Membership

MacOS Anti-Forensics (W37)

Examine anti-forensic techniques affecting macOS evidence. Study how investigative traces can be changed and what those limitations mean for analysis. This is an earlier course edition; examples reflect the tools and versions used when it was recorded.

Instructor · Cordny Nederkoorn

Modules:
4
Lessons:
69

eForensics learning

Practical skills.
Verified progress.

What you'll learn

  • Describe categories of anti-forensic techniques.
  • Examine how macOS evidence can be altered or concealed.
  • Evaluate the effect of anti-forensics on investigative conclusions.

Prerequisites

You should be familiar with: computer forensic investigation concepts: imaging, hashing working on a MacOS: finding files computer data, image and video files (where to find logs on MacOS, different image files, etc.) installing computer-based software from a website Basic programming skills (desired but not essential) Equipment and software: To participate in the course you'll need: A macBook Pro with min. MacOS 10.11.6 (El Capitan); 2,7 GHz Intel Core i5; 8 GB 1867 MHz DDR3 Good internet connection to download tools on the fly

Module 2

Module 1

Assessments

Assignment Required

(W37A02) Module 1 Assignments

Module 3

Module 2

Assessments

Assignment Required

(W37A03) Module 2 Assignments - Theory

Assignment Required

(W37A04) Module 2 Assignments - Practice

Module 4

Module 3

Assessments

Assignment Required

(W37A05) Module 3 Exercises

Module 5

Final Exam

Lessons will appear here after course content is added.

Assessments

Assignment Required

(W37A06) Final Exam

Course access

Unlock MacOS Anti-Forensics (W37).

Enter your email. We’ll send a sign-in code here without taking you away from this course.