Skip to main content
The Cyber Security: ethical hacking and cyber security training, Canada
Advanced

macOS and iOS Forensic Analysis

macOS and iOS forensic analysis rewards examiners who understand Apple's own design decisions. This course goes into APFS internals, system and application artifacts, and the synchronisation that quietly moves evidence between a Mac, an iPhone and iCloud.

Ten weeks also covers incident response on managed Mac fleets, where mobile device management, endpoint telemetry and Apple security features together decide what you are able to collect.

Duration
10 weeks
Format
Live online, instructor-led
Prerequisites
Windows Forensic Analysis
Class size
Capped at 12 learners
macOS and iOS Forensic Analysis

What you will be able to do

  • Explain APFS containers, snapshots and copy on write in evidential terms
  • Image modern Macs including Apple silicon and encrypted volumes
  • Reconstruct user activity from unified logs, FSEvents and Spotlight metadata
  • Decode Messages, Mail, Safari, Photos and Notes artifacts on both platforms
  • Interpret KnowledgeC and biome data to establish device usage patterns
  • Separate locally created evidence from data arriving through iCloud sync
  • Triage a managed Mac during a live incident without destroying evidence
  • State clearly what Apple platform limitations mean for your conclusions

Course outline

6 modules

  • APFS containers, volumes and snapshots
  • Copy on write and what deletion actually means
  • FileVault, the Secure Enclave and hardware backed encryption
  • Local Time Machine snapshots as historical evidence
  • Imaging modern Macs including Apple silicon hardware

What you need before you start

  • Prior forensic analysis experience on any platform
  • Comfort with the command line and reading structured data formats
  • A Mac is helpful for some exercises but a virtual lab is provided
  • Roughly five hours a week for lab work between classes

Who this course is for

  • Examiners whose casework now includes Apple devices
  • Incident responders supporting organisations with large Mac fleets
  • Mobile forensic analysts extending into macOS
  • Investigators handling cases where iCloud sync complicates the evidence
  • Consultants who must validate Apple artifacts before reporting them

Where this leads

Prepares you for

CHFI

Awarded by EC-Council

Apple platform work supports the wider Computer Hacking Forensic Investigator syllabus, which is platform broad rather than Apple specific. EC-Council alone examines candidates and awards CHFI; this academy provides instruction and practical experience toward it.

Questions about this course

Ready to launch your cyber security career?

Join the next live online cohort. No experience required, just bring the curiosity.