HeX-OR Forensics
Digital Forensics & Information Assurance

Search

Tags

Analysis Apple Backup Data Exfiltration Driver Stacks Enumeration Exfiltration File System FSEvents Google iOS Mac Artifacts MSC MTP News OS X osx Parsers privacy PTP Python Registry Research USB Devices Wifi
Menu Close
  • Resources
  • About

Author: Nicole Ibrahim

0

SANS DFIR Summit 2017: Mac OS X and iOS FSEvents Presentation

Posted on July 1, 2017 by Nicole Ibrahim

Another big thank you going out to the SANS crew for inviting me to speak at the DFIR summit 2017 in Austin. It was a great pleasure and an amazing conference. My presentation slides are available for download here Mac… Continue Reading →

Conferences, Mac
3

Apple FSEvents Forensics

Posted on June 7, 2017 by Nicole Ibrahim

Undocumented, unexplored, and underutilized, that is until now. Apple FSEvents or File System events are an invaluable artifact for every Apple examiner and should be a go to resource for artifacts relating to file system activity that occurred in the past.… Continue Reading →

Mac, Research, Scripting Apple, File System, FSEvents, iOS, Mac Artifacts, OS X, osx, Parsers, Python

Recent Posts

  • SANS DFIR Summit 2017: Mac OS X and iOS FSEvents Presentation
  • Apple FSEvents Forensics
  • SANS DFIR Summit 2014 Presentation Slides: USB Devices and Media Transfer Protocol
  • Part 6: USB Device Research – Open File Artifacts (LNK Files)
  • Part 5: USB Device Research – Directory Traversal Artifacts (Shell bagMRU Entries)

Recent Comments

  • Joachim Metz on Apple FSEvents Forensics
  • FSEventsParser 3.1 Released : Learn DFIR on Apple FSEvents Forensics
  • The Windows 7 Event Log and USB Device Tracking :: Digital Forensics Stream on Part 4: USB Device Research – The Testing Environment & Registry Artifacts for USB Devices at First Insert
  • Apple FSEvents Forensics – Cyber Forensicator on Apple FSEvents Forensics
  • ShellBags Explorer 0.9.0.0 released! – sec.uno on Part 5: USB Device Research – Directory Traversal Artifacts (Shell bagMRU Entries)

Archives

Categories

  • Conferences
  • Mac
  • Ramblings
  • Research
  • Scripting
  • Windows
© 2019 HeX-OR Forensics. All rights reserved.
Hiero by aThemes