Skip to content

macOS DFIR field reference

Read a Mac like a timeline.

Where macOS keeps its evidence, how to collect it without breaking it, and how to turn Unified Logs, FSEvents, KnowledgeC, TCC and launchd into one defensible story.

evidence areas
6
in-depth guides
12
glossary terms
12
Illustrative example: one event per evidence source, merged on a single UTC clock.

/evidence-map

The macOS evidence map

Six areas cover the questions every Mac investigation asks: how to collect, what ran, what changed on disk, what the user did, how it persisted, and what it was allowed to touch.

01

Acquisition & Triage

Collect a Mac without losing evidence: Aftermath, mac_apt, UAC and Apple Silicon.

  • Aftermath
  • mac_apt
  • UAC
  • log collect
  • macOS Forensic Acquisition: Live vs Dead-Box Triage
  • Apple Silicon Forensics: What M-Series Macs Change

2 guides

02

Unified Logs

Query tracev3 logs for logins, sudo, SSH, installs, Gatekeeper and TCC prompts.

  • /private/var/db/diagnostics
  • uuidtext
  • .logarchive
  • macOS Unified Logs Forensics: tracev3, log show, Predicates

1 guide

03

APFS, Snapshots & FSEvents

Read APFS timestamps, mount local snapshots and replay file-system change history.

  • /.fseventsd
  • tmutil
  • kMDItemDateAdded
  • APFS Snapshots and Timestamps: A Forensic Guide for macOS
  • FSEvents Forensics: The macOS File System Change Log

2 guides

04

User Activity

KnowledgeC, Biome, Spotlight and Safari: what the user opened, when and for how long.

  • knowledgeC.db
  • Biome
  • History.db
  • .Spotlight-V100
  • knowledgeC.db and Biome: Reconstructing Mac User Activity
  • Spotlight Forensics: Metadata Stores, mdls and Parsing
  • Safari Forensics on macOS: History.db, Downloads and Tabs

3 guides

05

Execution & Persistence

Trace downloads through quarantine and Gatekeeper, then hunt LaunchAgents and login items.

  • com.apple.quarantine
  • QuarantineEventsV2
  • LaunchAgents
  • sfltool dumpbtm
  • Quarantine Events and Gatekeeper: Tracing Mac Downloads
  • Investigating launchd Persistence on macOS

2 guides

06

TCC & Keychain

See which apps were granted Full Disk Access, screen recording or accessibility, and what the keychain reveals.

  • TCC.db
  • login.keychain-db
  • MDMOverrides.plist
  • TCC Database Forensics: macOS Privacy Permissions
  • macOS Keychain Forensics: Concepts and Metadata

2 guides

/guides

Start with a guide

All guides

03 · APFS, Snapshots & FSEvents

FSEvents Forensics: The macOS File System Change Log

How the macOS .fseventsd logs record file creation, deletion and rename events, how to parse them, and how to estimate dates without per-record timestamps.

Read guide

05 · Execution & Persistence

Investigating launchd Persistence on macOS

Find and analyze macOS persistence: LaunchAgents, LaunchDaemons, launchctl, Background Task Management (sfltool dumpbtm), cron, periodic and profiles.

Read guide

/method

How the guides are written

  • Artifact first

    Every guide starts from the file on disk: path, format, epoch and the question it answers.

  • Version aware

    macOS changes artifacts between releases. Guides flag what moved, what was renamed and what to verify on your target.

  • Defensive by design

    Collection, parsing and detection only. No exploit code, no bypass recipes, no credential theft.

/glossary

Speak the vocabulary

Short definitions of the terms you will meet in every macOS case.

Full glossary