Duration: 3 days.
Audience: Forensic investogators with experience in forensic case work and a basic working knowledge of
FTK, FTK IMager and PRTK.
Pre-requisites: Read and Understand the English language
Attend the AccessData Forensic BootCamp or have equivalent experience with FTK and PRTK.
Have previous investigative experience in forensic case work
Be familiar with the Microsoft Windows environment
Topics Covered: Introduction
Macintosh GPT Structure
Obtaining the Date and Time from a Mac
Imaging a Mac
Directory Structure - Finding Evidence
Recovering the User Logon Password
Application Data - Safari
Application Data - Firefox
Application Data - iChat