Many forensics tools do a wonderful job of extracting data from Windows machines, but are less effective in Macintosh. OSForensics version 4.0 will include Mac OS X artifacts in its recent history, but to examine the directories mentioned in this chapter, or to execute the Bash commands, you may need more than tools can provide.
One technique is to create a copy of the forensic image and then mount it as a read-only virtual machine (VM). It is critical that you mount it read only. You can find instructions on the Internet for converting a forensic image to a virtual machine (such as a VMWare or Oracle VirtualBox). However, the forensic tool Forensic Explorer (http://www.forensicexplorer.com) will mount forensic images as read-only virtual machines, using the VM of your choice. OSForensics version 4 (http://www.osforensics.com) will also allow you to create a virtual machine from a forensic image.