Conduct detailed, in-depth forensic analysis on raw data from Mac and iOS cases. Learn APFS file system examination, log analysis, metadata extraction, and investigation of Apple-specific technologies like Time Machine, FileVault, AirTags, and FindMy. Build confidence in handling Mac and iOS incident response investigations.
Investigate Mac computers and iOS devices using forensic techniques specific to Apple platforms. Build expertise in the fastest-growing segment of enterprise forensics.
Apple devices appear in most enterprise environments and nearly all investigations involving executives and creatives. FOR518 provides specialized expertise for Apple platform forensics.
What You Will Learn:
macOS Analysis
Examine APFS file system artifacts and structures
Analyze unified logs and system databases
Investigate user activity and applications
Recover deleted files and encryption keys
iOS Device Forensics
Acquire data from iOS devices and backups
Analyze iOS extractions and app data
Investigate messages, calls, and communications
Recover deleted content and media
Cross-Platform Correlation
Connect Mac and iOS evidence across devices
Investigate iCloud, AirDrop, and Apple services
Analyze AirTags, Apple Watch, and HomeKit
Track user activity across the Apple ecosystem
23 hands-on labs include course lab setup, system log parsing, APFS analysis, application fundamentals, pattern of life analysis, and a Mac Forensics and Incident Response Challenge.
The final capstone puts your Apple forensic skills to the test through a real-life scenario requiring comprehensive analysis.
Prepares for GIAC GIME certification (exam sold separately). Ideal for Digital Forensic Analysts, Law Enforcement Officers, Incident Response Team Members, and Media Exploitation Analysts.
36 CPE credits. 6 days of expert-led training.
Highlights
Examine macOS and iOS file systems and data layouts. Analyze APFS artifacts, unified logs, and user activity. Investigate the Apple ecosystem including AirTags, Apple Watch, and HomeKit. Perform timeline analysis and encrypted data recovery.
23 hands-on labs covering system log parsing, APFS file system analysis, application forensics, pattern of life examination, and a comprehensive Mac Forensics Challenge capstone.
Prepares for GIAC GIME certification (exam sold separately). Ideal for forensic analysts and incident responders. 6 days of expert-led training. Earn 36 CPE credits.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator to estimate your infrastructure costs.
This listing offers one pricing option: a single user license for the FOR518 - Single User course. You buy it as a contract, priced per unit. Each unit covers one individual's access to the course. To train more than one person, you add more units, so cost scales with the number of learners. The license is for individual use and cannot be shared. There are no separate tiers, instance sizes, or usage-based add-ons within this listing.
Top-of-mind questions for buyers
What does one FOR518 Single User unit cover, and can two people share it?
One unit is a license for one named individual to access the FOR518 course. The course materials, quizzes, and labs are for your individual use only. You cannot share, resell, or use them to train others. To train a second person, you buy a second unit.
How does course cost change as I add more learners?
Cost scales one-for-one with the number of learners. Each additional person needs their own unit, since a single-user license covers only one individual. There are no bundled seat tiers within this listing. Buying more units raises the total by the per-unit price for each added learner.
How long does my course access last after I buy a unit?
OnDemand self-study access runs for a set period after you start the course, and can be extended by purchasing an extension, up to one year from activation. Live Online courses include a fixed access window to recordings. Access ends when the period expires; check your specific format for exact duration.
www.sans.org
Helpful?
Vendor refund policy
Refunds available within 30 days if course not accessed.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Get 24x7 access to our world-renowned Digital Forensics & Incident Response (DFIR) team with a DFIR Retainer. We provide unmatched industry knowledge, understanding of your local threat landscape and deep expertise across all stages of the breach response lifecycle.
Harness local Large Language Models for DFIR investigations without exposing sensitive data to third-party services. Learn to deploy self-hosted AI, build custom forensic agents, and analyze logs and artifacts using natural language queries.
Investigate cybercrime from initial indicators through attribution. Covers threat actor tracking, dark web investigations, cryptocurrency tracing, criminal community monitoring, and evidence collection for law enforcement support.
Investigate Windows systems using forensic techniques that recover evidence of user activity, malware execution, and data theft. Covers registry analysis, browser artifacts, deleted file recovery, prefetch, shimcache, and timeline reconstruction for investigations that stand up to legal scrutiny.
Master tactical, operational, and strategic cyber threat intelligence skills. Learn to collect, analyze, and operationalize threat data to improve detection and response capabilities. Build intelligence products that inform security decisions across your organization. 36 CPEs.
Be the first to review this product. We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.