SEC504: Hacker Tools, Techniques, and Incident Handling

Experience SANS training through course previews.
Learn MoreLet us help.
Contact usConnect, learn, and share with other cybersecurity professionals
Engage, challenge, and network with fellow CISOs in this exclusive community of security leaders
Become a member for instant access to our free resources.
Sign UpMission-focused cybersecurity training for government, defense, and education
Explore industry-specific programming and customized training solutions
Sponsor a SANS event or research paper
We're here to help.
Contact UsThe latest updates to the Digital Forensics and Incident Response Poster bring a wealth of new sections and enhancements.
The updated Digital Forensics and Incident Response Poster adds new sections and enhancements for macOS 15 and iOS 18 from Sarah Edwards' SANS FOR518 course research.
The latest updates to the Digital Forensics and Incident Response Poster bring a wealth of new sections and enhancements, including significant changes to artifacts in the latest versions of macOS and iOS. These updates are based on cutting-edge research conducted by Sarah Edwards during her work on the SANS FOR518: Mac and iOS Forensic Analysis and Incident Response course, covering macOS 15 and iOS 18.
Download the new update here.
So, what are some of the key updates? While there are too many to cover them all, here are a few highlights:
Biomes are gradually replacing the traditional KnowledgeC and InteractionC databases for tracking user activity. This new format uses protobuf-encoded data to track app usage times and transitions across devices.
This feature tracks device interactions with CarPlay-enabled vehicles, logging activities such as navigation, media playback, and calls.
Spotlight indexes a system to help users search for files by indexing metadata, extended attributes, and even some file content. This can reveal what files a user has searched for and shared.
AirDrop transfers are logged in Unified Logs, recording both accepted and declined transfers, along with file types and the devices involved.
This section covers how devices log interactions between users through apps like Messages, Mail, and Phone, helping to track communication patterns.
The Transparency, Consent, and Control (TCC) database logs sensitive app permissions, such as access to location, contacts, and the microphone, along with timestamps of when permissions were granted.
This section explains how Apple’s XProtect antivirus system quarantines potentially harmful files, giving investigators access to information on flagged files and the reasons behind the quarantine.
This section details how health metrics like steps, heart rate, and other fitness data that might be available to an investigator and analyzed using forensic tools like APOLLO.
This updated section offers insights into Bluetooth interactions, including timestamps for device connections and nearby devices.
A new section on 10. Apple File System (APFS) snapshot mounting explains how to retrieve data from specific points in time, enhancing forensic capabilities when analyzing system changes or historical data.
The updated Digital Forensics Poster equips investigators with cutting-edge knowledge and tools to navigate the ever-evolving Apple ecosystem. From CarPlay interactions to more granular tracking with Biomes and APFS snapshots, these updates provide deep insights into user activities and device interactions across macOS and iOS platforms. Staying current with these advancements is essential for maximizing the potential of forensic investigations on Apple devices.
Please note that to make room for these updates, we’ve removed some older information related to the HFS+ file system and earlier versions of macOS and iOS. If you expect to work with older systems, you may want to hold on to previous versions of the poster!
Equip yourself with the latest forensic insights for macOS and iOS investigations! Download the updated Digital Forensics and Incident Response Poster now and stay ahead with new tools and techniques to uncover vital evidence across Apple devices.
Kathryn Hedley has led various forensic teams since 2010, spending three years embedded within a cross-organizational team, liaising directly with multiple clients. She is currently a Director and Digital Forensic Specialist for Khyrenz Ltd.
Read more about Kathryn Hedley