macOS Endpoint Investigation
Master macOS Endpoint Investigation
macOS investigation is its own discipline, not Windows forensics with different file paths. This course teaches you to acquire a modern Mac correctly, read each of its evidence stores, and assemble findings that hold up — with honest treatment of what the platform does and does not record. Targets macOS Sequoia 15 and macOS 26 Tahoe, because the Macs on your bench are a mix of both and the artifacts shift between releases.
What you'll be able to do
Course overview
The macOS Endpoint Investigation course delivers the skills to take a Mac — or a collection from one — and answer what ran, what persisted, what the user did, and what left the machine, backed by corroborated evidence and a stated confidence level. The platform keeps a record you have never had on Windows: a behavioral timeline of what the user did, alongside the execution, persistence, and network evidence every investigation needs. This course teaches you to read it. Learn how to:
By the end, you'll run a full macOS investigation the way a working DFIR analyst does, with honest treatment of the platform limits Apple Silicon and macOS impose.
Who this course is for
You're a digital forensics analyst, incident responder, threat hunter, or security engineer who already has foundational investigation skills and needs to work Macs — or needs to work them better. This course is designed for you if you want to:
In short, if Macs appear in your investigations and you need to work them correctly, this course is for you.
What you'll learn
By the end of this macOS Endpoint Investigation course you will be able to:
Key course takeaways
Things you need to know
What are the prerequisites for this course?
Familiarity with file systems, command-line tools, and basic forensic concepts will help you move faster, but every macOS-specific concept is explained from first principles. Prior experience with disk forensics on any platform is useful. No macOS or Apple-specific prior knowledge is required.
What are the device requirements?
A Mac running macOS Sequoia 15 or macOS 26 Tahoe for the live exercises, or access to a verified image and a log archive for the dead-box workflow. All tools used in the course (mac_apt, APOLLO, FSEventsParser, iLEAPP, ccl-segb, Aftermath) are free and open source. No lab VM or hypervisor is required.
How will the course benefit your career?
Macs now appear in most enterprise fleets, and the number of responders who can investigate them correctly is small. An analyst who can work a Mac from acquisition through a defensible findings package — and who knows what Apple Silicon and the platform cannot give you — is valuable on any DFIR team. The course targets both current macOS releases, so the skills stay relevant as the platform moves.
Usage rights and disclaimer
Course materials: Licensed for individual professional development. You may not redistribute course content or share account credentials.
Fictional environment: All scenarios use Northgate Engineering. Any resemblance to real organizations is coincidental.
Version and changelog
Current version: 1.0 | Last updated: June 2026
June 2026 - v1.0: Initial release. 14 modules across 4 phases. Targets macOS Sequoia 15 and macOS 26 Tahoe on Apple Silicon. Full capstone investigation, ~25 macOS fieldcraft procedures, and the complete artifact inventory from acquisition through timeline and anti-forensics detection.
This course is actively maintained.
End of Course Exam
Complete the course, then prove your skills under time pressure. Pass mark: 70. Earn your certificate with CPE credits.
Requires 80% course completion. One random scenario per attempt. Certificate issued on pass.