MFSC-201: The Advanced Practices in Mac Forensics

This course is given by SUMURI. As each quarter passes, Apple’s success has been nothing but impressive. In addition to desktop and mobile computers, Apple produces a variety of unique and innovative devices and applications found in just about every modern society, home, and business. As more and more Apple devices enter the marketplace exponentially, the need for Macintosh Forensic Training is quite apparent.

The Advanced Practices in Mac Forensics (MFSC-201) course provides unparalleled vendor-neutral and tool-agnostic instruction in advanced topics relating to the forensic use and analysis of Apple hardware, technologies, and applications. The training is designed for the participant to learn in a teamwork environment and taught by instructors who maintain a “no one left behind” attitude. In addition, complicated topics are made easy to understand through instructor-led exercises and real-life scenarios— supported by a quality student manual to be utilized as a supplemental resource after the course.

MFSC-201 is the second prerequisite for the Certified Forensic Mac Examiner certification. The CFME is a two-part certification process that tests the candidate on topics covered in MFSC-101 and MFSC-201. It is absolutely at no extra cost to those candidates who have attended both of the courses.

Topics include but are not limited to:

  • Advanced File System Analysis – Introduction to the concept of domains within the macOS environment and locations of evidentiary artifacts and their contents.
  • Advanced Command Line – Work with macOS’ powerful and highly useful command-line interface to assist in forensic examinations of a Mac.
  • macOS Log Analysis – Learn how to identify artifacts from persistent and volatile logs, including Apple Unified Logs.
  • File System Event Monitoring and Analysis – Work with live and logged File System Events to identify artifacts and determine file usage history on a volume or disk.
  • Identifying and Analyzing Virtual Machines – Identify the use of a VM within macOS and the procedures necessary to analyze artifacts.
  • AppleScript and Automator – Learn to develop custom programs and workflows to automate almost any task to simplify and enhance forensic examinations.
  • macOS Server & Software RAIDs – Discussion on macOS server technology and Apple software RAIDs. Learn the best practices on handling servers and Apple RAIDs.
  • Macintosh Timeline Analysis – Understand and identify unique macOS metadata timestamps for use in building a timeline of a file system that can retrace the suspect’s history minute by minute or second by second.
  • iCloud Forensics – Find and analyze iCloud artifacts and data, such as documents, synced with an Apple iCloud account.
  • Time Machine Analysis – Understand the Time Machine backup process and structure in order to find data.
  • Unique Apple Technology – Lean the best practices and resources available to deal with unique Apple technology such as Air Tags and Continuity.
  • Advanced Search Techniques – Use advanced search techniques, both macOS native and 3rd party tools, to find evidentiary artifacts within the macOS.
  • Application Deconstruction – Learn how to find any and all artifacts left behind by installed, and in some cases uninstalled, applications.

PREREQUISITE: Completion of MFSC-101 or comparable Mac Forensics Course

WHEN:  April 29 – May 3, 2024

COST: $2,495.00 US Dollars


Existing IACIS members: Log in with your credentials and go to the Products page to purchase and register for the course.

Non-IACIS members: Membership fee is waived with the purchase of the training course; however, to register for the course you must complete a membership application at the time of purchase. Purchase training course HERE.

****Payment MUST BE RECEIVED at least 45 days prior to the first day of class. Any payment arrangements other than payment through the website or payment via invoice must be approved by the IACIS Treasurer prior to admittance into the course. Please contact the treasurer for questions and approval (

Cancellations within 45 days from the start of class to 31 days from the start of class will be subject to a $150 cancellation fee. There will be no refunds within 30 days from the start of class.****

* On-Site Check-in Times (student pickup of equipment, ID card, IACIS info) are:

             Sunday, April 28 2024: 1800 – 2100

             Monday, April 29, 2024: 0700 – 0800

* Please make arrangements to arrive in time to check-in so that you may be in class promptly the first day.


Please read the following notes regarding this class:

  1. Each student is required to supply their own Mac computer for the class with macOS Sonoma installed.
  2. The dress code for the conference is business casual (collared shirts and slacks). The wearing of shorts, flip flops, tank tops, etc. is not allowed in the classroom. Students are required to attend all classes to successfully complete the program. Students who fail to meet the attendance requirements will not be issued a certificate at the conclusion of the program.
  3. Classes begin at 8:00 AM ET and conclude at 5:00 PM ET, each day, with a one-hour lunch break. Classes will end at 4:00 PM ET on the last day of class. Please do not arrange for departing flights prior to 7:00 PM ET to allow time for travel to the airport and any security clearances.


You can find information about hotel booking HERE


If IACIS is unable to hold their 2024 Orlando training event, then all students who have registered and paid, will have the option of a full refund or a reserved seat at the 2025 training event.  IACIS is not responsible for any outside expenses (e.g. travel and accommodation) in the event of the training event being cancelled.  Anyone who paid for training will receive complimentary membership through the year that his/her training takes place.