Mac forensics

From Simson Garfinkel
Revision as of 09:00, 3 November 2018 by Simson (talk | contribs) (→‎Forensics Programs)
(diff) ← Older revision | Latest revision (diff) | Newer revision → (diff)
Jump to navigationJump to search

Notes on Mac Forensics.

Contents

  • 1 On the Web
  • 2 Apple's Resources
  • 3 Other curricula
  • 4 Drive Image Tools
  • 5 Forensics Programs
  • 6 Terminal Hacks
  • 7 People
  • 8 Archives
  • 9 Course Ideas

On the Web

  • BlacBag Technologies site.
  • MacForensics Lab
  • Mac Forensics Yahoo Group
  • Imaging a FileVault 2-Encrypted Volume using Macquisition
  • Imaging a Fusion Drive with FileVault 2 Encryption using Macquisition
  • Mac OS X on Forensics Wiki

Apple's Resources

  • Apple Security Updates
  • Apple Tech Specs

Other curricula

  • Mac I: Best Practices in MAC Forensics
  • Mac II: Advanced Practices in MAC Forensics

Drive Image Tools

  • Carbon Copy Cloner
  • DiskWarrior

Forensics Programs

  • BlackLight®, by BlackBag Technologies
  • https://davidkoepi.wordpress.com/2011/06/12/macosxaddressbookforensics/

Terminal Hacks

Is FV2 running?

   fdsetup status

People

Ryan Kubasiak, previously ran http://www.macosxforensics.com/, now on the digital crimes team at Apple

Archives

  • MacOS X Forensics, Philip Craiger and Paul Burke, IFIP, DigitalForensics 2006, Advances in Digital Forensics II


Course Ideas

  • Cracking FileVault2 with JohnTheRipper
  • The Diskutil command
Retrieved from "https://simson.net/wiki/index.php?title=Mac_forensics&oldid=1974"

Navigation menu

Page actions

  • Page
  • Discussion
  • View
  • View source
  • History

Page actions

  • Page
  • Discussion
  • More
  • Tools

Personal tools

  • Log in

Pages

  • Bio
  • Consulting
  • Photos
  • Notes
  • Notepaper Generator

Academic

  • Students
  • Courses
  • CV
  • Research
  • Unpublished

Special

  • Main page
  • Recent changes
  • Random page
  • All pages
  • Special pages

Contact

  • Contact
  • Upload a File

Tools

  • What links here
  • Related changes
  • Special pages
  • Printable version
  • Permanent link
  • Page information
Attribution-Noncommercial-No Derivative Works 3.0 Unported
Powered by MediaWiki
  • This page was last edited on 3 November 2018, at 09:00.
  • Content is available under Attribution-Noncommercial-No Derivative Works 3.0 Unported unless otherwise noted.
  • Privacy policy
  • About Simson Garfinkel
  • Disclaimers