Apple Pattern of Life Lazy Output’er (APOLLO)
Sarah Edwards presented a new tool called APOLLO or Apple Pattern of Life Lazy Output’er. The tool was presented …
Sarah Edwards presented a new tool called APOLLO or Apple Pattern of Life Lazy Output’er. The tool was presented …
Pasquale Stirparo has started a post series about macOS persistense mechanisms titled “Beyond good ol’ LaunchAge…
Guys, we have created a Telegram group, where we will do our best to answer all your questions. We will be very happy if you…
Sarah Edwards has posted her research of knowledgeC.db database. This database can be found on macOS and iOS devices. O…
afro can parse APFS images. It not only extracts the latest data but also older versions of the files. Learn more about the …
Epochalypse utility by Pasquale Stirparo has been updated. Now it supports APFS timestamps. You can download this Pytho…
Despite the fact APFS isn’t currently supported by AXIOM, the author of “The Swanepoel Method” blog ran a …
During this webinar BlackBag Technologies representatives will show you how to acquire, decrypt and analyze APFS volumes: …
If you are doing macOS memory forensics often enough, we have great news for you – 44 new OS X profiles have been…
Sarah Edwards has found a very usefull bug in macOS High Sierra – unified logs show plaintext password for APFS encryp…
Login