This course is accredited by:

Download our Prospectus Download Course Content

Forthcoming dates

Book your training three months in advance of the course start date and get a 20% discount, as reflected in the pricing below

  • CPE Credits: 24
  • MSc credits:

Courses available in

  • 7Safe courses in england
  • Digital Forensics

Certified Mac Forensics Specialist (CMFS)

Specialist - level course

Apple is increasing its market share in both the private and commercial/corporate marketplace.  This three-day course concentrates on identifying what is, how can I find, extract, decode and interpret the data stored on an Apple device from a forensic practitioner's perspective, using hands-on exercises to demonstrate and reinforce understanding.

How will I benefit?

This course will give you the opportunity to:

  • Develop confidence when faced with Apple systems and required to collect data from Mac systems
  • Learn effective techniques to process and interpret data and artefacts from Mac OS
  • Learn effective techniques for the identification and interpretation of forensic artefacts on Apple systems
  • Improve your ability to respond effectively to a wider range of forensic incidents

 Want to know more? Watch the video below

“An excellent course which gave a thorough overview of Mac Forensics, the HFS+ file system and important artefacts and their locations on the file system. The exercises supported the theory well and helped build on the course content. As a non-Mac user, I now feel a lot more confident working with Macs, not just for forensic analysis, but generally.”

CMFS Delegate

The Babraham Institute

Have you completed this course? Click below to add to your LinkedIn profile

LinkedIn Add to Profile button

 

For more information about this course, please see below

  • About this course
    This course concentrates on identifying what is, how can I find, extract, decode and interpret the data stored on an Apple device from a forensic practitioner's perspective, using hands-on exercises to demonstrate and reinforce understanding.
  • What will I learn?

    Upon completion of the course you will have:-

    • collected volatile data from a live Mac system
    • Explored different approaches to imaging and decrypting Mac systems
    • An understanding of the new APFS file system
    • Practical knowledge of Apple partitioning schemes and the HFS+ file system
    • Examined a Mac system for configuration of user accounts, Application/data
    • An understanding of Time Machine
    • Interpreted data from unified logs, Plists and SQLite databases
  • Who should attend?

    Forensic practitioners, systems administrators and cyber investigators who want to extend their experience with Window-based systems to the Mac environment.

For more information on this course, please email the Education team or contact us on +44(0)1763 285285

To download the full course content click here and the complete training prospectus click here

« BACK

« Back