Session Type
Lab
Name
Take a Byte! Exploring Apple’s macOS Operating System Artifacts in AXIOM
Speakers
Christopher Vance | Magnet Forensics
Description

With Apple’s switch to the APFS file system and new storage paths in macOS Catalina, making sense of Apple’s structures has changed once again. This lab will explore the latest macOS version and the artifacts contained therein to give those from the seasoned examiner to the beginning an understanding to how to analyze these data sets within Magnet AXIOM. Artifacts such as Airdrop, KnowledgeC, USB Devices, log data, and more will be covered in this session. Students will learn how to explore several file types in AXIOM to make the most of their macOS examinations such as plist files, SQLite databases, and more!

If you would like to apply for a CPE credit for attending this lab session, Magnet Forensics will issue a certificate of attendance after the completion of the conference. In order to qualify for this certificate, you must validate your attendance by checking in and checking out of the session on-site.