DF420 - Mac Examinations with EnCase

Course Overview

The introduction of the iPod, iPhone, and iPad and the use of Intel-based processors have generated a steep increase in the sales of Macintosh computers, which are no longer restricted to the realm of desktop publishing and computer-aided design. Computer users are attracted by the design of the Macintosh, its UNIX-like stability, ease-of-use, and its ability to run Microsoft® Windows. Most die-hard Windows users will refuse to return their Mac once they’ve started using it.

This hands-on course makes a departure from the world of Microsoft Windows and provides in-depth instruction on analyzing the various Mac operating system artifacts.

Students attending this course will learn the following:

  • Acquisition of internal storage in an Apple Macintosh and disk layout
  • HFS+ volume structure including in-depth analysis of the Catalog and Extents Overflow files and low-level file recovery
  • APFS container and volume structures, including data recovery using APFS checkpoints
  • Fundamental Mac OS operations, Mac disk, and disk-image analysis and acquisition
  • Mac OS system, user, application, and Internet artifacts

Audience

This course is intended for EnCase users working as law enforcement officers, corporate and private investigators, computer forensic examiners, and network security personnel. A basic understanding of the concepts of computer forensics is required. This class continues the tuition provided in the DF210-Building an Investigation course with a focus on conducting examinations of the Mac operating systems.

Learn more about our training courses

We are excited about your interest in our courses and eager to provide you with all the details you need.

Send us a message via the contact form and we will get back to you as soon as possible.

Send us your enquiries