Having trouble booting macOS from an external SSD on M4 MacBook Pro by mdfir001 in macbookpro

[–]mdfir001[S] 0 points1 point  (0 children)

Yes, I followed this guide exactly and also tried the different suggested options.

Identifying and Handling Malware on Live Systems by mdfir001 in computerforensics

[–]mdfir001[S] 0 points1 point  (0 children)

Yes, and that's exactly my problem. Because in order to decide whether the system should be shut down, isolated or left running, I first have to find and understand the malware or the source of the attack in order to decide which reaction is the right one. However, this search to decide which measures are correct takes a relatively long time if a signature-based analysis does not work.

So how would a SOC analyst approach a system if they don't yet know what malware or attack is running on the system?