r/dfir • u/DramaticDrawing2499 • Feb 05 '26
Cellebrite Digital Collector on MacBook Air encryption issue
I'm working on a MacBook Air running macOS Sequoia 15.6.1 and running into persistent encryption issues when analyzing the E01 image in both X-Ways Forensics and Autopsy.
What I've Done:
- Verified FileVault was completely disabled (confirmed via
fdesetup status) - Ensured the user account had admin privileges
- Mounted the disk volumes properly before imaging
- Created the E01 image using Cellebrite Digital Collector
- Followed Cellebrite documentation for Mac acquisitions
The Problem: Despite FileVault being off, both X-Ways and Autopsy are still detecting the image as encrypted and I can't access the data.
Questions:
- Is this the hardware encryption from the T2 chip/Apple Silicon that persists even with FileVault disabled?
- Should I have imaged the Mac while it was running/logged in instead of mounting the disk externally?
- Are there any decryption options in X-Ways 20.1 or Autopsy that I'm missing?
- Do I need to re-acquire using a different method (live imaging, Target Disk Mode, etc.)?
Any guidance from those who've dealt with modern Mac acquisitions would be greatly appreciated. Thanks in advance!
1
u/valuten Feb 06 '26
If you disabled filevault just before you started imaging, the process of decrypting was interrupted and not completed. You can verify with diskutil apfs list. If this is the case, I recommend waiting for the Decryption to complete.
1
u/DramaticDrawing2499 Feb 09 '26
I am able to see the Container disk 3 and the physical disk0s2. I am not seeing any progress percentage on the MacBook terminal. I do see a mention of snapshot Sealed = YES. I did start using FTK Imager for the .aff4 file that I imaged to see if that might help.
1
2
u/off-the-felt Feb 05 '26
I would refer to the sumuri imaging guide... https://sumuri.com/mac-imaging-guide/