Mac OS X, iPod, and iPhone Forensic Analysis DVD Toolkit,
Edition 1Editors: By Jesse Varsalone
-
Inaccessible, or known limited accessibility
Ways Of Reading
-
This e-publication is accessible to the full extent that the file format and types of content allow, on a specific reading device, by default, without necessarily including any additions such as textual descriptions of images or enhanced navigation.
Navigation
-
The contents of the PDF have been tagged to permit access by assistive technologies as per PDF-UA-1 standard.
-
Page breaks included from the original print source
Additional Accessibility Information
-
All (or substantially all) textual matter is arranged in a single logical reading order (including text that is visually presented as separate from the main text flow, e.g., in boxouts, captions, tables, footnotes, endnotes, citations, etc.). Non-textual content is also linked from within this logical reading order. (Purely decorative non-text content can be ignored).
-
The language of the text has been specified (e.g., via the HTML or XML lang attribute) to optimise text-to-speech (and other alternative renderings), both at the whole document level and, where appropriate, for individual words, phrases or passages in a different language.
Conformance
-
The publication was certified on 20250728
-
Accessibility addendum
-
For detailed accessibility information, see Elsevier’s website at https://www.elsevier.com/about/accessibility
-
For queries regarding accessibility information, contact [email protected]
Note
-
This product relies on 3rd party tooling which may impact the accessibility features visible in inspection copies. All accessibility features mentioned would be present in the purchased version of the title.
This book provides digital forensic investigators, security professionals, and law enforcement with all of the information, tools, and utilities required to conduct forensic investigations of computers running any variant of the Macintosh OS X operating system, as well as the almost ubiquitous iPod and iPhone. Digital forensic investigators and security professionals subsequently can use data gathered from these devices to aid in the prosecution of criminal cases, litigate civil cases, audit adherence to federal regulatory compliance issues, and identify breech of corporate and government usage policies on networks.
MAC Disks, Partitioning, and HFS+ File System Manage multiple partitions on a disk, and understand how the operating system stores data.
FileVault and Time Machine Decrypt locked FileVault files and restore files backed up with Leopard's Time Machine.
Recovering Browser History Uncover traces of Web-surfing activity in Safari with Web cache and .plist files
Recovering Email Artifacts, iChat, and Other Chat Logs Expose communications data in iChat, Address Book, Apple's Mail, MobileMe, and Web-based email.
Locating and Recovering Photos Use iPhoto, Spotlight, and shadow files to find artifacts pof photos (e.g., thumbnails) when the originals no longer exist.
Finding and Recovering QuickTime Movies and Other Video Understand video file formats--created with iSight, iMovie, or another application--and how to find them.
PDF, Word, and Other Document Recovery Recover text documents and metadata with Microsoft Office, OpenOffice, Entourage, Adobe PDF, or other formats.
Forensic Acquisition and Analysis of an iPod Documentseizure of an iPod model and analyze the iPod image file and artifacts on a Mac.
Forensic Acquisition and Analysis of an iPhone Acquire a physical image of an iPhone or iPod Touch and safely analyze without jailbreaking.
Key Features
- Includes Unique Information about Mac OS X, iPod, iMac, and iPhone Forensic Analysis Unavailable Anywhere Else
- Authors Are Pioneering Researchers in the Field of Macintosh Forensics, with Combined Experience in Law Enforcement, Military, and Corporate Forensics
About the author
By Jesse Varsalone , Jesse Varsalone is a Cisco Certified Academy Instructor and holds the CCNA certification. Jesse is also a CISSP, MCT, MCSE, and currently works as a Computer Forensics Senior Professional.
Chapter 2 Getting a Handle on Mac Hardware
Chapter 3 Mac Disks and Partitioning
Chapter 4 HFS Plus File System
Chapter 5 FileVault
Chapter 6 Time Machine
Chapter 7 Acquiring Forensic Images
Chapter 8 Recovering Browser History
Chapter 9 Recovery of E-mail Artifacts, iChat, and Other Chat Logs
Chapter 10 Locating and Recovering Photos
Chapter 11 Finding and Recovering Quicktime Movies and other Video
Chapter 12 Recovering PDFs, Word Files, and Other Documents
Chapter 13 Forensic Acquisition of an iPod
Chapter 14 iPod Forensics
Chapter 15 Forensic Acquisition of an iPhone
Chapter 16 iPhone Forensics
Appendix A Using Boot Camp, Parallels, and VMware Fusion in a MAC Environment
Appendix B Capturing Volatile Data on a Mac
9780321240699, Real Digital Forensics: Computer Security and Incident Response (Paperback) Keith J. Jones, Richard Bejtlich, Curtis W. Rose 688 pages. Addison-Wesley, December 2005. Bookscan: 3,508 units. $54.99 Trade Discount. (Book and DVD package)
0121631044; Digital Evidence and Computer Crime: Forensic Science, Computers and the Internet, $69.96, Eoghan Casey. 688 pages Elsevier Academic Press March 2004. 8,891 Units LTD, 1564 Bookscan.