This resource is no longer available
This article in our Royal Holloway Information Security Thesis Series provides a technical explanation of how Mac OS X persistence evidences can be extracted for forensic investigation.
Contents include:
- Mac OS X, the hybrid platform
- Types of evidences
- Implementation using the Plaso forensics framework