
Mac Hunt Walkthrough - macOS Phishing Compromise Investigation
macOSforensicsphishingmalwareTryHackMewalkthroughcybersecuritydigital forensicsincident responsedata exfiltration
This is a detailed forensic walkthrough of the TryHackMe Mac Hunt room, documenting a macOS phishing compromise investigation. The analysis traces how a victim named Jake was targeted through a LinkedIn direct message containing a fake job offer PDF, which instructed him to switch from office WiFi to his personal iPhone hotspot and download a malicious MeetMeLive installer from a spoofed domain. The walkthrough demonstrates locating artifacts across macOS system files including Safari downloads, WiFi configurations, DHCP leases, TCC databases, and LaunchAgents to reconstruct the attack timeline, identify the malware's Full Disk Access permissions, persistence mechanism, and data exfiltration to http://techthm.thm/exfil.