Apple introduced APFS into iOS 10.3 and MacOS 13 as the default, fading HFS+ into obsolescence. The new filesystem also brings powerful new features, which greatly enance forensics capabilities, while at the same time introducing challenges. Years later, Apple released a much appreciated but partial specification.

This talk describes APFS in more detail, from the forensic analyst's perspective. Snapshots, Encryption, and Fusion Drives all have direct effect on data recovery, and these aspects, in particular, are addressed.

Jonathan Levin is the author of the "MacOS and iOS Internals" trilogy and of "Android Internals". He is CTO of Technologeeks, a group of like minded experts offering kernel, internals, and low-level consulting.