Spickzettel macOS-Artefakte
Alle Artefakte in einer Tabelle, nach Kategorie gruppiert. Im Querformat drucken oder im Browser als PDF speichern.
www.macforensics.app/de/artifacts
Die wichtigsten Artefakte sind übersetzt. Einträge mit dem Hinweis „Englisch“ öffnen die englische Seite.
| Artefakt | Speicherort | Belegt | Zeitstempel | Zugriff | Aufbewahrung | Auswertung |
|---|---|---|---|---|---|---|
| Ausführung | ||||||
| Crash ReportsEnglischmacOS 10.15+ | /Library/Logs/DiagnosticReports/ | That a given executable ran on the Mac, from which path, launched by which parent, and when it crashed or hung | Local time with UTC offset in JSON strings and file names | root, or membership of _analyticsusers (admins are members) | Moved to Retired and cleaned up by SubmitDiagInfo; days to weeks | jq, mac_apt, Console |
| Gatekeeper- und XProtect-Spuren unter macOSmacOS 10.15+ | /var/db/SystemPolicyConfiguration/ExecPolicy | Ob macOS ein bestimmtes Programm geprüft, zugelassen, blockiert oder bereinigt hat und welche Verhaltensweisen es gemeldet hat | Unified Log: Anzeige in der mit jedem Eintrag gespeicherten Zeitzone, sofern --timezone fehlt; XPdb dt: Datum und Uhrzeit als Text; ExecPolicy: Unix-Sekunden | root; Full Disk Access; XPdb ist ab 26.2 ein Data Vault | Unified Log: Tage bis Wochen; Datenbanken: bis zum Neuaufbau (variiert) | log, mac_apt, sqlite3 |
| InstallHistory.plistEnglischmacOS 10.15+ | /Library/Receipts/InstallHistory.plist | Which software packages and updates were installed, when, and through which installer process | Plist date values (UTC); receipt install-time in Unix epoch seconds | Readable by all users; InstallHistory.plist is writable by the admin group | Until deleted; receipts until pkgutil --forget or removal | mac_apt, Plaso, pkgutil, plutil |
| Mounted Disk Images on macOSEnglischmacOS 10.15+ | /Volumes/<name>/ (mount point), plus logs and per-user caches | That a disk image was mounted, under which volume name, which apps were run from it and where it came from | Unified Log entries in UTC; FSEvents event IDs; file system times of the image and translocation folders | root for logs and /private/var/folders; owning user for Downloads | Log events follow rotation; the image file, quarantine and FSEvents records persist longer | hdiutil, log, FSEventsParser, mac_apt, xattr |
| Shell-Historie unter macOSmacOS 10.15+ | ~/.zsh_history | Welche Befehle ein Benutzer in einer interaktiven Shell eingegeben hat, in welcher Reihenfolge und in welchem Terminal-Fenster | Standardmäßig keine; Sekunden der Unix-Epoche nur, wenn EXTENDED_HISTORY (zsh) oder HISTTIMEFORMAT (bash) gesetzt ist | Dateibesitzer oder root; einfache Dateien im Home-Ordner | zsh-Standard SAVEHIST=1000 Zeilen; Sitzungsdateien des Terminals werden nach etwa zwei Wochen gelöscht | mac_apt, grep, sed |
| sudo LogsEnglischmacOS 10.15+ | /private/var/db/diagnostics/ | Which account ran which command as root (or another user), from which directory and terminal, and failed attempts | Unified Logs: timestamp with UTC offset; ts files: file mtime plus monotonic counters | root to read the log store, /etc/sudoers and /var/db/sudo | Unified Log rotation (days to weeks); ts records until reboot or overwrite | log, macos-UnifiedLogs, mac_apt, Plaso |
| TCC.dbmacOS 10.15+ | /Library/Application Support/com.apple.TCC/TCC.db | Welche Programme sensible Datenschutzberechtigungen angefordert oder erhalten haben, durch wen, und wann sich die Entscheidung zuletzt änderte | Unix-Epoche in Sekunden (UTC) in last_modified | Full Disk Access zum Lesen; die System-Datenbank ist zusätzlich durch SIP geschützt | Bis die Zeile geändert, zurückgesetzt (tccutil) oder die App entfernt wird | mac_apt, Plaso, Velociraptor, sqlite3 |
| Persistenz | ||||||
| Anmeldeobjekte und BTM-Datenbank unter macOSmacOS 10.15+ | /private/var/db/com.apple.backgroundtaskmanagement/BackgroundItems-v*.btm | Welche Anmeldeobjekte, Agents und Daemons registriert wurden, von welchem Entwickler, und ob sie zugelassen waren | NSKeyedArchiver-Datumswerte (Mac Absolute Time, UTC) plus Zeiten des Dateisystems | root und Full Disk Access (BTM-Speicher); besitzender Benutzer (alte backgrounditems.btm) | Bis das Objekt entfernt wird oder sfltool resetbtm den Speicher neu aufbaut | DumpBTM, bgiparser, Plaso, sfltool |
| Configuration Profiles and MDMEnglischmacOS 10.15+ | /private/var/db/ConfigurationProfiles/ | Which profiles and payloads (certificates, proxies, VPN, TCC/PPPC, system extensions, login items) were installed, by MDM or manually, and when | Install dates in the profile store (plist dates); Unified Log entries in UTC | root; the profile store is SIP-protected on current releases, read it from an image or with profiles(1) live | Profiles persist until removed; install events follow Unified Log rotation | profiles, log, plutil, macos-UnifiedLogs |
| cron, at and periodicEnglischmacOS 10.15+ | /usr/lib/cron/tabs/ | Whether a command was scheduled to run repeatedly or once through a Unix-style scheduler, by which account | File system times of tab and job files (APFS, UTC); cron schedules are in local time | root (tabs directory is mode 700) | Until the crontab, job or script is removed | crontab, mac_apt, Aftermath |
| Kernel and System ExtensionsEnglischmacOS 10.15+ | /Library/SystemExtensions/db.plist and /private/var/db/SystemPolicyConfiguration/KextPolicy | Which third-party kernel extensions and system extensions were installed, approved, activated or loaded, by which team ID, and when | KextPolicy created_at / last_seen as date-time values (check the storage type per image); Unified Log entries in UTC | root; KextPolicy is SIP-protected, read it from an image or with Full Disk Access | Records persist until the extension is removed and often after; Unified Log events follow rotation | kmutil, systemextensionsctl, sqlite3, plutil, KnockKnock, APOLLO |
| LaunchAgents und LaunchDaemonsmacOS 10.15+ | ~/Library/LaunchAgents, /Library/LaunchAgents, /Library/LaunchDaemons | Welcher Code automatisch startet, als welcher Benutzer, bei welchem Auslöser und seit wann | Keine internen Zeitstempel; APFS-Dateizeiten (Nanosekunden, UTC) | Benutzer-Agents: besitzender Benutzer; /Library: root; FDA für das Sicherungstool empfohlen | Bis die Plist gelöscht wird; Overrides und BTM-Einträge können sie überdauern | mac_apt, Plaso, KnockKnock, plutil |
| Dateizugriff | ||||||
| APFS-Zeitstempel und lokale Snapshots unter macOSmacOS 10.15+ | /System/Volumes/Data | Wann Dateien erstellt, geändert und einem Ordner hinzugefügt wurden und wie das Volume Stunden zuvor aussah | Nanosekunden seit 1970-01-01 UTC (Unix-Epoche) | Jeder Benutzer für stat auf eigene Dateien; root plus Full Disk Access zum Einhängen von Snapshots | Zeitstempel bis zum Überschreiben; stündliche lokale Snapshots werden etwa 24 Stunden behalten | libfsapfs, stat, mac_apt |
| Cloud Storage Clients on MacEnglischmacOS 10.15+ | ~/Library/CloudStorage/ plus each client's Application Support, Group Container and log folders | Which cloud accounts were linked, which files existed in or passed through the synced folders, and when they were uploaded, downloaded or deleted | Mixed: Unix epoch (seconds or milliseconds) in most client databases, Mac absolute time in File Provider data, local time in some logs | Owning user; some client databases are encrypted or obfuscated and need the user's keychain | Databases track the current sync state; logs rotate by size and age; deleted files may remain in the cloud service's own trash | sqlite3, FSEventsParser, plutil, grep |
| CUPS Print Jobs and LogsEnglischmacOS 10.15+ | /private/var/spool/cups/ and /private/var/log/cups/ | Which user printed which job (document name and application), to which printer, when, and how many pages or copies | IPP attributes time-at-creation / processing / completed in Unix epoch seconds; log lines in local time with UTC offset | root for the spool and logs; printers.conf readable by root | Control files for up to the configured job history (default 500 jobs); data files usually removed after the job; logs rotate by size | mac_apt, lpstat, grep |
| FSEvents (.fseventsd)macOS 10.15+ | /System/Volumes/Data/.fseventsd/ | Welche Pfade auf einem Volume erstellt, geändert, umbenannt oder gelöscht wurden, in Ereignisreihenfolge | Keine pro Eintrag; Schätzung über die mtime der Log-Datei und datierte Pfade | root; auf einem Live-System Full Disk Access | Fortlaufend, von fseventsd bereinigt (Monate beobachtet, variiert) | FSEventsParser, mac_apt |
| iCloud Drive (CloudDocs)EnglischmacOS 10.15+ | ~/Library/Application Support/CloudDocs/session/db/client.db | Which files were in the user's iCloud Drive, when, and from which of their devices | Unix epoch seconds (UTC) in CloudDocs databases | User or root; Full Disk Access for the collector on a live system | Current sync state; items leave when deleted and purged from iCloud | mac_apt, sqlite3 |
| Microsoft Office and Outlook for MacEnglischmacOS 10.15+ | ~/Library/Containers/com.microsoft.<App>/ and ~/Library/Group Containers/UBF8T346G9.Office/ | Which documents were opened in Word, Excel and PowerPoint, from which paths and when, the Office user identity, and the local copy of Outlook mail | Plist dates (kLastUsedDateKey); Windows FILETIME in MicrosoftRegistrationDB.reg; Outlook database dates per schema | Owning user; Group Containers and Containers need Full Disk Access to collect on current releases | MRU lists hold a limited number of entries; Outlook caches follow account sync settings | mac_apt, plutil, sqlite3 |
| Photos.sqliteEnglischmacOS 10.15+ | ~/Pictures/Photos Library.photoslibrary/database/Photos.sqlite | When media was captured, added, edited, hidden or trashed, where it was taken and which app or device imported it | Mac absolute time (seconds since 2001-01-01 UTC); time zone offset per asset | TCC-protected library: Full Disk Access (or Photos access) for the collector | Until deleted; Recently Deleted items are purged after 30 days | osxphotos, exiftool, sqlite3 |
| QuarantineEventsV2 und Quarantäne-xattr unter macOSmacOS 10.15+ | ~/Library/Preferences/com.apple.LaunchServices.QuarantineEventsV2 | Welche Dateien ein Benutzer heruntergeladen hat, von welcher URL und Ursprungsseite, mit welcher App und wann | Datenbank: Mac Absolute Time (UTC); xattr: Unix-Sekunden in Hex (UTC) | Besitzender Benutzer oder root; Full Disk Access für das Sicherungstool empfohlen | Bis zur Löschung oder Bereinigung (keine dokumentierte automatische Löschung) | mac_apt, Plaso, Velociraptor, sqlite3 |
| QuickLook Thumbnail CacheEnglischmacOS 10.15+ | $(getconf DARWIN_USER_CACHE_DIR)/com.apple.quicklook.ThumbnailsAgent/com.apple.QuickLook.thumbnailcache/ | That a file existed at a path and was displayed as a thumbnail or preview, with a cached image that can outlive the original | last_hit_date in Mac absolute time; file modification time stored in the version blob | Owning user or root; the cache sits under /private/var/folders, collect as root | Cache is pruned by size and age and rebuilt with qlmanage -r cache; not a long-term record | mac_apt, sqlite3, plutil |
| Recent Items (.sfl2/.sfl3)EnglischmacOS 10.15+ | ~/Library/Application Support/com.apple.sharedfilelist/ | Which documents, apps and servers a user recently opened, with full paths and source volumes | Mostly none per item; bookmark dates in Mac absolute time (2001 epoch) | User-owned; Full Disk Access for the collector on a live system | Rolling lists capped by the Recent Items count (default 10) | mac_apt, plutil |
| Spotlight Store (.Spotlight-V100)EnglischmacOS 10.15+ | /System/Volumes/Data/.Spotlight-V100/Store-V2/<UUID>/store.db | Where a file came from, when it was added and opened, and that it existed even after deletion | Mac absolute time (seconds since 2001-01-01 UTC); mdls shows UTC | root; Full Disk Access on a live system | Until the indexer updates or purges the entry, or the index is rebuilt | spotlight_parser, mac_apt |
| Time Machine BackupsEnglischmacOS 10.15+ | /Library/Preferences/com.apple.TimeMachine.plist | Which backup destinations were used, when backups ran, and what files looked like at each backup | Backup names YYYY-MM-DD-HHMMSS; plist dates as plist date objects | root plus Full Disk Access for tmutil listbackups and backup contents | Hourly 24 h, daily for a month, weekly after; oldest deleted when full | tmutil, Plaso, plutil |
| Benutzeraktivität | ||||||
| Apple MailEnglischmacOS 10.15+ | ~/Library/Mail/V10/MailData/Envelope Index | Which emails were sent or received, from and to whom, when, in which mailbox, and which attachments were opened | Envelope Index dates in Unix epoch seconds (UTC); message headers in RFC 5322 local time | TCC-protected (Mail data): Full Disk Access for the collector | Until deleted or removed from the server; local copies follow account sync settings | sqlite3, emlx (Python) |
| Apple Notes NoteStore.sqliteEnglischmacOS 10.15+ | ~/Library/Group Containers/group.com.apple.notes/NoteStore.sqlite | What a user wrote in Notes, when each note was created and last modified, attachments, folders, iCloud or local account, and deleted notes still in the database | Mac absolute time (seconds since 2001-01-01 UTC) | Owning user; the group container is TCC-protected, so the collector needs Full Disk Access | Until deleted; Recently Deleted keeps notes for about 30 days, and freed pages may survive in the WAL or free list | apple_cloud_notes_parser, mac_apt, sqlite3 |
| Biome-SEGB-StreamsmacOS 12+ | ~/Library/Biome/streams/restricted/<Stream>/local/ | Welche Apps im Fokus waren, besuchte Websites, verbundene Geräte und Netzwerke, mit Zeiten pro Eintrag | Mac Absolute Time (Cocoa) als Double in SEGB-Einträgen; Dateinamen sind Cocoa-Zeit in Mikrosekunden | Full Disk Access (Benutzer-Streams); System-Streams sind durch SIP eingeschränkt | Wochen für die meisten Streams (etwa 28 Tage, ein Wert aus iOS-Untersuchungen); abgelaufene Dateien wandern nach tombstone | mac_apt, ccl-segb |
| Calendar, Contacts and Reminders Databases on macOSEnglischmacOS 10.15+ | ~/Library/Application Support/AddressBook/, ~/Library/Group Containers/group.com.apple.reminders/, ~/Library/Calendars/ or group.com.apple.calendar | Who the user knew and how to reach them, which meetings and appointments existed, where and with whom, and which tasks were created or completed | Mac absolute time (seconds since 2001-01-01 UTC) in all three Core Data stores | Owning user; each store is TCC-protected (Contacts, Calendars, Reminders), so the collector needs Full Disk Access | Until deleted locally or through sync; deleted items may persist briefly for sync and in WAL files | sqlite3, APOLLO, plutil |
| Chrome and Firefox History on macOSEnglischmacOS 10.15+ | ~/Library/Application Support/Google/Chrome/Default/History | Which sites a user opened in Chrome, Chromium browsers or Firefox, when, and what they downloaded | Chrome: microseconds since 1601-01-01 UTC; Firefox PRTime: microseconds since 1970-01-01 UTC | File owner or root; give the collector Full Disk Access as well | Chrome: about 90 days of visits; Firefox: size-based expiration of old pages | Hindsight, mac_apt, sqlite3 |
| Dock and Finder PlistsEnglischmacOS 10.15+ | ~/Library/Preferences/com.apple.finder.plist | Which apps a user kept or recently ran in the Dock, and which folders, paths and servers they visited in Finder | Few per key; Dock tile dates in HFS+ seconds (1904 epoch) | User-owned; Full Disk Access for the collector on a live system | Until the preference changes or the user resets it | mac_apt, plutil |
| dslocal User AccountsEnglischmacOS 10.15+ | /private/var/db/dslocal/nodes/Default/users/<name>.plist | Which local accounts exist, when they were created, who is admin, and recent password and failed-login activity | accountPolicyData: Unix epoch seconds (UTC) | root; Full Disk Access recommended for the collector | Until the account is deleted; home may survive in /Users/Deleted Users | mac_apt, Velociraptor, plutil, dscl |
| knowledgeC.dbmacOS 10.15+ | /private/var/db/CoreDuet/Knowledge/knowledgeC.db | Welche Apps wann und wie lange genutzt wurden und ob das Display zu dem Zeitpunkt an war | Mac Absolute Time (Sekunden seit 2001-01-01 UTC) plus Offset in ZSECONDSFROMGMT | root plus SIP-Einschränkungen (System-DB); Full Disk Access (Benutzer-DB) | Auf typischen Systemen etwa vier Wochen an Ereignissen (je nach Stream unterschiedlich) | APOLLO, Plaso, sqlite3 |
| macOS Keychain FilesEnglischmacOS 10.15+ | ~/Library/Keychains/ | Which accounts, services, networks and certificates a user had saved, and when items were created or modified | File keychain: UTC strings YYYYMMDDhhmmssZ; keychain-2.db: Mac absolute time | Owning user or root; secrets need user credentials and, for data protection items, the original device | Until the item or keychain is deleted | security, sqlite3 |
| Messages chat.dbEnglischmacOS 10.15+ | ~/Library/Messages/chat.db | Who communicated with whom, what was said, when it was sent, delivered and read, and which files were exchanged | Nanoseconds since 2001-01-01 UTC (High Sierra+); older rows in seconds | TCC-protected (Messages data): Full Disk Access for the collector | Until deleted; Recently Deleted keeps items up to 30 days (Ventura+) | imessage-exporter, mac_apt, Plaso, sqlite3 |
| Notification Center DatabaseEnglischmacOS 10.15+ | ~/Library/Group Containers/group.com.apple.usernoted/db2/db | Which app showed which notification text to the user, and when it was delivered | Mac absolute time (seconds since 2001-01-01 UTC) | Sequoia+: TCC-protected group container (Full Disk Access); older: owning user | Not documented by Apple; varies, measure from oldest delivered_date | mac_apt, Plaso, sqlite3 |
| Safari History.dbmacOS 10.15+ | ~/Library/Safari/History.db | Welche URLs ein macOS-Benutzer in Safari geöffnet hat, wann, über welche Weiterleitungen und ob der Verlauf gelöscht wurde | Mac Absolute Time (Cocoa, Sekunden seit 2001-01-01 UTC), gespeichert als REAL | Full Disk Access für den lesenden Prozess (TCC); root allein reicht nicht | Benutzereinstellung, standardmäßig ein Jahr oder bis zum manuellen Löschen; Download-Liste standardmäßig ein Tag | mac_apt, APOLLO, sqlite3, plutil |
| Saved Application StateEnglischmacOS 10.15+ | ~/Library/Saved Application State/<bundle-id>.savedState/ | Which apps were open with which windows, document titles and dock menu entries, and for Terminal, the text visible in each window | File system times of windows.plist and data.data (last state save) | Owning user; readable from an image or with Full Disk Access | Rewritten while the app runs; kept after quit when Close windows when quitting an app is off; deleted on clean quit otherwise | mac_apt, plutil |
| Screen Time DatabasesEnglischmacOS 10.15+ | /private/var/folders/<xx>/<id>/0/com.apple.ScreenTimeAgent/Store/ | How much time each app or web domain was used per period, on which device and by which Apple Account | Mac absolute time (seconds since 2001-01-01 UTC); durations in seconds | Owning user or root; extra protection on current macOS, image collection is most reliable | Not documented by Apple; measure from the oldest usage block | mac_apt, APOLLO, sqlite3 |
| Netzwerk | ||||||
| netusage.sqliteEnglischmacOS 10.15+ | /private/var/networkd/db/netusage.sqlite | That a process used the network, when it was first and last seen, how much data it moved per interface type, and which networks the Mac attached to | Mac absolute time (seconds since 2001-01-01 UTC) | root; the networkd folder is protected, collect with Full Disk Access or from an image | Rows persist for long periods; counters are cumulative and records are pruned by networkd on its own schedule | mac_apt, APOLLO, sqlite3 |
| Screen Sharing and Apple Remote Desktop ArtifactsEnglischmacOS 10.15+ | /private/var/db/RemoteManagement/ and ~/Library/Containers/com.apple.ScreenSharing/ | Who connected to this Mac over VNC / Screen Sharing or ARD, from which address and when, and which hosts this Mac's user controlled | Unified Log entries in UTC; plist dates and ARD caches in Mac absolute time | root for /private/var/db/RemoteManagement and the log store; owning user for the Screen Sharing container | Log events follow Unified Log rotation; connection history and ARD caches persist until cleared | log, mac_apt, plutil, macos-UnifiedLogs |
| SSH and Remote Login on macOSEnglischmacOS 10.15+ | ~/.ssh/ and /private/etc/ssh/ | Inbound SSH logons (who, from which IP, with which key or password), outbound SSH targets, and key-based persistence | Unified Log entries in UTC; file system times of authorized_keys, known_hosts and host keys | Owning user for ~/.ssh; root for /private/etc/ssh and the log store | Key files until edited; sshd events follow Unified Log rotation (days to weeks) | log, macos-UnifiedLogs, ssh-keygen, stat, grep |
| Wi-Fi Known Networks on macOSEnglischmacOS 10.15+ | /Library/Preferences/com.apple.wifi.known-networks.plist | Which Wi-Fi networks and access points a Mac joined, when first added, and when last joined by the user or system | Plist date objects (stored as Mac absolute time, shown in UTC); wifi.log in local time | root (known-networks plist is 0600 root:wheel on current macOS) | Known networks until the user forgets them; wifi.log rotated daily, about 10 archives | mac_apt, plutil |
| USB & Geräte | ||||||
| Bluetooth Devices on macOSEnglischmacOS 10.15+ | /Library/Bluetooth/Library/Preferences/com.apple.MobileBluetooth.devices.plist | Which Bluetooth devices were paired with or seen by a Mac, their names and vendors, and when they were last seen | LastSeenTime: Unix epoch seconds; legacy plist dates: plist date objects (UTC) | root (files under /Library/Bluetooth are root-only on current macOS) | Paired devices until removed; LE 'other' cache and logs roll over | mac_apt, APOLLO, plutil, sqlite3 |
| iPhone Backups and Pairing Records on a MacEnglischmacOS 10.15+ | ~/Library/Application Support/MobileSync/Backup/<UDID>/ | Which iPhone or iPad was paired with and backed up to this Mac, when, whether the backup is encrypted, and the full content of the device at backup time | Plist dates in Info.plist and Status.plist; file system times of the backup folder | Owning user for MobileSync (TCC-protected, Full Disk Access needed); root for /private/var/db/lockdown | Backups persist until deleted in Finder; pairing records until the device is untrusted or the OS is reinstalled | iLEAPP, MVT, mac_apt, plutil, sqlite3 |
| USB DevicesEnglischmacOS 10.15+ | /private/var/db/diagnostics/ | Which USB storage devices were attached, when volumes were mounted, and which files were touched on them | Unified Logs UTC instants; FSEvents has no per-record time | root for the log store and .fseventsd; live commands need no special rights | Unified Log rotation (days to weeks); FSEvents until pages are purged | log, macos-UnifiedLogs, mac_apt, FSEventsParser |
| Anti-Forensik | ||||||
| macOS Trash and .DS_StoreEnglischmacOS 10.15+ | ~/.Trash/ and /Volumes/<volume>/.Trashes/<uid>/ | Which files a user moved to the Trash, their original folder and name, and roughly when they were trashed | File system times of the trashed item (ctime changes on the move); .DS_Store modD/moDD in Mac absolute time | Owning user; ~/.Trash is TCC-protected for other apps, so the collector needs Full Disk Access | Until the Trash is emptied, or 30 days if Remove items from the Trash after 30 days is enabled | mac_apt, DSStoreParser, stat |
| Logs | ||||||
| System LogsEnglischmacOS 10.15+ | /private/var/log/ | Install, update, Wi-Fi and legacy syslog activity, often beyond Unified Log retention | Local time; install.log uses ISO-style time with UTC offset, BSD syslog lines have no year | admin group or root (system.log and wifi.log are mode 640, group admin) | Size or daily rotation set in /etc/asl.conf, /etc/asl/ and /etc/newsyslog.d/ | Plaso, mac_apt, syslog, grep |
| Unified LogsmacOS 10.15+ | /private/var/db/diagnostics/ | Was Prozesse und Subsysteme wann gemeldet haben: Anmeldungen, Rechteausweitung, Sicherheitsprüfungen, Geräte | Mach-Zeit, umgerechnet über timesync-Einträge; log show gibt ISO 8601 mit UTC-Offset aus | root (die Gruppe admin kann den Speicher lesen); log collect benötigt sudo | Größenbasierte Rotation, typischerweise einige Tage bis wenige Wochen | log, macos-UnifiedLogs, Plaso, mac_apt |
Speichersicherung unter macOS behandeln diese Seiten nicht; siehe mac-dump: github.com/Cyber-Experts/mac-dump