CoreAnalytics in macOS 10.13
26 juli 2018 - 10:22   
geplaatst door: puk1980
https://www.crowdstrike.com/blog/i-know-what-you-did-last-month-a-new-artifact-of-execution-on-macos-10-13/

Citaat
Analysts that perform macOS forensics have had few, if any, artifacts of program execution to rely on during investigations — until now. In macOS 10.13 (High Sierra), Apple introduced CoreAnalytics, which is a system diagnostics mechanism that maintains a record of Mach-O programs that have executed on a system over approximately one month. CoreAnalytics can serve a number of valuable analytical purposes for both insider threat investigations and incident response. The artifact can be used to:

- Determine the extent to which a system was in use, with accuracy up to one day

- Determine which programs were run on a particular day, whether in the foreground or in the background

- Determine how long, approximately, a program was running and/or active, as well as provide an approximate number of times the program was launched or brought to the foreground interactively

This article provides a technical overview and analysis of the CoreAnalytics artifacts found in macOS 10.13, as well as a means for investigators to parse this artifact into a more digestible format.

meer...
antw: CoreAnalytics in macOS 10.13
28 juli 2018 - 08:14    reactie #1
geplaatst door: Spooter
interessant
antw: CoreAnalytics in macOS 10.13
28 juli 2018 - 09:21    reactie #2
geplaatst door: srna513006
Ik begrijp globaal wat daar staat maar weet eigenlijk niet wat daar nu mee gedaan wordt en ik vraag mij wel af, valt dit nu positief of negatief uit voor de standaard Apple gebruiker?
Mac Mini M4 - iPad Air (4e gen) v15.x - iPhone XR - Apple TV 4K - Watch 8
antw: CoreAnalytics in macOS 10.13
28 juli 2018 - 09:33    reactie #3
geplaatst door: GeorgeM
Misschien helpt dit:

Citaat
Conclusion
CoreAnalytics provides a trove of information about the usage of a system and its applications. Program execution history that covers a month of activity can serve a crucial purpose in investigations where collection of evidence is not immediately feasible. Though documentation from Apple may provide additional clarity into the purpose of certain fields and the nature of their values, the analysis above provides a strong basis on which analysts can begin to investigate application activity on macOS systems.

Volgens mij betekent dit dat mensen met (diepgaande) toegang tot je systeem meer te weten kunnen komen over wat jij op je Mac gedaan hebt. Maar dan moeten ze natuurlijk wel eerst binnen zijn.