U.S. flag

An official website of the United States government, Department of Justice.

NCJRS Virtual Library

The Virtual Library houses over 235,000 criminal justice resources, including all known OJP works.
Click here to search the NCJRS Virtual Library

MEGA: A tool for Mac OS X operating system and application forensics

NCJ Number
305470
Journal
Digital Investigation Volume: 5 Dated: 2008 Pages: S83-S90
Author(s)
Robert A. Joyce; Judson Powers; Frank Adelstein
Date Published
September 2008
Length
8 pages
Annotation

This article examines several forensic analysis tools for popular computer operating systems.

Abstract

Computer forensic tools for Apple Mac hardware have traditionally focused on low-level file system details. Mac OS X and common applications on the Mac platform provide an abundance of information about the user's activities in configuration files, caches, and logs. The authors are developing MEGA, an extensible tool suite for the analysis of files on Mac OS X disk images. MEGA provides simple access to Spotlight metadata maintained by the operating system, yielding efficient file content search and exposing metadata such as digital camera make and model. It can also help investigators to assess FileVault encrypted home directories. MEGA support tools are under development to interpret files written by common Mac OS applications such as Safari, Mail, and iTunes.