Apple (Mac) Computer Forensic Analysis
- Log in to post comments
In our computer forensics and Information Security practice, we frequently encounter the need to examine Apple computers. Although tools, such as Encase and FTK can be effective in analyzing HFS+ systems (this is the Mac file system), the examiner has to take other steps. For example, things such as recovering deleted files and creating an image that can be effectively analyzed can be done very effectively by a computer forensics examiner who is familiar with Macs. Why is using a Mac important for examining other Macs? Is a FireWire acquisition useful to cost the imaging time? How do you recover deleted files? We are familiar with examination of Apple Mac HFS+ computers. Whether the case is a criminal case involving digital evidence, a civil case involving computer forensics, a domestic relations case requiring analysis of data, or a case involving the forensic analysis of a smart phone, we have the necessary qualifications and experience.
We use Macs to do the acquisition and utilize fast connections to speed up the acquisition while maintaining the integrity of the process. Although we are known as a Virginia computer forensics expert, we assist attorneys and businesses throughout the United States regarding issues related to the best practices for acquiring evidence from Apple computers. For a computer forensics consultation, you may find our contact information here.