
macOS Lockdown Mode: A DFIR Odyssey
Source: YouTube · SANS Digital Forensics and Incident Response · published Aug 15, 2025 · 32:48
Mac OS Lockdown Mode is a high-security feature designed to protect targeted individuals from sophisticated cyberattacks by restricting device functionality, which leaves distinct forensic artifacts useful for investigators.
Key Takeaways:
• The speaker introduces themselves as a security analyst at Salesforce and a DFIWS organizer, focusing on Mac OS and iOS malware research 0:02
• The presentation agenda covers the detection methods, forensic artifacts, and caveats associated with enabling Lockdown Mode 1:00
• Lockdown Mode significantly restricts standard user behaviors to mitigate advanced persistent threats 1:03
Understanding these restrictions and their forensic implications is crucial for digital investigators analyzing compromised high-risk devices.
Sources:
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 0.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
Good morning, good afternoon, good evening to the folks who are joining from different parts of the world and today we are going to you know cover Mac OS lockdown mode and uh this is just you know my brief introduction. So I work as a security analyst at Salesforce and I am also a organizing committee member for DFIWS and I do enjoy researching on Mac OS and iOS is dealing with a lot of malware and forensics and uh I'm really thankful for SANS for you know inviting me back. It's really good to be back since I spoke in 2023 DeFi summit. So thanks for that and yes uh this skipping to the agenda. This is what we are going to cover today. Uh all about lockdown mode. How do you actually detect it? What are the forensic artifacts? what are some of the caveats and some other stuff. So just a warn…