Mac and iOS Forensic Analysis and Incident Response

Course Code: IFIS DFI/02

What You Will Learn?

  • Mac and iOS Fundamentals: How to analyze and parse the Hierarchical File System (HFS+) and Apple File System (APFS) by hand and recognize the specific domains of the logical file system and Mac-specific file types.
  • User Activity: How to understand and profile users through their data files and preference configurations.
  • Advanced Intrusion Analysis and Correlation: How to determine how a system has been used or compromised by using the system and user data files in correlation with system log files.
  • Apple Technologies: How to understand and analyze many Mac and iOS-specific technologies, including Time Machine, Spotlight, iCloud, Document Versions, FileVault, Continuity, and FaceTime.

$ 1200


  • Certificate of completion
  • Full access to study materials
  • Access to summit ACADEMY

Share via:

Laptop Requirements

  • Basic Usage of Linux/Mac
  • Comfortable with Terminal Like Interface

About Course

This course aims to enable investigators to investigate the apple devices they encounter. The increasing popularity of Apple devices can be seen everywhere, from college reading rooms, television, restaurants to corporate boardrooms. Dealing with these devices as an investigator is no longer a niche skill.


Prior condition for this course

  • In-Depth File System Examination
  • File System Timeline Analysis
  • Advanced Computer Forensics Methodology
  • Mac Memory Analysis
  • File System Data Analysis
  • Metadata Analysis
  • Recovering Key Mac Files
  • Volume and Disk Image Analysis
  • Analysis of Mac Technologies including Time Machine, Spotlight, and FileVault
  • Advanced Log Analysis and Correlation
  • iDevice Analysis and iOS Artifacts

Course Outline

  • Topic 1: Mac and iOS Essentials
  • Topic 2: File Systems & System Triage
  • Topic 3: User Data, System Configuration, and Log Analysis
  • Topic 4: Application data Analysis
  • Topic 5: Advanced Analysis
  • Topic 6: Mac Forensics & Incident Response

Duration and Fees

Duration: 10 days
Pricing: $1200

Need to know more?

Contact Our team and get all your questions  answered or you can request for a call back

Request a Callback

Talk to us on +256 414 231 136 or fill in these details below and request a callback

By providing your details, you agree to our privacy policy


Follow Us

  • Institute of Forensics & ICT Security, 4th Floor Ntinda Complex
  • Plot 33, Ntinda Road Opp St. Luke Church. P.O. Box 40292, Kampala, Uganda.
  • +256(414) 231136

© All rights reserved Institute od Forensics & ICT Security

Privacy Policy

Terms of Use | Site Map