Program

/

CODE BLUE 2026

Contests/Workshops

Practical macOS DFIR

macOS’s growing popularity has led to its rapid adoption across both enterprise and personal environments. In response, DFIR analysts and researchers must be well-equipped to navigate the unique characteristics of the macOS ecosystem. This practical workshop explores lesser known yet critical aspects of macOS, including an understanding of its core components, forensic artifacts, and real-world scenarios encountered during DFIR and malware investigations. The workshop emphasizes the use of free and open-source software (FOSS) for the extraction and analysis of macOS artifacts. Attendees will gain a distinctive perspective and hands-on experience with macOS forensics - an essential skillset in a landscape traditionally dominated by Windows.

Takeaways:

  1. macOS Built-in Security:
    Exploring the built-in security features of macOS and how they contribute to system protection.
  2. Understanding macOS Forensic Artifacts:
    Identifying and interpreting key forensic artifacts, including PLISTs, SQLite databases, and system logs.
    macOS DFIR with FOSS Collecting and analyzing forensic data from macOS systems using free and open-source tools.
  3. Investigating macOS for Malicious Activity:
    Detecting signs of compromise by examining LaunchAgents, LaunchDaemons, login items, and system configuration databases — supported by case studies and hands-on artifact analysis.

Workshop Outline

  • タイトル

    Practical macOS DFIR

  • 日時

    11月17日 10:00-17:30

  • 会場

    Room1

  • 主催

    Bhargav Rathod

  • 必要なスキル・持ち物

    初級〜中級(UNIX/Linux CLIの基礎知識)。macOSデバイス必須(macOS 15以降、Intel/Apple Silicon、実機推奨・VM可)。ツール(DB Browser for SQLite、Exiftool、Apparancy、Aftermath)は当日提供。

  • 事前登録

    不要

  • 当日参加

    可

  • 備考

    規模:最小10名〜最大25名・個人単位