Saltar al contenido

Guías

Guías detalladas de análisis forense en macOS: artefactos, ubicaciones, análisis, SQL y errores habituales.

Las guías se publican primero en inglés. Las traducciones llegarán más adelante; mientras tanto, aquí están los originales.

01 · Adquisición y triaje

Apple Silicon Forensics: What M-Series Macs Change

How Apple Silicon changes Mac forensics: Secure Enclave, always-on storage encryption, Share Disk, boot security policy, SSV and acquisition strategy.

ENLeer la guía

03 · APFS, instantáneas y FSEvents

FSEvents Forensics: The macOS File System Change Log

How the macOS .fseventsd logs record file creation, deletion and rename events, how to parse them, and how to estimate dates without per-record timestamps.

ENLeer la guía

06 · TCC y llavero

macOS Keychain Forensics: Concepts and Metadata

Understand macOS keychains for DFIR: login and System keychains, the data protection keychain, iCloud Keychain, metadata value and legal limits.

ENLeer la guía

05 · Ejecución y persistencia

Investigating launchd Persistence on macOS

Find and analyze macOS persistence: LaunchAgents, LaunchDaemons, launchctl, Background Task Management (sfltool dumpbtm), cron, periodic and profiles.

ENLeer la guía

01 · Adquisición y triaje

macOS Forensic Acquisition: Live vs Dead-Box Triage

How to acquire evidence from a Mac: live vs dead-box, FileVault, Full Disk Access, SIP, order of volatility, and triage with Aftermath, mac_apt and UAC.

ENLeer la guía

06 · TCC y llavero

TCC Database Forensics: macOS Privacy Permissions

Analyze macOS TCC.db privacy permissions: access table columns, service names, auth_value meanings, MDM grants, SIP protection and unified log evidence.

ENLeer la guía