![]() However, this method works in a pinch, and at least you can start analysis until you get things working on a Mac. I would strongly recommend verifying any results with another tool or method, such as the one detailed by Sarah Edwards. Note the word "experimental" - and read the disclaimers by the author. If you are on a Windows machine and need access to an APFS volume or image (E01 or raw), it's easy enough to spin up a Linux VM and get to work.įor my testing, I used an experimental Linux APFS driver by sgan81 - apfs-fuse. Sometimes one way may not work for you, or maybe you don't have access to a Mac at the moment. It's always nice to have options in forensics.
0 Comments
Leave a Reply. |
AuthorWrite something about yourself. No need to be fancy, just an overview. ArchivesCategories |