Latest news

MacOS support comes to Magnet Nexus

Many organizations like the MacOS environment for its stability, security, and intuitive design. That’s why over the past decade, Mac OS adoption in the corporate sector has been growing. In US-based enterprise companies (1,000+ employees), IDC reported the usage of macOS devices is around 23% in 2021, up 6% from two years prior.

As more and more organizations offer employees Mac devices, in addition to PCs, the need for versatile DFIR tools that work seamlessly across different operating systems becomes more critical.

This is why we are thrilled to announce that Magnet Nexus a remote endpoint collection and analysis solution built to save you time and to get you forensic insights faster, now supports MacOS investigations!

As a SaaS-based solution, investigative teams can harness the power of cloud-based resources, making it easier than ever to conduct large-scale investigations without the hassle of complex installations, maintenance, and update processes.

The decision to extend support for MacOS, in addition to Windows and Linux endpoints, is rooted in our commitment to helping simplify digital investigations when investigation complexity continues to grow.

Magnet Nexus for Mac-first or hybrid-OS organizations

With the addition of MacOS support, you can now use Nexus to:

  • Have one solution to collect from multiple different endpoints regardless of OS type: For organizations with mixed operating system environments, the introduction of MacOS support means investigative teams can now collaborate in one solution on Windows, Linux, and Mac investigations.
  • Deploy agents using your preferred method, including Jamf Pro: Generate a signed Mac agent in Nexus and deploy it using your preferred method, including popular device management solution for Apple devices: Jamf Pro. Learn more about how to deploy the Nexus agent using Jamf Pro here.
    • Note: The Nexus agent must be “Allowlisted” by the corporate policy to avoid any pop-ups on the Mac endpoint. This includes Transparency Consent Controls (TCC) as well as Full Disk Access.
  • Key artifacts included and more to come: Collecting and analyzing key Mac-only artifacts such as Network Profiles, Bash/ZSH Sessions, Biomes (coming soon), and Daily Logs (coming soon) is crucial in private sector digital forensic investigations.
    • These Mac OS-specific artifacts, like Bash/ZSH session logs, provide insight into command-line activities, revealing system-level operations or potential modifications to system files. While some artifacts, such as browser data from Chrome, Edge, and Firefox, are cross-platform, they are equally important for tracing internet usage, identifying potential data exfiltration, and uncovering the user’s online behavior.
    • Additionally, Outlook email data, SSH keys (often found on Mac OS systems), and USB connection history are vital for understanding communication patterns, remote access, and the use of external storage devices, which may be relevant in data theft cases. Text documents across platforms offer direct evidence of information creation, modification, or access. By examining these artifacts, forensic investigators can reconstruct events, identify unauthorized actions, and protect corporate assets and data integrity.

How to use Magnet Nexus for MacOS investigations

Nexus was built to be easy-to-use, and as a SaaS solution, with minimal to no set-up, maintenance, or updating required.

Mac investigations in Nexus are no different. It’s as simple as logging in (from any browser with an internet connection!), creating a Mac agent, deploying it using your preferred method, and creating a case. Check out this interactive demo to see how easy it is firsthand:

Request a free trial of Magnet Nexus today!

At Magnet Forensics, our mission is to empower digital forensics professionals with the tools they need to solve cases faster and more efficiently.

The addition of Mac support to Nexus is another step forward in achieving that goal. We’re excited to see how you’ll use this new capability, alongside Windows and Linux endpoint investigations, to help find the truth.

Subscribe today to hear directly from Magnet Forensics on the latest product updates, industry trends, and company news.

Start modernizing your digital investigations today.

Top