SEC595: Applied Data Science and AI/Machine Learning for Cybersecurity Professionals


Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact UsAs macOS adoption grows in enterprise environments, threat actors are increasingly targeting these systems, leaving incident responders to adapt their investigative approaches. While Endpoint Detection and Response (EDR) solutions provide broad visibility, Apple’s Unified Logging System (AUL) often captures deeper, host-level telemetry that EDR tools miss. This session will compare EDR telemetry with macOS unified logs, demonstrating scenarios where unified logs answer key forensic questions that EDR cannot. Understand how to leverage AUL in investigations, use Private Data Logging, and work within log retention limitations. You will leave with actionable methods to enhance macOS incident response by tapping into this underutilized but powerful forensic data source.


Ayo Animashaun is a Security Engineer on Dropbox’s Detection and Response Team (DART), where he specializes in macOS forensics and malware analysis.
Read more about Fouad Animashaun













