macOS has created roadblocks for examiners for years. Investigators must contend with not only hardware-based encryption like the T-2 chip, to System Integrity Protection (SIP), which prevented disk and write access to specific directories across the Mac. Now with macOS Catalina (10.15) we find even more complications with the addition of a new read-only volume found on macOS endpoints. In this webinar we will review some of the challenge’s examiners have faced when investigating mac’s in recent years as well as demonstrate how you can quickly and covertly connect to and acquire from the latest Mac endpoints.
Join Trey Amick and Drew Roberts from Magnet Forensics and learn how to acquire from macOS endpoints without disabling SIP or having to work around T-2 based Macs.
After viewing this webinar you will be issued a certificate by email documenting that you have taken part in the session.