Exploring macOS Rebuilt Desktops in Magnet AXIOM
In Magnet AXIOM 4.6, we’re happy to bring a new refined result to the table: “Rebuilt Desktops”, similar to the one we introduced earlier for Windows operating system but this time for macOS!
In Magnet AXIOM 4.6, we’re happy to bring a new refined result to the table: “Rebuilt Desktops”, similar to the one we introduced earlier for Windows operating system but this time for macOS!
With Magnet AXIOM 4.6, we’ve updated and added a whole slew of new Mac and iOS artifacts for examiners to use in their investigations.
In this how-to document, we share how you can get images containing the entire file system of iOS devices with GrayKey and analyze that data with AXIOM.
In this how-to document, we share how you can get images containing the entire file system of iOS devices with GrayKey and analyze that data with AXIOM.
It’s important that we continue to enhance the user experience of AXIOM to help our customers’ ability to effectively and efficiently seek the truth in their digital forensics investigations. In the latest release of AXIOM 4.5, we improved our searching functionality throughout! Here’s what you can expect when you perform searches after upgrading to AXIOM … Continued
Chris Vance goes through the “Files” app that Apple added in iOS 11.
AXIOM 4.4 introduces support for results captured with the MAGNET Web Page Saver, the ability to choose the evidence summaries included in exports and more.
The goal of timestomping is to edit the timestamps being displayed and reported to the end user and incident responders in an attempt to make it seem as though the file doesn’t fall into the timeline of other detected malicious activity.
As investigators, part of our job includes providing an accurate account on the evidence recovered from the incident under investigation. Including details down to the look and feel of how a device is setup and how a user interacted with it goes a long way in providing the context needed for our casework. In the … Continued
Starting with AXIOM 4.4, you can bring your WPS results into AXIOM as a new source and have artifacts parsed from the results.