Mac OS X, iPod, and iPhone forensic analysis DVD toolkit /

Main Author: Kubasiak, Ryan R.
Other Authors: Morrissey, Sean., Varsalone, Jesse
Format: Book
Language:English
Published: Burlington, MA : Syngress, c2009.
Subjects:
Table of Contents:
  • 1. Tiger and Leopard Mac OS X operating systems
  • 2. Getting a handle on Mac hardware
  • 3. Mac disks and partitioning
  • 4. HFS Plus file system
  • 5. FileVault
  • 6. Time Machine
  • 7. Acquiring forensic images
  • 8. Recovering browser history
  • 9. Recovery of e-mail artifacts, iChat, and other chat logs
  • 10. Locating and recovering photos
  • 11. Finding and recovering Quicktime movies and other video
  • 12. Recovering PDFs, Word files, and other documents
  • 13. Forensic acquisition of an iPod
  • 14. iPod forensics
  • 15. Forensic acquisition of an iPhone
  • 16. iPhone forensics
  • Appendix A. Using Boot Camp, Parallels, and VMware Fusion in a MAC environment
  • Appendix B. Capturing volatile data on a Mac.