This course is given by SUMURI. The Best Practices in Mac Forensics (MFSC-101) course shows you how and why you are missing evidence using non-native forensic solutions and how to find what is missed by using a Mac to process a Mac.
Steve Whalen developed this course to provide vendor-neutral and tool-agnostic training that covers the process of examining a Macintosh computer from the first step to the last step in logical order. MFSC-101 is designed for both the beginner Mac examiner as well as the advanced. The knowledge you gain can be applied to any forensic tool on any platform. Surprising to most is that the entire course is taught using a Mac to examine a Mac without expensive automated forensic tools. Even more surprising is that the participants realize that they can find more evidence and find it faster!
MFSC-101 is the first of two prerequisites for the Certified Forensic Mac Examiner (CFME) certification. The CFME is a two-part certification process that tests the candidate on topics covered in MFSC-101 and MFSC-201. It is absolutely at no extra cost to those candidates who have attended both of the courses.
Topics include but are not limited to:
- Overview of macOS Versions – identifies features of forensic importance in different macOS and when they appeared
- Understanding the Mac File System Technology – a review of all file system technology supported by macOS such as APFS, Core Storage, Fusion Drives, and macOS Extended
- Intel Mac Technology and Bootcamp – explains the forensic significance of Mac Intel Technology
- M1 Silicon Mac Technology – explains the unique issues and forensic significance of M1 Silicon Technology
- Mac Security Issues and FileVault Attacks – current best practices for dealing with Mac Security
- Macintosh Search and Seizure – best practices for seizing Mac and iOS hardware
- Safely Obtaining System Information – how to safely obtain system information without making changes to the evidence
- Open Firmware Passwords – explains OFP, how to set and remove OFP if it is necessary
- Volatile Data Collection – discussion on unique issues concerning Mac Volatile Data, methods to collect it, and the need for a Trusted Utilities Disk
- Forensic Imaging – discussion and exercises on imaging Intel and M1 Silicon Macs to include issues present by Mac security features
- Imaging Mac RAM – discussion on the challenges in capturing RAM due to macOS security features
- Mounting Forensic Images in the macOS – safely mounting forensic images for Processing and analysis
- Indexing Forensic Images – how to index forensic images using macOS
- Search Techniques Using macOS – creating custom search expressions from the command-line and GUI
- Locating Evidence – how to identify, analyze and extract macOS and application artifacts such as Email, Graphics, Internet Artifacts, Documents, System Artifacts, Instant Messaging, logs, and more
- Recovering Deleted Files – an exercise in manually recovering deleted files and the dangers of Mac optimization
- Examining SQLite Databases and PLIST files – examining the heart of Mac data storage
- Using macOS for Forensics – how to utilize built-in macOS technology for forensics
- Report Development – how to create native reports using the Mac to view data properly
- Examining iOS Devices Artifacts – identifying and examining iOS artifacts found on a Mac
- Recommendations for Mac Forensics system configuration and hardware
WHEN: April 24-28, 2023
COST: $2,495.00 US Dollars
Registration for this course is closed.
****Payment MUST BE RECEIVED at least 45 days prior to the first day of class. Any payment arrangements other than payment through the website or payment via invoice must be approved by the IACIS Treasurer prior to admittance into the course. Please contact the treasurer for questions and approval (email@example.com)
Cancellations within 45 days from the start of class to 31 days from the start of class will be subject to a $150 cancellation fee. There will be no refunds within 30 days from the start of class.****
* On-Site Check-in Times (student pickup of equipment, ID card, IACIS info) are:
Sunday, April 23, 2023: 1800 – 2100
Monday, April 24, 2023: 0700 – 0800
* Please make arrangements to arrive in time to check-in so that you may be in class promptly the first day.
Please read the following notes regarding this class:
- Each student is required to supply their own Mac computer for the class. The Mac should be able to run macOS on Monteray or later. It is preferred that macOS Ventura be installed.
- The dress code for the conference is business casual (collared shirts and slacks). The wearing of shorts, flip flops, tank tops, etc. is not allowed in the classroom. Students are required to attend all classes to successfully complete the program. Students who fail to meet the attendance requirements will not be issued a certificate at the conclusion of the program.
- Classes begin at 8:00 AM ET and conclude at 5:00 PM ET, each day, with a one-hour lunch break. Classes will end at 4:00 PM ET on the last day of class. Please do not arrange for departing flights prior to 7:00 PM ET to allow time for travel to the airport and any security clearances.
The course will be taught at the Caribe Royale Hotel, 8101 World Center Drive, Orlando, Florida 32821 (USA). This hotel is 16 miles from the Orlando International Airport, it has a large pool, spacious workout facility and is close to Disney World and Universal Studios.
Due to an unprecedented situation with Caribe Royale, the hotel is completely booked for week one of the 2023 IACIS Training event.
IACIS is currently working with Orlando Marriott to determine if we can use it as overflow, but at the time of this writing we have no information on what they have available or if they will honor GSA rates. We will update this site as new information become available.
|Embassy Suites by Hilton Orlando Lake Buena Vista South||1(407)597-4000|
|Orlando Marriott World Center||1(407)239-4200|
|Gaylord Palms Resort & Convention Center||1(407)586-0000|
|Walt Disney World Swan||1(407)934-3000|
|Walt Disney World Dolphin Resort||1(407)934-4000|
Also, if you are government employee you may be able to use FedRooms.com to find GSA rate lodging in the area.
Please note: Availability at the Caribe Royale may change as time gets closer to the event so it is recommended that you check with the Caribe Royale often by using booking via this Caribe Royale Hotel link here. As a reminder, if you are not a Caribe Royale Hotel guest and require daily parking on hotel property during the event you will be responsible for all associated parking fees.
Or book via phone by calling the following numbers:
Reservations Toll Free: 1-800-823-8300/1-888-258-7501 or our local number 407-238-8000.
If IACIS is unable to hold their 2023 Orlando training event, then all students who have registered and paid, will have the option of a full refund or a reserved seat at the 2024 training event. IACIS is not responsible for any outside expenses (e.g. travel and accommodation) in the event of the training event being cancelled. Anyone who paid for training will receive complimentary membership through the year that his/her training takes place.