03 · APFS, instantáneas y FSEvents
APFS Snapshots and Timestamps: A Forensic Guide for macOS
How APFS volumes, firmlinks, local snapshots and nanosecond timestamps work on macOS, and how to use them to build timelines and spot timestomping.
Guías detalladas de análisis forense en macOS: artefactos, ubicaciones, análisis, SQL y errores habituales.
Las guías se publican primero en inglés. Las traducciones llegarán más adelante; mientras tanto, aquí están los originales.
03 · APFS, instantáneas y FSEvents
How APFS volumes, firmlinks, local snapshots and nanosecond timestamps work on macOS, and how to use them to build timelines and spot timestomping.
01 · Adquisición y triaje
How Apple Silicon changes Mac forensics: Secure Enclave, always-on storage encryption, Share Disk, boot security policy, SSV and acquisition strategy.
03 · APFS, instantáneas y FSEvents
How the macOS .fseventsd logs record file creation, deletion and rename events, how to parse them, and how to estimate dates without per-record timestamps.
06 · TCC y llavero
Understand macOS keychains for DFIR: login and System keychains, the data protection keychain, iCloud Keychain, metadata value and legal limits.
04 · Actividad del usuario
Where knowledgeC.db and Biome store app usage, focus and device state on macOS, how to query ZOBJECT with correct time conversion, and what Biome changed.
05 · Ejecución y persistencia
Find and analyze macOS persistence: LaunchAgents, LaunchDaemons, launchctl, Background Task Management (sfltool dumpbtm), cron, periodic and profiles.
01 · Adquisición y triaje
How to acquire evidence from a Mac: live vs dead-box, FileVault, Full Disk Access, SIP, order of volatility, and triage with Aftermath, mac_apt and UAC.
02 · Registros unificados
Investigate macOS Unified Logs: tracev3 and uuidtext storage, log show predicates, logarchive collection, private redaction, retention and offline parsing.
05 · Ejecución y persistencia
Decode the com.apple.quarantine xattr, query QuarantineEventsV2, and use spctl, codesign and unified logs to trace downloads and Gatekeeper decisions.
04 · Actividad del usuario
Analyze Safari History.db, Downloads.plist, bookmarks and session files on macOS, plus Chrome and Firefox locations, epochs and SQL queries.
04 · Actividad del usuario
How to use the Spotlight index, mdls, mdfind and com.apple.metadata xattrs to recover download origins, usage counts and file history on macOS.
06 · TCC y llavero
Analyze macOS TCC.db privacy permissions: access table columns, service names, auth_value meanings, MDM grants, SIP protection and unified log evidence.