattr, query QuarantineEventsV2, and use spctl, codesign and unified logs to trace downloads and Gatekeeper decisions.
04 · User Activity
How to use the Spotlight index, mdls, mdfind and com.apple.metadata xattrs to recover download origins, usage counts and file history on macOS.
06 · TCC & Keychain
Analyze macOS TCC.db privacy permissions: access table columns, service names, auth_value meanings, MDM grants, SIP protection and unified log evidence.