macOS Extraction of System Artifacts with Oxygen Forensic® KeyScout

Oxygen Forensic® KeyScout is a built-in module of Oxygen Forensic® Detective that extracts data from macOS, including pre-installed Apple apps, user-installed apps, system files, and user credentials. Let’s take a look at macOS system artifacts that are supported by Oxygen Forensic® KeyScout.   System Artifacts Extracted with Oxygen Forensic® KeyScout…

Hunting Computer Artifacts with Oxygen Forensic KeyScout

Oxygen Forensic KeyScout is a portable utility available at no additional charge within Oxygen Forensic Detective software. It allows searching and extracting data from a running computer system using OS API calls and user privileges. You can find the KeyScout utility on the Oxygen Forensic Detective home screen.  Once located…