Imaging APFS - A Walkthrough for Starting Forensics on MacOS

  Рет қаралды 9,129

SEVNX

SEVNX

3 жыл бұрын

Here to demystify the imaging process for computers and devices using APFS is SEVN-X's Chief Strategist Matt Barnett.
Tools used in this process (Affiliate Links)
Docking Station
amzn.to/3Axz69j
Disk Drive Reader
amzn.to/3hJzitx
1Tb Western Digital Hard Drive
amzn.to/2SS9oeu
USB-C Cable
amzn.to/3htK8VH
Blog Post
www.sevnx.com/blog/post/creat...
More info at sevnx.com

Пікірлер: 15
@forpaqk
@forpaqk 2 жыл бұрын
Excellent presentation, informative and captivating.
@user-vl7fv4wp8e
@user-vl7fv4wp8e 8 ай бұрын
great sharing, thanks! i have a question, if diskutil is not available while disable disk arbitration, how can we determine which disk is our target disk(synthesized) after connect?
@davidpoole8726
@davidpoole8726 2 жыл бұрын
Very nice how-to. What happens if the device employees the T2 chipset with or without FileVault2?
@sevnxsecurity
@sevnxsecurity 2 жыл бұрын
The device used in this tutorial had the T2 in it. With FV2 enabled, it gets more complex pretty quickly.
@luxmunk
@luxmunk 2 жыл бұрын
Very interesting vid. Forgive my ignorance about forensics, but what is an example of when you’d use this? Is this how one could image an entire Mac? I ask because of the reference you made to the long wait time for completion when you were only handling 1mg. What about 1gb? Or 1tb? I often have such a need when cloning failing harddrives while still installed in the Mac. In the past couple years, I’d pretty much abandoned this method for accessing drives. I was losing faith in Target Disk Mode as a once-go to tool for all kinds of Mac repairs. PS the distinction between an actual Thunderbolt 3 vs a USB-c is a detail I would have taken years of trial and error to discover. Such a beneficial tip. I own an Independent Apple Service shop. Thanks.
@sevnxsecurity
@sevnxsecurity 2 жыл бұрын
This is definitely more of a process you would use when you need to forensically image a device with a 'testifiable' and defensive process. For simple data recovery, it's probably overkill but if it's your only option it is.. well... an option. Hope that helps.
@johnhanley2431
@johnhanley2431 Жыл бұрын
You are a good speaker. However, the music really distracts from following you. For example, when I try to watch on my iPhone with earbuds, the music is too loud and I have to replay sections to hear your words. On my desktop the music is not so loud, but the music is still too distracting. Remove the background music.
@sevnxsecurity
@sevnxsecurity Жыл бұрын
Thanks for the feedback John, I’ll let our editing department know for future videos.
@minorukobayashi3684
@minorukobayashi3684 2 жыл бұрын
This method should not work on M1 Mac. This is because there is no target disk mode.
@sevnxsecurity
@sevnxsecurity Жыл бұрын
It's been replaced with Mac Sharing Mode. It's similar but accessed differently. I haven't imaged an M1/M2 yet but let me know if you'd like us to investigate and do a video on the process for sound imaging principles on Apple Silicon.
@sanjeevgoel7412
@sanjeevgoel7412 2 жыл бұрын
For god sake, remove the music in your videos. It is really annoying.
@sevnxsecurity
@sevnxsecurity 2 жыл бұрын
Thanks for the feedback Sanjeev, we’ve made adjustments in our latest video.
@SoulSox
@SoulSox Жыл бұрын
@@sevnxsecurity Yes, the music is distracting and too loud. Almost impossible to focus on the content.
@IlCapodeiCapiTheBoss
@IlCapodeiCapiTheBoss Ай бұрын
this doesn't seems to work with FV2 /encrypted disk, cause the output is pretty much blank? any solution please? cause cannot unencrypted without mounting/ diskarbritation and needed a thunderbolt to work @sevnxsecurity
@sevnxsecurity
@sevnxsecurity Ай бұрын
Unfortunately, this tutorial does not apply to encrypted disks. You pretty much need the decryption key, and write-blocked hardware to image the drive the usual way.
What is APFS? - The Apple File System Explained
19:53
Computer Clan
Рет қаралды 179 М.
M1 MacBook and Forensics
6:44
Data Rescue Labs Inc.(ForensicGuy)
Рет қаралды 8 М.
OMG😳 #tiktok #shorts #potapova_blog
00:58
Potapova_blog
Рет қаралды 4,4 МЛН
МАМА И STANDOFF 2 😳 !FAKE GUN! #shorts
00:34
INNA SERG
Рет қаралды 4,5 МЛН
Incredible magic 🤯✨
00:53
America's Got Talent
Рет қаралды 29 МЛН
Mac File Systems Explained | APFS, HFS+ & More
8:19
SABRENT USA Official
Рет қаралды 7 М.
Digital Forensics  - What you need to know. Part 1
18:35
Data Rescue Labs Inc.(ForensicGuy)
Рет қаралды 25 М.
The State of Mac Forensics with Steve Whalen from Sumuri
1:11:26
IACIS Podcast
Рет қаралды 353
Understanding the File And Folder Structure Of Your Mac
11:27
macmostvideo
Рет қаралды 371 М.
Don't Waste $1000 on Data Recovery
23:22
Linus Tech Tips
Рет қаралды 4 МЛН
Best digital forensics | computer forensics| cyber forensic free tools
25:16
Information Security Newspaper
Рет қаралды 123 М.
Linux Forensics with Linux - CTF Walkthrough
42:00
DFIRScience
Рет қаралды 14 М.
I Built a NAS: One Year Later. EVERYTHING I Learned and the Mistakes
17:37
Jimmy Tries World
Рет қаралды 807 М.
OMG😳 #tiktok #shorts #potapova_blog
00:58
Potapova_blog
Рет қаралды 4,4 МЛН