Program

/

CODE BLUE 2026

Contests/Workshops

Practical macOS DFIR

macOS’s growing popularity has led to its rapid adoption across both enterprise and personal environments. In response, DFIR analysts and researchers must be well-equipped to navigate the unique characteristics of the macOS ecosystem. This practical workshop explores lesser known yet critical aspects of macOS, including an understanding of its core components, forensic artifacts, and real-world scenarios encountered during DFIR and malware investigations. The workshop emphasizes the use of free and open-source software (FOSS) for the extraction and analysis of macOS artifacts. Attendees will gain a distinctive perspective and hands-on experience with macOS forensics - an essential skillset in a landscape traditionally dominated by Windows.

Takeaways:

  1. macOS Built-in Security:
    Exploring the built-in security features of macOS and how they contribute to system protection.
  2. Understanding macOS Forensic Artifacts:
    Identifying and interpreting key forensic artifacts, including PLISTs, SQLite databases, and system logs.
    macOS DFIR with FOSS Collecting and analyzing forensic data from macOS systems using free and open-source tools.
  3. Investigating macOS for Malicious Activity:
    Detecting signs of compromise by examining LaunchAgents, LaunchDaemons, login items, and system configuration databases — supported by case studies and hands-on artifact analysis.

Workshop Outline

  • Title

    Practical macOS DFIR

  • Date

    Nov. 17th 10:00-17:30

  • Venue

    Room1

  • Presents

    Bhargav Rathod

  • Required Skills & Items

    Beginner to intermediate (basic UNIX/Linux CLI knowledge). A macOS device is required (macOS 15+, Intel or Apple Silicon; physical device preferred, VM OK). Tools (DB Browser for SQLite, Exiftool, Apparancy, Aftermath) provided during the workshop.

  • Pre-registration

    Not required

  • Walk-in

    OK

  • Remarks

    Scale: 10-25 participants, individual