CASE STUDY

Case Study: Client Turns to Sandline to Unlock an Encrypted MacBook Without a Password 

How cross-device analysis and password pattern recognition created a path forward when standard recovery options had been exhausted

The password Sandline needed was not among the more than 100 credentials recovered from the user’s iPhone. The breakthrough came from what those credentials revealed: a repeatable pattern. 

A Specialized Forensic Investigations Practice

Sandline Global is an end-to-end eDiscovery company with a fully staffed forensic laboratory and a team of examiners located across the United States and overseas. Known for our specialized Forensic Investigations practice, we conduct in-lab examinations and handle complex device imaging, cloud acquisitions, data recovery, and investigative matters from initial preservation through downstream review and production. 

Sandline is known for finding a path forward when an investigation appears to have reached a dead end. Our examiners draw on deep technical experience to develop practical workarounds and tailored solutions when standard methods are not enough. This matter is one example. 

Client Profile

A leading regional law firm representing corporate and individual clients in complex litigation and investigative matters. 

The firm engaged Sandline in connection with an estate matter to preserve and extract data from an iPhone and a MacBook. The laptop was protected by Apple FileVault, and neither the user’s login password nor the FileVault recovery key was available. 

The Challenge

FileVault encrypts the data stored on the MacBook. The data remains protected even if the device’s physical storage drive is removed and connected to another computer. Although the MacBook was physically available, its contents remained inaccessible without a valid credential or recovery key. 

Repeated authentication attempts on a modern device can also create unnecessary risk, including increasing delays, temporary lockouts, or a requirement for the recovery key. Sandline needed a defensible method that preserved the original evidence while providing a safe way to evaluate potential passwords. 

Sandline’s Approach

Preserve first. 

Sandline created a forensic image of the encrypted MacBook before attempting further access. The team then performed password-testing efforts against the preserved encrypted data rather than repeatedly entering credentials on the original computer. This maintained the integrity of the source evidence and reduced the risks associated with direct authentication attempts. 

Use one device to inform another. 

The estate had maintained a record of the user’s iPhone passcode, allowing Sandline to access the phone and perform a Full File System (FFS) extraction. The extraction provided access to application data, system information, protected data stores, and other artifacts beyond those typically available through a standard logical collection. From those artifacts, Sandline identified more than 100 stored credentials associated with the user’s applications, web activity, and other services. 

Analyze the pattern, not just the password list. 

None of the recovered credentials unlocked the MacBook. Rather than stopping there, Sandline’s examiners proactively analyzed the passwords for common elements. They identified shared roots and recurring variations in capitalization, symbols, and other characters. Using those patterns, the team developed its own targeted password variations and safely tested them against the preserved encrypted data. One of the newly generated candidates was successful. 

Complete the acquisition. 

With a valid password identified, Sandline returned to the original MacBook, authenticated to the device, and performed a forensic acquisition of its decrypted contents. The data could then be examined, inventoried, and provided to the case team. 

The workflow eliminated the need to manually review 36,821 documents, helping counsel reduce review costs and move through the population more efficiently. 

The Outcome

By correlating forensic artifacts across devices, Sandline turned an otherwise inaccessible encrypted laptop into a viable source of evidence. The iPhone did not contain the MacBook password itself; it contained the evidence needed to understand how the user created passwords and develop a successful variation. 

This matter demonstrates the value of pairing forensic technology with investigative judgment. Sandline did more than run a list of recovered credentials: our examiners interpreted the available artifacts, formed and tested a targeted hypothesis, preserved the integrity of the original evidence, and carried the successfully acquired data into the broader eDiscovery lifecycle. Counsel received file and metadata inventories from the devices, giving the case team visibility into the available content and allowing responsive data to proceed to review.