Practical macOS DFIR
macOS’s growing popularity has led to its rapid adoption across both enterprise and personal environments. In response, DFIR analysts and researchers must be well-equipped to navigate the unique characteristics of the macOS ecosystem. This practical workshop explores lesser known yet critical aspects of macOS, including an understanding of its core components, forensic artifacts, and real-world scenarios encountered during DFIR and malware investigations. The workshop emphasizes the use of free and open-source software (FOSS) for the extraction and analysis of macOS artifacts. Attendees will gain a distinctive perspective and hands-on experience with macOS forensics - an essential skillset in a landscape traditionally dominated by Windows.
Takeaways:
- macOS Built-in Security:
Exploring the built-in security features of macOS and how they contribute to system protection. - Understanding macOS Forensic Artifacts:
Identifying and interpreting key forensic artifacts, including PLISTs, SQLite databases, and system logs.
macOS DFIR with FOSS Collecting and analyzing forensic data from macOS systems using free and open-source tools. - Investigating macOS for Malicious Activity:
Detecting signs of compromise by examining LaunchAgents, LaunchDaemons, login items, and system configuration databases — supported by case studies and hands-on artifact analysis.
Workshop Outline
-
Title
Practical macOS DFIR
-
Date
Nov. 17th 10:00-17:30
-
Venue
Room1
-
Presents
Bhargav Rathod
-
Required Skills & Items
Beginner to intermediate (basic UNIX/Linux CLI knowledge). A macOS device is required (macOS 15+, Intel or Apple Silicon; physical device preferred, VM OK). Tools (DB Browser for SQLite, Exiftool, Apparancy, Aftermath) provided during the workshop.
-
Pre-registration
Not required
-
Walk-in
OK
-
Remarks
Scale: 10-25 participants, individual