OMG, Seriously? – APFS Encrypted Plaintext Password found in ANOTHER (More Persistent!) macOS Log File

At some point you just need to stop looking and be blissfully ignorant…this was not one of those days. In and update to my previously updated blog article, I have found another instance where the plaintext password was written to system logs.&nb… Continue reading OMG, Seriously? – APFS Encrypted Plaintext Password found in ANOTHER (More Persistent!) macOS Log File

Uh Oh! Unified Logs in High Sierra (10.13) Show Plaintext Password for APFS Encrypted External Volumes via Disk Utility.app

I’ve been updating my course (Mac and iOS Forensics and Incident Response) to use new APFS disk images (APFS FTW!) and came across something that both incredibly useful from a forensics perspective but utterly horrifying from a security standpoint. Scr… Continue reading Uh Oh! Unified Logs in High Sierra (10.13) Show Plaintext Password for APFS Encrypted External Volumes via Disk Utility.app

Script Update – Mac MRU Parser v1.5 – Added Volume Analysis Support and Other Stuff!

Get the script here!Added volume analysis support for the following plists. These are not really MRUs but it could be damn useful to gather this info.Sidebar List plist [10.12-] – /Users/<username>/Library/Preferences/com.apple.sidebarl… Continue reading Script Update – Mac MRU Parser v1.5 – Added Volume Analysis Support and Other Stuff!

Mount All the Things! – Mounting APFS and 4k Disk Images on macOS 10.13

Recently there has been some questions on the forums and Twitter as to how to mount forensic disk images that were captured from Mac system that implemented 4k block sizes. A few years ago, Mac systems started to use 4k blocks instead of 512 byte block… Continue reading Mount All the Things! – Mounting APFS and 4k Disk Images on macOS 10.13

Script Update – Mac MRU Parser – Spotlight Shortcuts & BLOB Parsing!

Get the script here!Added in Spotlight ShortcutsI’ve updated my macMRU.py script to parse the Spotlight Shortcuts plist file that I consider to be very MRU-like. This plist file contains what the user typed into the Spotlight search window, what they c… Continue reading Script Update – Mac MRU Parser – Spotlight Shortcuts & BLOB Parsing!