Home |  Log In  
Forensics and eDiscovery technologies for Mac OS X, Microsoft Windows, and Linux

General

If you find this section helpful to you, please consider adding to it. We all come across ideas and tips in the execution of our duties, sharing these tips serves to make our community stronger and wiser.

If you have a tip you would like to see added here please contact us on info@subrosasoft.com.

Sincerely, the SubRosaSoft team.


Article Image Item Name-
Disabling Windows Autorun

Disabling Windows Autorun

Care needs to be taken when examining suspect USB thumb drives and CDs. These types of media may contain autorun viruses and malware that could potentially infect the investigators workstation. Steps should be taken to disable autorun on Windows computers and decrease the chance of damage by...
Disabling Windows BitLocker Encryption

Disabling Windows BitLocker Encryption

BitLocker is a new drive encryption technology introduced with the Vista operating system. With BitLocker enabled, all files on a personal computer’s hard disk drive are automatically encrypted. BitLocker is included in the Enterprise and Ultimate editions of Vista and is disabled by default. Disk...
Find the Last Server a User was Connected to in Mac OS X

Find the Last Server a User was Connected to in Mac OS X

Mac OS X makes connecting to remote servers very easy. Retrieving information about servers a suspect has connected to will help an investigator find other resources they should be investigating or to prove intent. Mac OS X logs these connections along with other information that may be of interest...
Finding Disk Images that Have Been Burnt to CD/DVD

Finding Disk Images that Have Been Burnt to CD/DVD

Disk Images (.dmg) are very common on Mac OS X. Disk Images allow both compression and password protection so they are very common for the distribution of software over the internet. When opened Disk Images mount as a drive in the Finder. You can use the MacForensicsLab's Analyze function to...
Finding iChat Usernames on Mac OS X

Finding iChat Usernames on Mac OS X

iChat is an AIM (AOL Instant Messenger) client and comes built-in to Mac OS X. It is popular with many Mac OS X users as it has an easy to use interface, it works with AIM, and it's well integrated into the operating system. Finding the usernames of a suspect may be of use to the investigator. You...
Finding Past and Present Address Book Content

Finding Past and Present Address Book Content

The Apple Address Book is the central address book in Mac OS X. In addition to containing user entered names and addresses, it also contains an entry for the computer's owner that is created when the user registers the machine the first time after installation. Even if entries are deleted from the...
Finding Recent Google Searches

Finding Recent Google Searches

Google is the most popular search engine on the planet. Safari, the default web browser in Mac OS X, has a built in Google search bar in the upper right corner of it's window. This makes it very easy to conduct a search and also means it's very likely that search information can be found if a...
Finding Recently Viewed Pictures in Mac OS X

Finding Recently Viewed Pictures in Mac OS X

The default image browsing application in Mac OS X is Preview. It is a popular program for viewing images as it supports a large number of file formats and provides a simple user interface. Finding recently browsed images can help direct an investigator to files of interest or help prove intent....
Finding Remote Desktop Connections

Finding Remote Desktop Connections

Apple Remote Desktop (sometime abbreviated ARD) allows users to control or monitor another computer over a network or internet connection. You can use the MacForensicsLab's Analyze function to explore the following file: ~/Library/Preferences/com.apple.RemoteDesktop.plist This file shows all the...
Finding the Last iPod Connected to Mac OS X

Finding the Last iPod Connected to Mac OS X

iPod sales have almost topped 10 million world wide. They are also becoming a popular device for suspects to store information other then just MP3s on thanks to their ability to be used as a mass storage device. Every time an iPod is attached to a Mac, the serial number of the iPod is recorded by...
Finding the Original Registrant of Mac OS X

Finding the Original Registrant of Mac OS X

When Mac OS X is run for the first time after installation, the user is prompted to enter their registration information such as name, address, email, and phone number. This information is then sent to Apple (if an internet connection is present) and also used to populate the administrators...
Finding the system time and date on a Mac

Finding the system time and date on a Mac

Acquiring the computer time from a Mac is a common task for many investigators. Having the computer time allows and investigator to correlate computer events to actual time frames and may help secure a conviction. Macs sold after March of 2001 will most likely have Mac OS X loaded on them and all...
Firefox Artifacts

Firefox Artifacts

Mozilla Firefox is fast becoming one of the most popular browsers on the internet today. Current estimates as of June 2007 believe Firefox makes up 14.55% of the world's web browsers. Being free, cross-platform, and updated regularly is just some of the many reasons many users have made the switch...
Flash Drive Registry Information

Flash Drive Registry Information

USB thumb drives (flash drives) have become a very popular tool for transferring files from computer to computer. They're small, portable, and often contain evidence that can be helpful to an investigation. When examining the Windows registry, one of the interesting things to look at are the...
Gain SYSTEM User Access in Microsoft Vista

Gain SYSTEM User Access in Microsoft Vista

Gaining SYSTEM user access in Microsoft Vista is a simple procedure and allows a forensic investigator higher level access then the administrator. This method of gaining access to a Microsoft Vista system doesn't require the investigator to know any of the usernames or passwords for the system. ...
Gaining Root Access in Linux

Gaining Root Access in Linux

There may be times when it can be beneficial to an investigation for the investigator to be able to login to a suspect machine as the root user to explore. Such access may allow an investigator access to items that may be locked without root access to the machine. Boot Linux into single-user mode ...
iPhone Artifacts

iPhone Artifacts

iPhones and iPod Touch with firmware version 2.0 or later will call home periodicly to see if any applications have been blacklisted by Apple. This allows Apple to disable malicious applications from iPhone and iPod Touch users phones. The iPhone and iPod Touch will check the following URL for any...
iPhone Unlocking

iPhone Unlocking

As Apple guys and forensics experts we are constantly aware of the legendary iPhone We have them ourselves (and love them) and we are aware of the challenge they pose to the law enforcement community. The technology on both sides of the "argument" are constantly changing and we try to tread the...
Mac mini Take Apart Guide

Mac mini Take Apart Guide

The Mac mini is a small, low cost Mac that offers a lot of features in a small package. It's a nice entry level machine for new and old Mac users. The low price along with it's rich feature set make it an ideal machine for general users. Although a forensic examiner can connect the Mac mini to...
Mac Open Firmware Password Removal

Mac Open Firmware Password Removal

Open Firmware is hardware independent firmware (computer software that loads the operating system). Open Firmware is present on PPC (PowerPC) Macs. Open Firmware does allow the user to set a password to keep other users from changing the boot drive or partition. This can be an issue if the...
MacBook Air Take Apart Guide

MacBook Air Take Apart Guide

Apple's new MacBook Air is a small light-weight laptop for users on the go. It packs lots of features into a small package. In fact it's just 0.76 inches at it's thickest point. The small and compact size means that all the components are tightly squeezed into the MacBook Air. Take apart can be...
Putting an iPod into Diagnostic Mode

Putting an iPod into Diagnostic Mode

The iPod has become the most popular MP3 player on the market. Because iPods can also be used as a mass storage device (with the exception of the iPod shuffle), digital evidence may be stored on these devices. The iPod is a computer in it's own right and because of this, it will mount and write to...
Recently Accessed Items in Mac OS X

Recently Accessed Items in Mac OS X

Showing applications, documents, and severs a user most recently accessed can help direct an investigator to files of interest or help show intent. By default, Mac OS X keeps track of the last 10 applications, documents, and servers used. The user can increase of decrease this number but most leave...
Recently Opened QuickTime Files

Recently Opened QuickTime Files

QuickTime is the default movie player in Mac OS X. Because of it's ability to play a wide range of video and audio media, QuickTime Player is a convenient tool for most users. Being able to show the last file played using QuickTime Player can help an investigator show intent. You can use the...
Recognizing Potential Evidence

Recognizing Potential Evidence

The following was taken from the United States Secret Service's Best Practices For Seizing Electronic Evidence. We highly recommend you read the entire article located here as it contains lots of good information regarding electronic evidence. Recognizing Potential Evidence Computers and digital...
Removing a Mac Hard Drive

Removing a Mac Hard Drive

With the smaller and more compact design of computers these days, it's becoming increasingly difficult to take them apart to get access to the hard drive for forensic acquisition and examination. Should you choose to take the Mac apart to access the hard drive for forensic investigation, Apple has...
Resetting the Admin Password in Mac OS X

Resetting the Admin Password in Mac OS X

The easiest way to bypass the administrator password is to remove the drive and attach it to another machine or a forensic station, then use MacForensicsLab to image the drive. That being said if you need to for some reason keep the drive inside the machine, you can reset the system administrator...
Sleepimage in Mac OS X

Sleepimage in Mac OS X

The sleepimage is a file that Mac OS X uses to store the contents of the active RAM when a machine is put to sleep. This information is stored to allow the OS to restore the pre-sleep state of the computer should the batter or power be interupted while the computer is sleeping. For an investigator,...
Unfreezing A FireWire Bus That Has Hung

Unfreezing A FireWire Bus That Has Hung

On occasion FireWire buses can hang and stop responding. Should you run into this issue, here's are the suggested steps to resolve it. If you have a hard drive freeze your FireWire bus and hang your machine, you can cause the system to reset the bus by plugging in a second device in the chain. The...
Using FileDefense to Stop Malware

Using FileDefense to Stop Malware

FileDefense changes the way your OS operates by adding a layer of security at the layer that we feel is the most important - the file access layer. The way we see it, the amount of damage any application can do to you is based on whether it can access your personal files. The more you can limit...
View Web Cache Data on Mac OS X

View Web Cache Data on Mac OS X

Web caches store copies of documents the user has accessed on the internet in order to reduce server access time when visiting that site again. The information contained inside web caches can help an investigator prove a crime was committed, build a timeline of events, and prove intent. You can use...
Viewing Recently Accessed Windows Files

Viewing Recently Accessed Windows Files

The Windows Registry stores a wealth of information that can be helpful to a forensic investigator during an examination. Knowing which documents were recently accessed on a suspects Windows machine can point an investigator to files of interest along with helping to show proof of intent. The...
Swapping iChat Encryption Certificates in Mac OS X

Swapping iChat Encryption Certificates in Mac OS X

iChat, the default AIM client on Mac OS X, allows Apple .Mac users to encrypt chat if both users are using .Mac accounts. The encryption certificate for the encrypted chat is created on the users machine. When attempting use of certificates that have been stored inside a Keychain, the...
Finding Recently Played Windows Media Files on Mac OS X

Finding Recently Played Windows Media Files on Mac OS X

Although Microsoft has officially dropped support for Windows Media Player for Mac (Microsoft redirects Mac users to the Flip4Mac website as they actively develop a free plugin that allows QuickTime to play Windows Media documents), there are still many users that have Windows Media Player for Mac...

 | Home | 

Copyright © 2006 - 2010 MacForensicsLab Inc.
Phone +1 (510) 870-7883 - Fax +1 (510) 868 3407
Mac and the Mac logo are trademarks of Apple Computer, Inc., registered in the U.S. and other countries.

Forensics Technologies - designed to perform investigations, for law enforcement and eDiscovery professionals.

MacForensicsLab - The only effective cross-platform weapon in the war on Cyber Crime and Digital Terrorism,
with unique tools designed to combat identity theft and child pornography.