
- 576 pages
- English
- ePUB (mobile friendly)
- Available on iOS & Android
Mac OS X, iPod, and iPhone Forensic Analysis DVD Toolkit
About this book
This book provides digital forensic investigators, security professionals, and law enforcement with all of the information, tools, and utilities required to conduct forensic investigations of computers running any variant of the Macintosh OS X operating system, as well as the almost ubiquitous iPod and iPhone. Digital forensic investigators and security professionals subsequently can use data gathered from these devices to aid in the prosecution of criminal cases, litigate civil cases, audit adherence to federal regulatory compliance issues, and identify breech of corporate and government usage policies on networks.MAC Disks, Partitioning, and HFS+ File System Manage multiple partitions on a disk, and understand how the operating system stores data.FileVault and Time Machine Decrypt locked FileVault files and restore files backed up with Leopard's Time Machine.Recovering Browser History Uncover traces of Web-surfing activity in Safari with Web cache and.plist filesRecovering Email Artifacts, iChat, and Other Chat Logs Expose communications data in iChat, Address Book, Apple's Mail, MobileMe, and Web-based email.Locating and Recovering Photos Use iPhoto, Spotlight, and shadow files to find artifacts pof photos (e.g., thumbnails) when the originals no longer exist.Finding and Recovering QuickTime Movies and Other Video Understand video file formats--created with iSight, iMovie, or another application--and how to find them.PDF, Word, and Other Document Recovery Recover text documents and metadata with Microsoft Office, OpenOffice, Entourage, Adobe PDF, or other formats.Forensic Acquisition and Analysis of an iPod Documentseizure of an iPod model and analyze the iPod image file and artifacts on a Mac.Forensic Acquisition and Analysis of an iPhone Acquire a physical image of an iPhone or iPod Touch and safely analyze without jailbreaking.- Includes Unique Information about Mac OS X, iPod, iMac, and iPhone Forensic Analysis Unavailable Anywhere Else- Authors Are Pioneering Researchers in the Field of Macintosh Forensics, with Combined Experience in Law Enforcement, Military, and Corporate Forensics
Frequently asked questions
- Essential is ideal for learners and professionals who enjoy exploring a wide range of subjects. Access the Essential Library with 800,000+ trusted titles and best-sellers across business, personal growth, and the humanities. Includes unlimited reading time and Standard Read Aloud voice.
- Complete: Perfect for advanced learners and researchers needing full, unrestricted access. Unlock 1.4M+ books across hundreds of subjects, including academic and specialized titles. The Complete Plan also includes advanced features like Premium Read Aloud and Research Assistant.
Please note we cannot support devices running on iOS 13 and Android 7 or earlier. Learn more about using the app.
Information
Chapter 1. Solutions in this chapter
- First Responders and Specialized Examiners
- Macintosh History
- Macintosh Aspects
- Macintosh Technologies
- Disk Structure
- Summary
- Solutions Fast Track
- Frequently Asked Questions
Introduction
First Responders and Specialized Examiners
A full analysis could be defined as a complete examination of all digital data on the media being examined, with a report of the relevant findings at the conclusion.A limited scope analysis can be defined as a narrow look at the digital data on the media being examined for the purpose of answering a quick question.
- Facilitate Arrest You have a search warrant and need to find evidence at the crime scene to facilitate and arrest of the target.
- Consent Search You don't have anything more than permission from the target to look, but the permission is the look on-premises only.
- Exigent Circumstances You have a case such as a missing person and a quick look at the most likely useful data sources is warranted.
Digital Examination
- Physically secure evidence or conduct on-site preview (Collection)
- Acquisition of digital media
- Verification of acquired data
- Archive of acquired data with verification
- Analysis of acquired data
- Reporting of results
Techniques for Examination
Live Macintosh Examination
Single User Mode
Using the suspect's own operating system is almost always a bad idea for extended tasks, and can lead to potentially mistaken results. Use Single User Mode carefully.
Boot CD/DVD Methods
Table of contents
- Brief Table of Contents
- Table of Contents
- Copyright
- Technical Editor
- Lead Authors
- Contributing Authors
- About the Mac OS X, iPod, and iPhone Forensic Analysis DVD Toolkit DVD
- Chapter 1. Tiger and Leopard Mac OS X Operating SystemsSolutions in this chapter
- Chapter 2. Getting a Handle on Mac HardwareSolutions in this chapter
- Chapter 3. Mac Disks and PartitioningSolutions in this chapter
- Chapter 4. HFS Plus File SystemSolutions in this chapter
- Chapter 5. FileVaultSolutions in this chapter:
- Chapter 6. Time Machine
- Chapter 7. Acquiring Forensic ImagesSolutions in this chapter:
- Chapter 8. Recovering Browser HistorySolutions in this chapter:
- Chapter 9. Recovery of E-mail Artifacts, iChat, and Other Chat LogsSolutions in this chapter:
- Chapter 10. Locating and Recovering PhotosSolutions in this chapter
- Chapter 11. Finding and Recovering Quicktime Movies and other Video
- Chapter 12. Recovering PDFs, Word Files, and Other DocumentsSolutions in this chapter
- Chapter 13. Forensic Acquisition of an iPodSolutions in this chapter
- Chapter 14. iPod ForensicsSolutions in this chapter
- Chapter 15. Forensic Acquisition of an iPhoneSolutions in this chapter:
- Chapter 16. iPhone ForensicsSolutions in this chapter
- Appendix A. Using Boot Camp, Parallels, and VMware Fusion in a MAC Environment
- Appendix B. Capturing Volatile Data on a Mac