MFSC-101: The Best Practices in Mac Forensics

This course is given by SUMURI. The Best Practices in Mac Forensics (MFSC-101) course shows you how and why you are missing evidence using non-native forensic solutions and how to find what is missed by using a Mac to process a Mac.

Steve Whalen developed this course to provide vendor-neutral and tool-agnostic training that covers the process of examining a Macintosh computer from the first step to the last step in logical order. MFSC-101 is designed for both the beginner Mac examiner as well as the advanced. The knowledge you gain can be applied to any forensic tool on any platform. Surprising to most is that the entire course is taught using a Mac to examine a Mac without expensive automated forensic tools. Even more surprising is that the participants realize that they can find more evidence and find it faster!

MFSC-101 is the first of two prerequisites for the Certified Forensic Mac Examiner (CFME) certification. The CFME is a two-part certification process that tests the candidate on topics covered in MFSC-101 and MFSC-201. It is absolutely at no extra cost to those candidates who have attended both of the courses.

Topics include but are not limited to:

  • Overview of macOS Versions – identifies features of forensic importance in different macOS and when they appeared
  • Understanding the Mac File System Technology – a review of all file system technology supported by macOS such as APFS, Core Storage, Fusion Drives, and macOS Extended
  • Intel Mac Technology and Bootcamp – explains the forensic significance of Mac Intel Technology
  • Silicon Mac Technology – explains the unique issues and forensic significance of M1 Silicon Technology
  • Mac Security Issues and FileVault Attacks – current best practices for dealing with Mac Security
  • Macintosh Search and Seizure – best practices for seizing Mac and iOS hardware
  • Safely Obtaining System Information – how to safely obtain system information without making changes to the evidence
  • Open Firmware Passwords – explains OFP, how to set and remove OFP if it is necessary
  • Volatile Data Collection – discussion on unique issues concerning Mac Volatile Data, methods to collect it, and the need for a Trusted Utilities Disk
  • Forensic Imaging – discussion and exercises on imaging Intel and M1 Silicon Macs to include issues present by Mac security features
  • Imaging Mac RAM – discussion on the challenges in capturing RAM due to macOS security features
  • Mounting Forensic Images in the macOS – safely mounting forensic images for Processing and analysis
  • Indexing Forensic Images – how to index forensic images using macOS
  • Search Techniques Using macOS – creating custom search expressions 
from the command-line and GUI
  • Locating Evidence – how to identify, analyze and extract macOS and application artifacts such as Email, Graphics, Internet Artifacts, Documents, System Artifacts, Instant Messaging, logs, and more
  • Recovering Deleted Files – an exercise in manually recovering deleted files and the dangers of Mac optimization
  • Examining SQLite Databases and PLIST files – examining the heart of Mac data storage
  • Using macOS for Forensics – how to utilize built-in macOS technology for forensics
  • Report Development – how to create native reports using the Mac to view data properly
  • Examining iOS Devices Artifacts – identifying and examining iOS artifacts found on a Mac
  • Recommendations for Mac Forensics system configuration and hardware

WHEN:  April 22-26, 2024

COST: $2,495.00 US Dollars


Existing IACIS members: Log in with your credentials and go to the Products page to purchase and register for the course.

Non-IACIS members: Membership fee is waived with the purchase of the training course; however, to register for the course you must complete a membership application at the time of purchase. Purchase training course HERE.

****Payment MUST BE RECEIVED at least 45 days prior to the first day of class. Any payment arrangements other than payment through the website or payment via invoice must be approved by the IACIS Treasurer prior to admittance into the course. Please contact the treasurer for questions and approval (

Cancellations within 45 days from the start of class to 31 days from the start of class will be subject to a $150 cancellation fee. There will be no refunds within 30 days from the start of class.****

* On-Site Check-in Times (student pickup of equipment, ID card, IACIS info) are:

             Sunday, April 21, 2024: 1800 – 2100

             Monday, April 22, 2024: 0700 – 0800

* Please make arrangements to arrive in time to check-in so that you may be in class promptly the first day.


Please read the following notes regarding this class:

  1. Each student is required to supply their own Mac computer for the class with macOS Sonoma installed.
  2. The dress code for the conference is business casual (collared shirts and slacks). The wearing of shorts, flip flops, tank tops, etc. is not allowed in the classroom. Students are required to attend all classes to successfully complete the program. Students who fail to meet the attendance requirements will not be issued a certificate at the conclusion of the program.
  3. Classes begin at 8:00 AM ET and conclude at 5:00 PM ET, each day, with a one-hour lunch break. Classes will end at 4:00 PM ET on the last day of class. Please do not arrange for departing flights prior to 7:00 PM ET to allow time for travel to the airport and any security clearances.


You can find information about hotel booking HERE


If IACIS is unable to hold their 2024 Orlando training event, then all students who have registered and paid, will have the option of a full refund or a reserved seat at the 2025 training event.  IACIS is not responsible for any outside expenses (e.g. travel and accommodation) in the event of the training event being cancelled.  Anyone who paid for training will receive complimentary membership through the year that his/her training takes place.