MAC Forensics Flashcards
1
Q
Name two ways to obtain a forensic copy
A
1.Target Disk Mode
2.Network Aquisition
3.Hard Drive Removal
2
Q
What is Disk Arbitration?
A
A software service, can block mounting/u mounting.
3
Q
What is the command to list attached drives?
A
Sudo diskutil list
4
Q
How do you list information about a particular drive?
A
Sudo diskutil info <drive></drive>
5
Q
How do you start a Mac in target mode?
A
Hold down “t”
6
Q
Command to transfer data from one computer to another
A
-nc =netcat
7
Q
What are the advantages of Network Aquisition?
A
- Can do multiple seized computers at once
- No need for dns or gateway