nitter
Mick Douglas 馃嚭馃嚘馃尰
@bettersafetynet
27 Jan 2021
OK forensics folks! What are some events you'd like to see from Mac logs? Here's the working list I have right now. User created User login/logoff (success & fail) group create group change sudo use app install/delete Please RT! Thanks in advance.
7
21
25
Hal Pomeranz
@hal_pomeranz
27 Jan 2021
Replying to
@bettersafetynet
(USB) device connection startup service change/create/delete keyring access iCloud activity Apple ID changes
Jan 27, 2021 路 10:27 PM UTC
1
1
Mick Douglas 馃嚭馃嚘馃尰
@bettersafetynet
27 Jan 2021
Replying to
@hal_pomeranz
what sort of iCloud activities? That's hella broad. Any pointers would be appreciated.
1
Hal Pomeranz
@hal_pomeranz
28 Jan 2021
I鈥檓 thinking things that would point to exfil and/or exploitation. Moving files back and forth, etc.
1