MEGA: A tool for Mac OS X operating system and application forensics

被引:6
|
作者
Joyce, Robert A. [1 ]
Powers, Judson [1 ]
Adelstein, Frank [1 ]
机构
[1] ATC NY, Ithaca, NY 14850 USA
关键词
Mac OS X; Computer forensics; Spotlight; Disk image analysis; Application analysis;
D O I
10.1016/j.diin.2008.05.011
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Computer forensic tools for Apple Mac hardware have traditionally focused on low-level file system details. Mac OS X and common applications on the Mac platform provide an abundance of information about the user's activities in configuration files, caches, and logs. We are developing MEGA, an extensible tool suite for the analysis of files on Mac OS X disk images. MEGA provides simple access to Spotlight metadata maintained by the operating system, yielding efficient file content search and exposing metadata such as digital camera make and model. It can also help investigators to assess FileVault encrypted home directories. MEGA support tools are under development to interpret files written by common Mac OS applications such as Safari, Mail, and iTunes. (c) 2008 Digital Forensic Research Workshop. Published by Elsevier Ltd. All rights reserved.
引用
收藏
页码:S83 / S90
页数:8
相关论文
共 50 条
  • [1] Mac OS X forensics
    Craiger, Philip
    Burke, Paul
    ADVANCES IN DIGITAL FORENSICS II, 2006, 222 : 159 - +
  • [2] Memory Forensics and the Macintosh OS X Operating System
    Leopard, Charles B.
    Rowe, Neil C.
    McCarrin, Michael R.
    DIGITAL FORENSICS AND CYBER CRIME, ICDF2C 2017, 2018, 216 : 175 - 180
  • [3] TESTING MEMORY FORENSICS TOOLS FOR THE MACINTOSH OS X OPERATING SYSTEM
    Leopard, Charles B.
    Rowe, Neil C.
    McCarrin, Michael R.
    JOURNAL OF DIGITAL FORENSICS SECURITY AND LAW, 2018, 13 (01) : 31 - 42
  • [4] Development of a Methodological Guide for Forensic Analysis in Computer Equipment with Mac OS X Operating System
    Byron Gustavo, Loarte Cajamarca
    Juan Sebastian, Grijalva Lima
    REVISTA PUBLICANDO, 2018, 5 (14): : 24 - 67
  • [5] Mac OS X
    不详
    LIBRARY JOURNAL, 2001, : 8 - 8
  • [6] Mac OS X
    不详
    IEEE MICRO, 1998, 18 (03) : 76 - 76
  • [7] A multimodal data collection tool using REALbasic and Mac OS X
    Peter J. Molfese
    Terri L. Bonebright
    Theresa M. Herman
    Catherine A. Roe
    Behavior Research Methods, Instruments, & Computers, 2002, 34 : 227 - 230
  • [8] A multimodal data collection tool using REALbasic and Mac OS X
    Molfese, PJ
    Bonebright, TL
    Herman, TM
    Roe, CA
    BEHAVIOR RESEARCH METHODS INSTRUMENTS & COMPUTERS, 2002, 34 (02): : 227 - 230
  • [10] Mac OS X密技
    潘登
    桌面出版与设计, 2001, (05) : 72 - 73