About

I am Tim Korver, a digital forensic analyst and trainer based in the Netherlands. I have worked in law enforcement for 25 years, of which more than 13 years in digital forensics.

I am a core instructor in Forensic Digital Investigation at the Netherlands Police Academy, where I train operational specialists. My own research focuses on the Apple Unified Log. What it records, how long it survives, and how far an interpretation can defensibly be taken.

The work

I work with the Dutch Law enforcement and Public Prosecution Service on improving how the Apple Unified Log is acquired, verified and analysed in practice.

I completed SANS FOR518 Mac Forensic Analysis and hold a degree in Forensic ICT. My graduation research on the Apple Unified Log is where this site started.

Elsewhere

My work has been featured in the Forensic Focus Digital Forensics Round-Up.

Artifacts I documented have been contributed to iLEAPP, maintained by Alexis Brignoni.

My research on the Unified Log has been referenced by Alexis Brignoni on the LEAPPs blog.

Posts from this site appear in This Week in 4n6.

My artifact catalogue is referenced by ElcomSoft as a resource for Apple Unified Log analysis.

LinkedInGitHubYouTube

What this site is

Two things.

Individual artifacts, documented so you can find them when you need them. That is the easier half.

And a method for reading a Unified Log. How to order entries by evidential strength, how to verify a causal chain instead of trusting proximity in time, and where to stop. That is the harder half to write and the more useful half to share. The strings change with every OS release. The way of reading does not.

All research published here is performed on my own reference devices, with logged actions and noted timestamps. No casework, ever.

Contact

tim@thesisfriday.com

Questions about artifacts, corrections, research ideas and teaching requests are all welcome. Corrections most of all. If I got something wrong I would rather hear it from you than leave it standing.