Description


The purpose of this script is to assist the examiner to visualize the paths of relevant target files within a Mac OS X Time Machine volume.

Before running the script the examiner must first blue-check the files in the volume that are of interest. It is advisable to tag those files first so as to avoid losing the selection by inadvertently switching views.

When the script runs it will write the selected files into a nominated logical evidence file (LEF) using the same paths as would be observed were the Time Machine volume to be viewed under Mac OS X. The examiner has the option of filtering the output, so, for instance, it's possible to select all of the pictures within the Time Machine volume but only write those pictures to the LEF is they contain the string '\Users\' somewhere in their path.

Only one Time Machine volume can be processed at a time. If the examiner selects files from more than one volume the script will raise an error. Every file of interest must be selected even if it is a hard-linked duplicate: the script won't find duplicates automatically - it would take too long.

It's important to bear in mind that re-creating the structure of a Time Machine backup can be time consuming and take a substantial amount of disk-space. Not only that, but because many files will exist in more than one backup, the resultant LEF will usually contain far more files than were actually selected by the examiner. This notwithstanding, the use of hash-values within the internal LEF structure will ensure that only one copy of a duplicate file is actually stored.

This script was developed for use in EnCase training. For more details, please click the following link:

Releases

Release
Size
Date
Mac OS X Time Machine Parser 1.1.0
  |  
Aug 1, 2024
More info Less info
Product compatibility
Release notes

Tested with:
EnCase Forensic 8.07

Languages
English

Unsubscribe from notifications

You are receiving release updates for this item because you have subscribed to the following products:
If you unsubscribe, you will no longer receive any notifications for these products.
Tip: to update your subscription preferences, go to Manage Subscriptions from your Dashboard, uncheck the products you no longer want to receive notifications for, and click 'Save'.

Marketplace Terms of Service

In order to continue, you must accept the updated Marketplace Terms of Service
Since you are downloading an app from the OpenText Marketplace, you need to accept the updated Marketplace Terms of Service before you can continue. Use the link to review the Marketplace Terms of Service. Once complete check the, "I accept the Marketplace Terms of Service" box below and click accept to continue your download.


Your download has begun...

Your download has begun

Related content and resources

Your browser is not supported!

Please upgrade to one of the following broswers: Internet Explorer 11 (or greater) or the latest version of Chrome or Firefox

release-rel-2025-2-1-6322 | Wed Feb 5 16:30:41 PST 2025