Jan. 25, 2024, 5:24 p.m. | SANS Digital Forensics and Incident Response

SANS Digital Forensics and Incident Response www.youtube.com

SANS Asia Pacific DFIR Summit 2023
Are You Really Getting the Benefits of Unified Logs?
Speaker: Minoru Kobayashi

Unified Logs was introduced as a new logging system in macOS 10.12 and records a variety of information. For example, in macOS 11 and later, a command such as "log show --info --predicate 'eventMessage begins with "LAUNCH: 0x"'" can be used to extract logs of application bundle execution. This information is very useful because macOS does not have forensic artifacts such as …

asia asia pacific benefits command dfir info information log logging logs macos pacific records sans speaker summit system

CyberSOC Technical Lead

@ Integrity360 | Sandyford, Dublin, Ireland

Cyber Security Strategy Consultant

@ Capco | New York City

Cyber Security Senior Consultant

@ Capco | Chicago, IL

Sr. Product Manager

@ MixMode | Remote, US

Corporate Intern - Information Security (Year Round)

@ Associated Bank | US WI Remote

Senior Offensive Security Engineer

@ CoStar Group | US-DC Washington, DC