Tom Doyle


Mac Research

Free Alternatives to FOR518: Mac and iOS Forensic Analysis and Incident Response

A general note: mac4n6.com/resources (Sarah Edwards' own site) is itself a free index of nearly all her SANS DFIR Summit, DEFCON, and BSides talks in PDF/video form, and touches most sections below. It's worth bookmarking on its own: http://www.mac4n6.com/resources


Apple Device Essentials, Security Architecture, and Disks/Volumes

macOS Acquisition Tools and Methods

iOS Acquisition Tools and Methods

Data Organization, Triage, and iCloud Forensics

macOS Unified Logging (Log Analysis)

User Account, Network, and Bluetooth Artifacts

APFS (Apple File System) Internals

Extended Attributes (xattr) and Quarantine

Spotlight Forensics

Document Versions and Metadata

FSEvents (File System Events Store Database)

Mach-O Executable Analysis

Safari (and Browser) Forensics

Messaging and Calling Artifacts (iMessage, FaceTime, Mail)

Notes, Photos, and Maps Analysis

Pattern-of-Life Analysis (APOLLO)

Password Cracking (Keychain, FileVault, User Accounts)

macOS Malware Analysis and Firewall Artifacts

Other Apple Technologies (Find My, AirTags, Time Machine, Apple Watch, HomeKit)