AboutDFIR.com – The Definitive Compendium Project
Digital Forensics & Incident Response

For information on file signature analysis (OS agnostic and file-type specific), please check out Gary Kessler’s File Signature Table

Artifact or ProcessResource
APFS File TimestampsFile Timestamps for Apple APFS
APOLLOExploring macOS with APOLLO
APOLLONew Webinar: Analyzing macOS with BlackLight's APOLLO Plugin
APOLLOAPOLLO github - Sarah Edwards
Apple Unified LogsAnalysis of Apple Unified Logs: Quarantine Edition [Entry 8] – Man! What a process!?
Apple Unified LogsAnalysis of Apple Unified Logs: Quarantine Edition [Entry 9] – We all know you're binging Netflix! Now Playing on your Apple Devices!
Apple Unified LogsAnalysis of Apple Unified Logs: Quarantine Edition [Entry 10] – You down with TCC? Yea, you know me! Tracking App Permissions and the TCC APOLLO Module
BookmarksBookmarks, a type of Alias: their access and use
DiscordFinding Discord chats in OS X
fseventd parsermacos_fseventsd parser github - puffyCid
iOS Apps on M1Taking a gander at iOS apps on an M1 Mac
LogsHow to find it in the log: 1 An introduction - hoakley and Part 2
Logs - Unified Log RollingRolling logs and anti-malware scans - The Eclectic Light Company
mac_aptmac_apt github - Yogesh Khatari
macOSApple Computer and MacOS Basics
macOS - AirDropAirDrop Forensics 2
macOS - Big SurBig Sur, Big Changes
macOS - CatalinaCatalina: A Voyage Through Apple’s New Artifacts
macOS - Daily LogsMac OS Daily Logs
macOS - Extended AttributesThere’s more to files than data: Extended Attributes
macOS - InteractionC.DB Socially Distant but Still Interacting! New and Improved Updates to macOS/iOS CoreDuet interactionC.db APOLLO Modules
macOS - SonomaSonoma’s log gets briefer and more secretive
macOS - Sysdiagnosesysdiag-who?
macOS - T2 ImagingMagnet Virtual Summit // MacOS Forensics: The Next Level - Taming the T2 Chip and More
Microsoft TeamsPart of a Sunday Funday Answer - Microsoft Teams
Microsoft TeamsMicrosoft Teams and Skype Logging Privacy Issue
MountyFile Timestamps for NTFS on macOS using Mounty
Safari macOS - Safari Preferences and Privacy
SafariiOS / macOS - Tracking Downloads from Safari Without Downloads
SafariAnalysing Safari browser history - Foxton Forensics
Screentime Notifications Screentime Notifications in Catalina (10.15)
SignalPulling encrypted Signal messages off of desktop OS’ for forensics
SkypeMicrosoft Teams and Skype Logging Privacy Issue
Tool ListOpen Source Tools & Mac Forensics - Sumuri
tvOSAPOLLO and tvOS – It Just Works! (...and judges me for binging TV)
Unified LogsReviewing macOS Unified Logs - Mandiant
Universal Serial Bus (USB)USB Forensics
Universal Serial Bus (USB)USB 101
VelociraptorVelociraptor - Dig Deeper