Legal Cyber Academy
Blog or channelFreeSuperseded or dormant

mac4n6

Access and status

Cost

Free

Free to read or download at source. No account, no purchase.

Status

Superseded or dormant

Superseded, replaced or no longer being updated. The archive may still be worth reading, but do not cite it as current practice.

What it is

A macOS and iOS forensic research blog, authored under the handle @iamevltwin with occasional contributors, covering Apple artifacts, analysis tooling and conference presentations.

Who it is for, and when

Dormant but still worth using: the most recent post is dated 18 March 2025, which is roughly eighteen months old, so treat it as an archive rather than a live feed. The archive remains one of the best public references on APFS, Unified Logs, FSEvents and Spotlight metadata, and those artifacts have not changed as fast as the blog has gone quiet. Verify anything version-specific against a current macOS build before relying on it.

What it does not cover

It stops before recent macOS and iOS releases, so nothing here covers the newest Apple Intelligence, Journal or system-log changes beyond early 2025, and there is no Windows, Android or cloud content.

Go to the source

Open at mac4n6.com (opens in a new tab)

https://www.mac4n6.com/blog/

Details

Type
Blog or channel
Written for
Working examinerAdvancedWorking examiner, Advanced
Topics
macos, ios, file-systems, log-analysis, timeline
Checked at source
  • Postmortem analysis of Linux systems from the operating system's own structures outward: partition tables and LVM, Linux file systems, directory layout, the systemd journal and other logs, boot reconstruction, installed packages, network configuration, time and locale, login sessions, desktop artifacts, and traces of attached peripherals.

  • A research blog by Joshua Hickman covering mobile and Apple-platform artifacts, timestamp semantics and the test images he builds and publishes for the community.

  • An open-source graphical forensic platform built over The Sleuth Kit, with an ingest-module architecture for keyword search, hash matching, web and email artefacts, and timeline review. It is now maintained by Sleuth Kit Labs, which also sells the commercial Cyber Triage product.

  • A large collection of free single-purpose Windows artefact parsers — among them MFTECmd, PECmd, LECmd, JLECmd, AmcacheParser, SBECmd, EvtxECmd, RECmd, and the Timeline Explorer and Registry Explorer GUIs. The tools are still distributed from ericzimmerman.github.io, with a Get-ZimmermanTools helper that pulls the current set.

  • The long-established Forensic Toolkit, originally AccessData's and now owned and sold by Exterro, which acquired the product line. It covers processing of computer and mobile data, distributed indexing and keyword search, artefact analysis, timeline visualisation, and Mac file system examination.