Comment Re:How would you exfiltrate data? (Score 1) 25
The way they used the "Crowdstrike Outage" to hide crimes was to reboot into a WinPE environment and 'do recovery' while wiping evidence.
I haven't used a Mac in a while but it used to be booting from external media was easy.
I can imagine ways to require keys from secure boot and hardware to decrypt the main drive but I haven't seen those deployed myself.
So, reboot from external, copy data, reboot normally.
Somebody can tell me if Apple already provides a way to avoid this.