mac4n6
Access and status
Cost
Free
Free to read or download at source. No account, no purchase.
Status
Superseded or dormant
Superseded, replaced or no longer being updated. The archive may still be worth reading, but do not cite it as current practice.
What it is
A macOS and iOS forensic research blog, authored under the handle @iamevltwin with occasional contributors, covering Apple artifacts, analysis tooling and conference presentations.
Who it is for, and when
Dormant but still worth using: the most recent post is dated 18 March 2025, which is roughly eighteen months old, so treat it as an archive rather than a live feed. The archive remains one of the best public references on APFS, Unified Logs, FSEvents and Spotlight metadata, and those artifacts have not changed as fast as the blog has gone quiet. Verify anything version-specific against a current macOS build before relying on it.
What it does not cover
It stops before recent macOS and iOS releases, so nothing here covers the newest Apple Intelligence, Journal or system-log changes beyond early 2025, and there is no Windows, Android or cloud content.
Go to the source
Open at mac4n6.com (opens in a new tab)https://www.mac4n6.com/blog/
Details
- Type
- Blog or channel
- Written for
- Working examinerAdvancedWorking examiner, Advanced
- Topics
- macos, ios, file-systems, log-analysis, timeline
- Checked at source
Related entries
Postmortem analysis of Linux systems from the operating system's own structures outward: partition tables and LVM, Linux file systems, directory layout, the systemd journal and other logs, boot reconstruction, installed packages, network configuration, time and locale, login sessions, desktop artifacts, and traces of attached peripherals.
The Binary Hick
FreeA research blog by Joshua Hickman covering mobile and Apple-platform artifacts, timestamp semantics and the test images he builds and publishes for the community.
Autopsy
FreeAn open-source graphical forensic platform built over The Sleuth Kit, with an ingest-module architecture for keyword search, hash matching, web and email artefacts, and timeline review. It is now maintained by Sleuth Kit Labs, which also sells the commercial Cyber Triage product.
A large collection of free single-purpose Windows artefact parsers — among them MFTECmd, PECmd, LECmd, JLECmd, AmcacheParser, SBECmd, EvtxECmd, RECmd, and the Timeline Explorer and Registry Explorer GUIs. The tools are still distributed from ericzimmerman.github.io, with a Get-ZimmermanTools helper that pulls the current set.
The long-established Forensic Toolkit, originally AccessData's and now owned and sold by Exterro, which acquired the product line. It covers processing of computer and mobile data, distributed indexing and keyword search, artefact analysis, timeline visualisation, and Mac file system examination.