WHAT YOU WILL PRODUCE
A documented examination of a Mac acquisition with a clear account of unavailable evidence.
Identify the Mac before choosing a method
Record the hardware generation, exact macOS build, storage layout and collection method. Apple silicon and Intel-based systems can require different acquisition approaches. Start with a narrow question and a defined time window, then identify which sources might answer it.
This guide assumes an authorized acquisition or supplied training dataset. A mounted volume, a backup, a logical export and a full collection are different evidence sets. Name the actual source rather than using “image” for all of them.
Account for encryption and device state
FileVault and platform encryption affect how stored data can be accessed. On supported Macs, encryption protection also depends on hardware and key management. Apple documents these relationships in its FileVault overview.
Record the observed login and power state at collection, the approved access method and any changes made. Credentials and recovery material belong in the agreed secure handling process, not in screenshots or the public report. If the available method cannot collect a protected volume, document the gap rather than claiming that the volume was empty.
Inventory volumes and snapshots
Document the acquired APFS containers, volumes and any snapshots actually present in the evidence set. Keep a clear mapping between the examiner's working paths and the paths represented in the original collection. Do not assume that a tool's display of one volume covers the whole device.
| Evidence source | Useful examination | Boundary to record |
|---|---|---|
| Acquired user data | Documents and application records within scope | Excluded users, protected paths and collection limits |
| Retained system logs | Events and application context in the captured period | Rotation, redaction, filtering and missing intervals |
| Application databases | Recorded activity and relationships | App version, synchronization and parser support |
| Available snapshots | A historical filesystem state | Snapshot date, coverage and whether it was collected |
| Backup material | Additional preserved content | Backup time and differences from the device state |
Preserve the supplied containers and manifests. Analyze copies, keep generated output separate and record hashes at transfer boundaries.
Investigate one event across sources
Suppose the case question concerns a downloaded application. Start with the available browser or download record, then inspect the acquired file's metadata and any relevant application or system records. Record each source locator and what it actually establishes.
A downloaded file does not prove execution. A cached application record does not independently identify the operator. A valid software signature establishes something about the signed object and its verification result; it is not a universal guarantee of benign behavior. Explain the narrower observation before presenting a broader interpretation.
If the records disagree, preserve both versions. Check whether one represents a synchronized event, a copied file, an installation update or an examiner-generated record. Do not normalize away the disagreement merely to produce a tidy story.
Treat logs as a bounded view
Record the exact log collection interval, filters and parser version. Preserve the original log archive where supplied, along with exported rows. Keep the raw timestamp, displayed offset and UTC interpretation in the timeline. The workstation's display timezone should not silently become the source timezone.
An empty query may mean the event was never logged, the retention period expired, the search filter was too narrow or the collection was incomplete. Phrase negative findings in terms of the sources actually examined: “No matching records were identified in collection E-003 for the specified period.”
Avoid exporting unrelated private data into a general report. Retain the full authorized evidence under case controls and publish only the material needed to explain the finding.
Practice on known data
Use a test Mac or a purpose-built training collection containing a benign download and application launch. Keep a separate ground-truth log. Build a short timeline using at least two available evidence sources and note which expected events your collection does not preserve.
The exercise is successful when another reviewer can reproduce the observation and understand the missing evidence. It is not necessary for every source to contain a record of every action.
Deliver a finding with its limits
Include the system details, acquisition boundary, volume inventory, verification records, tool versions and a timeline with source locators. Clearly distinguish what the collection shows from what remains unknown. Record remediation actions separately so a later reviewer can distinguish incident activity from response work.
Use the case worksheet, synthetic timeline and forensic imaging guide to keep the report and evidence record connected.