Skip to main content
Laptop opened from below with a visible SSD module on a work matAI-generated

Service

Mac forensics

macOS systems store their traces in APFS structures, unified logs and a range of user artefacts. On Apple silicon, acquisition is constrained by the secure boot architecture and requires the appropriate approach.

What is examined

  • APFS volumes, snapshots and deleted file remnants
  • Unified logs, launch agents and login items
  • User artefacts: Spotlight, quarantine data, browser and mail stores
  • Time Machine backups and connected devices

How the examination is carried out

  1. 1.Acquisition depending on hardware generation, with hashes recorded
  2. 2.Evaluation of snapshots to reconstruct earlier states
  3. 3.Correlation of log entries with file system timestamps
  4. 4.Documentation of every step, including failed acquisition attempts

Technical limits

These limits are stated before the instruction, not afterwards.

  • FileVault volumes require the password or recovery key.
  • On Apple silicon, physical acquisition is not available in the classic sense.
  • Unified logs cover only a limited period.
  • Deleted data on SSDs is frequently unrecoverable due to TRIM.

FREQUENTLY ASKED QUESTIONS

Mac forensics: frequently asked questions

Equipment used

Systems used in this examination

Next step

Discuss your case

Describe the situation briefly. We will say what can realistically be established, and what cannot.

+49 221 99981 490ContactBook an appointment