

It's hidden with better tools.Īs with most forensics challenges, steganography makes an appearance. Find the flag in the GoodExample.jpg image. Provide the MAC address of the ethernet adapter for this machine. What was exactly typed in the Spotlight search bar on 02:09:48įind the logs. You guessed it! There is a SQLite database that contains a list of bookmarks. Here are some of the questions and a few hints to give you an idea of to expect: How many bookmarks are registered in safari? You can find the full list of questions here.


Some are super easy to solve others took some time. There are a total of 16 questions of varying levels of difficulty. I turned on my Windows laptop and installed FTK Imager and Autopsy.
OSFORENSICS FOR MAC INSTALL
OSFORENSICS FOR MAC MAC OS
Here is the first MAC OS forensics challenge to release - Spotlight.Ī nice opportunity to evaluate your skills against an OS usually encountered in today's investigations.Īuthor: #DFIR #BlueTeam #InfoSec #CyberSecurity #SOC /KWZppk1IjF- CyberDefenders December 3, 2020 Spotlight is a MAC OS image forensics challenge where you can evaluate your DFIR skills against an OS you usually encounter in today's case investigations. Bear in mind, I did a lot of macOS troubleshooting when administrating and configuring an MDM solution, so I wasn't diving in blind. My goal was to see if I can Google search my way through the various questions. What is Spotlight?Ī few days ago, I saw this tweet on Twitter and given the fact I had no concrete plans for this weekend I decided to take a swing at the challenge. I never did any macOS forensics before yesterday, so this challenge was quite the experience and twice the fun. I have been using macOS daily for about 11 months now but only in an everyday context (e.g. This post is my attempt at a quick recap. Even though I never did any macOS forensics, I did quite well on this challenge (solved 14/16 questions) and learned a bunch. It's been a while since I did any forensic challenges, so I was excited when I saw this new challenge from CyberDefenders.
