Distinguish your fluency in Mac and iOS systems as a forensic professional equipped with the skills and knowledge to analyze data from any Apple device.
The GIAC iOS and macOS Examiner (GIME) certification validates a practitioner's computer forensic analysis and incident response skills for Mac and iOS systems. GIME certification holders are qualified to carry out traditional investigations as well as intrusion analysis scenarios for compromised Apple devices.
Areas Covered
- Mac and iOS file systems, system triage, and application data
- Mac and iOS incident response, malware, and intrusion analysis
- Mac and iOS user data and timeline analysis
Who is GIME for?
- Experienced digital forensic analysts
- Law enforcement officers, federal agents, and detectives
- Media exploitation analysts
- Incident Response Team members
- Information security professionals seeking expertise in macOS and iOS system internals
- SANS DFIR alumni looking to round out their forensic skills
Instructor Testimonial
“Instructor Testimonial
Forensic professionals need tool independent training and certification to show they can tackle any Mac or iOS investigation whether it is traditional forensics or incident response. The GIME certification provides students the confidence they need to analyze data from any Apple device.”
Exam Format
- 1 proctored exam
- 2 hours
- Minimum passing score of 67%
- 75 questions
Note: GIAC periodically reviews and may update certification specifications to ensure fairness, validity, and reliability. Using a psychometric standard-setting study, GIAC has set the passing score for the GIME exam at 67% for all candidates who receive the exam version released on or after [DATE].
To confirm the exam format and passing score that apply to your specific attempt, please refer to the Certification Information section of your GIAC account: https://exams.giac.org/pages/attempts.
Certification Delivery
GIAC certification attempts will be activated in your GIAC account after your application has been approved and according to the terms of your purchase. Details on delivery will be provided along with your registration confirmation upon payment. You will receive an email notification when your certification attempt has been activated in your account. You will have 120 days from the date of activation to complete your certification attempt.
NOTE: All GIAC Certification exams are web-based and required to be proctored. There are two proctoring options: remote proctoring through ProctorU, and onsite proctoring through PearsonVUE. Click here for more information.

Exam Certification Objectives & Outcome Statements
- Apple Application AnalysisThe candidate will analyze configurations and data for contacts, notes, wallet, photos, maps, screen time and apple watch applications.
- Apple File System ArtifactsThe candidate will examine event artifacts created by file system operations, operating system use, Spotlight, and removable media devices.
- Apple Systems TriageThe candidate will prepare system triage with fundamental system artifacts. Triage information includes system identifiers, OS installation and backup dates, management profiles, network information, and user accounts.
- Application FundamentalsThe candidate will identify basic application data structures and construct SQL queries to examine the data.
- Document and iCloud analysisThe candidate will distinguish changes across document versions and iCloud data.
- Encrypted Container and Memory AnalysisThe candidate will identify memory acquisition methods and use brute force techniques to access encrypted data for analysis
- Incident ResponseThe candidate will examine artifacts created by malicious code and analyze volatile system artifacts.
- Introduction to Apple Operating SystemsThe candidate will differentiate between system acquisition and data types available for analysis.
- Introduction to Disk and File SystemsThe candidate will identify key data types associated with Apple systems and mount system images for analysis.
- Log Analysis and Timeline CreationThe candidate will correlate key log types and create an event timeline.
- Pattern of LifeThe candidate will organize system based artifacts to track user behavior and habits.
- Productivity Application AnalysisThe candidate will analyze configurations and data for mail, safari, communication, and reminder applications.
- User Data and System ConfigurationThe candidate will identify artifacts created from system configuration and user data.
Practice Tests
- Practice exams are a simulation of the real exam, allowing you to become familiar with the test engine and style of questions
- Practice exams can serve as a gauge to determine if your preparation methods are sufficient
- The bank of practice questions is limited, so you may encounter the same question on multiple practice tests
- Practice exams never include actual exam questions
- Purchase a GIME practice test here
Other Resources
- Training is available in a variety of modalities including live training and OnDemand
- Practical work experience can help ensure that you have mastered the skills necessary for certification
- College level courses or self-paced study through other programs or materials may meet the needs for mastery
- Understand the procedure to contest exam results
- Use this justification letter to share key details of this certification opportunity with your boss

