03 · APFS, Snapshots & FSEvents
APFS Snapshots and Timestamps: A Forensic Guide for macOS
How APFS volumes, firmlinks, local snapshots and nanosecond timestamps work on macOS, and how to use them to build timelines and spot timestomping.
Read guide
03 · Evidence area
APFS gives you nanosecond timestamps, a sealed system volume and point-in-time snapshots, while fseventsd quietly records which paths were created, renamed or deleted. Together they rebuild what happened on disk, even for files that are gone.
2 guides in this area
03 · APFS, Snapshots & FSEvents
How APFS volumes, firmlinks, local snapshots and nanosecond timestamps work on macOS, and how to use them to build timelines and spot timestomping.
03 · APFS, Snapshots & FSEvents
How the macOS .fseventsd logs record file creation, deletion and rename events, how to parse them, and how to estimate dates without per-record timestamps.
Where each artifact lives, what it proves, its timestamps and the tools to parse it.