macOS Endpoint Investigation

Master macOS Endpoint Investigation

macOS investigation is its own discipline, not Windows forensics with different file paths. This course teaches you to acquire a modern Mac correctly, read each of its evidence stores, and assemble findings that hold up — with honest treatment of what the platform does and does not record. Targets macOS Sequoia 15 and macOS 26 Tahoe, because the Macs on your bench are a mix of both and the artifacts shift between releases.

View Pricing Take End of Course Exam → 40 CPE Credits

What you'll be able to do

Acquire an Apple Silicon Mac correctly, verify image integrity, and run a structured triage pass that turns a referral into an investigative question set
Query the Unified Log with structured predicates and read every macOS artifact class — FSEvents, persistence stores, KnowledgeC and Biome, and the network and device traces
Prove execution and persistence as separate, separately evidenced facts using the quarantine database, install receipts, and the launchd execution record
Triage a Mach-O binary to a static verdict on type, linkage, signature state, revocation, and capability — without running it
Build a sourced, graded unified timeline and detect anti-forensic tampering from impossible MACB orderings and independent artifact sources
Produce a defensible findings package with honest confidence grades and stated platform limits, and complete a full capstone investigation on a machine you have not seen before
FOR503 | Specialist tier | 14 modules across 4 phases | 36-40 hours at your own pace | 40 CPE credits | Free preview, no account needed | All tools free | Updated June 2026
Course Agenda View all modules

Course overview

The macOS Endpoint Investigation course delivers the skills to take a Mac — or a collection from one — and answer what ran, what persisted, what the user did, and what left the machine, backed by corroborated evidence and a stated confidence level. The platform keeps a record you have never had on Windows: a behavioral timeline of what the user did, alongside the execution, persistence, and network evidence every investigation needs. This course teaches you to read it. Learn how to:

Acquire an Apple Silicon Mac correctly and verify the image before touching the evidence
Read the Unified Log, FSEvents store, and every artifact class macOS keeps by default
Prove execution, persistence, and user activity from the platform's own records
Triage a macOS malware sample to a static verdict without running it
Build a sourced, graded unified timeline and produce a findings package that holds up

By the end, you'll run a full macOS investigation the way a working DFIR analyst does, with honest treatment of the platform limits Apple Silicon and macOS impose.

Who this course is for

You're a digital forensics analyst, incident responder, threat hunter, or security engineer who already has foundational investigation skills and needs to work Macs — or needs to work them better. This course is designed for you if you want to:

Investigate macOS endpoints with the same rigor you apply to Windows, without mapping Windows concepts onto a different platform
Read the artifacts macOS actually produces, especially the behavioral and pattern-of-life stores that have no Windows equivalent
Handle Apple Silicon machines and stay current across macOS releases without rebuilding your approach from scratch
Build defensible findings that state confidence levels and name the limits — so conclusions hold up to scrutiny

In short, if Macs appear in your investigations and you need to work them correctly, this course is for you.

What you'll learn

By the end of this macOS Endpoint Investigation course you will be able to:

Acquire a macOS image correctly on Apple Silicon, verify chain of custody, and run a structured triage pass that turns a referral into an investigative question set
Query the Unified Log with structured predicates and read its retention as a boundary, not a blank
Read MACB timestamps and the FSEvents store to establish what changed on disk and when, even after files are deleted
Prove execution separately from persistence, using the quarantine database, install receipts, codesign and spctl trust reads, and the launchd execution record
Reconstruct the user's pattern of life from KnowledgeC and Biome, the shared file lists, QuickLook, and the browser and communication artifact stores
Triage a Mach-O binary to a static verdict: type, linkage, signature state, revocation, and capability strings — without running it
Follow evidence across the Apple ecosystem — iCloud, paired devices, removable media — and state what the endpoint can and cannot prove
Detect backdated timestamps and anti-forensic residue from the MACB ordering and independent artifact sources
Build a sourced, graded unified timeline and produce a findings package with honest caveats and graded confidence levels

Key course takeaways

Run a complete macOS investigation end to end, from acquisition through findings package, on Apple Silicon hardware running Sequoia or Tahoe
Master the artifact classes macOS keeps that Windows does not, especially the behavioral and pattern-of-life stores that answer the user-attribution questions
Apply the platform-honest approach: state what the evidence proves, grade confidence, name the limits Apple Silicon and the platform impose
Build ~25 macOS fieldcraft procedures you can execute on a real engagement without consulting documentation
Work the full capstone investigation on a machine you have never seen, applying everything from M1 to M12 without a walkthrough

Things you need to know

What are the prerequisites for this course?

Familiarity with file systems, command-line tools, and basic forensic concepts will help you move faster, but every macOS-specific concept is explained from first principles. Prior experience with disk forensics on any platform is useful. No macOS or Apple-specific prior knowledge is required.

What are the device requirements?

A Mac running macOS Sequoia 15 or macOS 26 Tahoe for the live exercises, or access to a verified image and a log archive for the dead-box workflow. All tools used in the course (mac_apt, APOLLO, FSEventsParser, iLEAPP, ccl-segb, Aftermath) are free and open source. No lab VM or hypervisor is required.

How will the course benefit your career?

Macs now appear in most enterprise fleets, and the number of responders who can investigate them correctly is small. An analyst who can work a Mac from acquisition through a defensible findings package — and who knows what Apple Silicon and the platform cannot give you — is valuable on any DFIR team. The course targets both current macOS releases, so the skills stay relevant as the platform moves.

Usage rights and disclaimer

Course materials: Licensed for individual professional development. You may not redistribute course content or share account credentials.

Fictional environment: All scenarios use Northgate Engineering. Any resemblance to real organizations is coincidental.

Version and changelog

Current version: 1.0  |  Last updated: June 2026

June 2026 - v1.0: Initial release. 14 modules across 4 phases. Targets macOS Sequoia 15 and macOS 26 Tahoe on Apple Silicon. Full capstone investigation, ~25 macOS fieldcraft procedures, and the complete artifact inventory from acquisition through timeline and anti-forensics detection.

This course is actively maintained.

COURSE ASSESSMENT

End of Course Exam

Complete the course, then prove your skills under time pressure. Pass mark: 70. Earn your certificate with CPE credits.

40minutes
3phases
100points
1scenario
Take End of Course Exam

Requires 80% course completion. One random scenario per attempt. Certificate issued on pass.