Zum Inhalt springen

Spickzettel macOS-Artefakte

Alle Artefakte in einer Tabelle, nach Kategorie gruppiert. Im Querformat drucken oder im Browser als PDF speichern.

Die wichtigsten Artefakte sind übersetzt. Einträge mit dem Hinweis „Englisch“ öffnen die englische Seite.

ArtefaktSpeicherortBelegtZeitstempelZugriffAufbewahrungAuswertung
Ausführung
Crash ReportsEnglischmacOS 10.15+/Library/Logs/DiagnosticReports/That a given executable ran on the Mac, from which path, launched by which parent, and when it crashed or hungLocal time with UTC offset in JSON strings and file namesroot, or membership of _analyticsusers (admins are members)Moved to Retired and cleaned up by SubmitDiagInfo; days to weeksjq, mac_apt, Console
Gatekeeper- und XProtect-Spuren unter macOSmacOS 10.15+/var/db/SystemPolicyConfiguration/ExecPolicyOb macOS ein bestimmtes Programm geprüft, zugelassen, blockiert oder bereinigt hat und welche Verhaltensweisen es gemeldet hatUnified Log: Anzeige in der mit jedem Eintrag gespeicherten Zeitzone, sofern --timezone fehlt; XPdb dt: Datum und Uhrzeit als Text; ExecPolicy: Unix-Sekundenroot; Full Disk Access; XPdb ist ab 26.2 ein Data VaultUnified Log: Tage bis Wochen; Datenbanken: bis zum Neuaufbau (variiert)log, mac_apt, sqlite3
InstallHistory.plistEnglischmacOS 10.15+/Library/Receipts/InstallHistory.plistWhich software packages and updates were installed, when, and through which installer processPlist date values (UTC); receipt install-time in Unix epoch secondsReadable by all users; InstallHistory.plist is writable by the admin groupUntil deleted; receipts until pkgutil --forget or removalmac_apt, Plaso, pkgutil, plutil
Mounted Disk Images on macOSEnglischmacOS 10.15+/Volumes/<name>/ (mount point), plus logs and per-user cachesThat a disk image was mounted, under which volume name, which apps were run from it and where it came fromUnified Log entries in UTC; FSEvents event IDs; file system times of the image and translocation foldersroot for logs and /private/var/folders; owning user for DownloadsLog events follow rotation; the image file, quarantine and FSEvents records persist longerhdiutil, log, FSEventsParser, mac_apt, xattr
Shell-Historie unter macOSmacOS 10.15+~/.zsh_historyWelche Befehle ein Benutzer in einer interaktiven Shell eingegeben hat, in welcher Reihenfolge und in welchem Terminal-FensterStandardmäßig keine; Sekunden der Unix-Epoche nur, wenn EXTENDED_HISTORY (zsh) oder HISTTIMEFORMAT (bash) gesetzt istDateibesitzer oder root; einfache Dateien im Home-Ordnerzsh-Standard SAVEHIST=1000 Zeilen; Sitzungsdateien des Terminals werden nach etwa zwei Wochen gelöschtmac_apt, grep, sed
sudo LogsEnglischmacOS 10.15+/private/var/db/diagnostics/Which account ran which command as root (or another user), from which directory and terminal, and failed attemptsUnified Logs: timestamp with UTC offset; ts files: file mtime plus monotonic countersroot to read the log store, /etc/sudoers and /var/db/sudoUnified Log rotation (days to weeks); ts records until reboot or overwritelog, macos-UnifiedLogs, mac_apt, Plaso
TCC.dbmacOS 10.15+/Library/Application Support/com.apple.TCC/TCC.dbWelche Programme sensible Datenschutzberechtigungen angefordert oder erhalten haben, durch wen, und wann sich die Entscheidung zuletzt änderteUnix-Epoche in Sekunden (UTC) in last_modifiedFull Disk Access zum Lesen; die System-Datenbank ist zusätzlich durch SIP geschütztBis die Zeile geändert, zurückgesetzt (tccutil) oder die App entfernt wirdmac_apt, Plaso, Velociraptor, sqlite3
Persistenz
Anmeldeobjekte und BTM-Datenbank unter macOSmacOS 10.15+/private/var/db/com.apple.backgroundtaskmanagement/BackgroundItems-v*.btmWelche Anmeldeobjekte, Agents und Daemons registriert wurden, von welchem Entwickler, und ob sie zugelassen warenNSKeyedArchiver-Datumswerte (Mac Absolute Time, UTC) plus Zeiten des Dateisystemsroot und Full Disk Access (BTM-Speicher); besitzender Benutzer (alte backgrounditems.btm)Bis das Objekt entfernt wird oder sfltool resetbtm den Speicher neu aufbautDumpBTM, bgiparser, Plaso, sfltool
Configuration Profiles and MDMEnglischmacOS 10.15+/private/var/db/ConfigurationProfiles/Which profiles and payloads (certificates, proxies, VPN, TCC/PPPC, system extensions, login items) were installed, by MDM or manually, and whenInstall dates in the profile store (plist dates); Unified Log entries in UTCroot; the profile store is SIP-protected on current releases, read it from an image or with profiles(1) liveProfiles persist until removed; install events follow Unified Log rotationprofiles, log, plutil, macos-UnifiedLogs
cron, at and periodicEnglischmacOS 10.15+/usr/lib/cron/tabs/Whether a command was scheduled to run repeatedly or once through a Unix-style scheduler, by which accountFile system times of tab and job files (APFS, UTC); cron schedules are in local timeroot (tabs directory is mode 700)Until the crontab, job or script is removedcrontab, mac_apt, Aftermath
Kernel and System ExtensionsEnglischmacOS 10.15+/Library/SystemExtensions/db.plist and /private/var/db/SystemPolicyConfiguration/KextPolicyWhich third-party kernel extensions and system extensions were installed, approved, activated or loaded, by which team ID, and whenKextPolicy created_at / last_seen as date-time values (check the storage type per image); Unified Log entries in UTCroot; KextPolicy is SIP-protected, read it from an image or with Full Disk AccessRecords persist until the extension is removed and often after; Unified Log events follow rotationkmutil, systemextensionsctl, sqlite3, plutil, KnockKnock, APOLLO
LaunchAgents und LaunchDaemonsmacOS 10.15+~/Library/LaunchAgents, /Library/LaunchAgents, /Library/LaunchDaemonsWelcher Code automatisch startet, als welcher Benutzer, bei welchem Auslöser und seit wannKeine internen Zeitstempel; APFS-Dateizeiten (Nanosekunden, UTC)Benutzer-Agents: besitzender Benutzer; /Library: root; FDA für das Sicherungstool empfohlenBis die Plist gelöscht wird; Overrides und BTM-Einträge können sie überdauernmac_apt, Plaso, KnockKnock, plutil
Dateizugriff
APFS-Zeitstempel und lokale Snapshots unter macOSmacOS 10.15+/System/Volumes/DataWann Dateien erstellt, geändert und einem Ordner hinzugefügt wurden und wie das Volume Stunden zuvor aussahNanosekunden seit 1970-01-01 UTC (Unix-Epoche)Jeder Benutzer für stat auf eigene Dateien; root plus Full Disk Access zum Einhängen von SnapshotsZeitstempel bis zum Überschreiben; stündliche lokale Snapshots werden etwa 24 Stunden behaltenlibfsapfs, stat, mac_apt
Cloud Storage Clients on MacEnglischmacOS 10.15+~/Library/CloudStorage/ plus each client's Application Support, Group Container and log foldersWhich cloud accounts were linked, which files existed in or passed through the synced folders, and when they were uploaded, downloaded or deletedMixed: Unix epoch (seconds or milliseconds) in most client databases, Mac absolute time in File Provider data, local time in some logsOwning user; some client databases are encrypted or obfuscated and need the user's keychainDatabases track the current sync state; logs rotate by size and age; deleted files may remain in the cloud service's own trashsqlite3, FSEventsParser, plutil, grep
CUPS Print Jobs and LogsEnglischmacOS 10.15+/private/var/spool/cups/ and /private/var/log/cups/Which user printed which job (document name and application), to which printer, when, and how many pages or copiesIPP attributes time-at-creation / processing / completed in Unix epoch seconds; log lines in local time with UTC offsetroot for the spool and logs; printers.conf readable by rootControl files for up to the configured job history (default 500 jobs); data files usually removed after the job; logs rotate by sizemac_apt, lpstat, grep
FSEvents (.fseventsd)macOS 10.15+/System/Volumes/Data/.fseventsd/Welche Pfade auf einem Volume erstellt, geändert, umbenannt oder gelöscht wurden, in EreignisreihenfolgeKeine pro Eintrag; Schätzung über die mtime der Log-Datei und datierte Pfaderoot; auf einem Live-System Full Disk AccessFortlaufend, von fseventsd bereinigt (Monate beobachtet, variiert)FSEventsParser, mac_apt
iCloud Drive (CloudDocs)EnglischmacOS 10.15+~/Library/Application Support/CloudDocs/session/db/client.dbWhich files were in the user's iCloud Drive, when, and from which of their devicesUnix epoch seconds (UTC) in CloudDocs databasesUser or root; Full Disk Access for the collector on a live systemCurrent sync state; items leave when deleted and purged from iCloudmac_apt, sqlite3
Microsoft Office and Outlook for MacEnglischmacOS 10.15+~/Library/Containers/com.microsoft.<App>/ and ~/Library/Group Containers/UBF8T346G9.Office/Which documents were opened in Word, Excel and PowerPoint, from which paths and when, the Office user identity, and the local copy of Outlook mailPlist dates (kLastUsedDateKey); Windows FILETIME in MicrosoftRegistrationDB.reg; Outlook database dates per schemaOwning user; Group Containers and Containers need Full Disk Access to collect on current releasesMRU lists hold a limited number of entries; Outlook caches follow account sync settingsmac_apt, plutil, sqlite3
Photos.sqliteEnglischmacOS 10.15+~/Pictures/Photos Library.photoslibrary/database/Photos.sqliteWhen media was captured, added, edited, hidden or trashed, where it was taken and which app or device imported itMac absolute time (seconds since 2001-01-01 UTC); time zone offset per assetTCC-protected library: Full Disk Access (or Photos access) for the collectorUntil deleted; Recently Deleted items are purged after 30 daysosxphotos, exiftool, sqlite3
QuarantineEventsV2 und Quarantäne-xattr unter macOSmacOS 10.15+~/Library/Preferences/com.apple.LaunchServices.QuarantineEventsV2Welche Dateien ein Benutzer heruntergeladen hat, von welcher URL und Ursprungsseite, mit welcher App und wannDatenbank: Mac Absolute Time (UTC); xattr: Unix-Sekunden in Hex (UTC)Besitzender Benutzer oder root; Full Disk Access für das Sicherungstool empfohlenBis zur Löschung oder Bereinigung (keine dokumentierte automatische Löschung)mac_apt, Plaso, Velociraptor, sqlite3
QuickLook Thumbnail CacheEnglischmacOS 10.15+$(getconf DARWIN_USER_CACHE_DIR)/com.apple.quicklook.ThumbnailsAgent/com.apple.QuickLook.thumbnailcache/That a file existed at a path and was displayed as a thumbnail or preview, with a cached image that can outlive the originallast_hit_date in Mac absolute time; file modification time stored in the version blobOwning user or root; the cache sits under /private/var/folders, collect as rootCache is pruned by size and age and rebuilt with qlmanage -r cache; not a long-term recordmac_apt, sqlite3, plutil
Recent Items (.sfl2/.sfl3)EnglischmacOS 10.15+~/Library/Application Support/com.apple.sharedfilelist/Which documents, apps and servers a user recently opened, with full paths and source volumesMostly none per item; bookmark dates in Mac absolute time (2001 epoch)User-owned; Full Disk Access for the collector on a live systemRolling lists capped by the Recent Items count (default 10)mac_apt, plutil
Spotlight Store (.Spotlight-V100)EnglischmacOS 10.15+/System/Volumes/Data/.Spotlight-V100/Store-V2/<UUID>/store.dbWhere a file came from, when it was added and opened, and that it existed even after deletionMac absolute time (seconds since 2001-01-01 UTC); mdls shows UTCroot; Full Disk Access on a live systemUntil the indexer updates or purges the entry, or the index is rebuiltspotlight_parser, mac_apt
Time Machine BackupsEnglischmacOS 10.15+/Library/Preferences/com.apple.TimeMachine.plistWhich backup destinations were used, when backups ran, and what files looked like at each backupBackup names YYYY-MM-DD-HHMMSS; plist dates as plist date objectsroot plus Full Disk Access for tmutil listbackups and backup contentsHourly 24 h, daily for a month, weekly after; oldest deleted when fulltmutil, Plaso, plutil
Benutzeraktivität
Apple MailEnglischmacOS 10.15+~/Library/Mail/V10/MailData/Envelope IndexWhich emails were sent or received, from and to whom, when, in which mailbox, and which attachments were openedEnvelope Index dates in Unix epoch seconds (UTC); message headers in RFC 5322 local timeTCC-protected (Mail data): Full Disk Access for the collectorUntil deleted or removed from the server; local copies follow account sync settingssqlite3, emlx (Python)
Apple Notes NoteStore.sqliteEnglischmacOS 10.15+~/Library/Group Containers/group.com.apple.notes/NoteStore.sqliteWhat a user wrote in Notes, when each note was created and last modified, attachments, folders, iCloud or local account, and deleted notes still in the databaseMac absolute time (seconds since 2001-01-01 UTC)Owning user; the group container is TCC-protected, so the collector needs Full Disk AccessUntil deleted; Recently Deleted keeps notes for about 30 days, and freed pages may survive in the WAL or free listapple_cloud_notes_parser, mac_apt, sqlite3
Biome-SEGB-StreamsmacOS 12+~/Library/Biome/streams/restricted/<Stream>/local/Welche Apps im Fokus waren, besuchte Websites, verbundene Geräte und Netzwerke, mit Zeiten pro EintragMac Absolute Time (Cocoa) als Double in SEGB-Einträgen; Dateinamen sind Cocoa-Zeit in MikrosekundenFull Disk Access (Benutzer-Streams); System-Streams sind durch SIP eingeschränktWochen für die meisten Streams (etwa 28 Tage, ein Wert aus iOS-Untersuchungen); abgelaufene Dateien wandern nach tombstonemac_apt, ccl-segb
Calendar, Contacts and Reminders Databases on macOSEnglischmacOS 10.15+~/Library/Application Support/AddressBook/, ~/Library/Group Containers/group.com.apple.reminders/, ~/Library/Calendars/ or group.com.apple.calendarWho the user knew and how to reach them, which meetings and appointments existed, where and with whom, and which tasks were created or completedMac absolute time (seconds since 2001-01-01 UTC) in all three Core Data storesOwning user; each store is TCC-protected (Contacts, Calendars, Reminders), so the collector needs Full Disk AccessUntil deleted locally or through sync; deleted items may persist briefly for sync and in WAL filessqlite3, APOLLO, plutil
Chrome and Firefox History on macOSEnglischmacOS 10.15+~/Library/Application Support/Google/Chrome/Default/HistoryWhich sites a user opened in Chrome, Chromium browsers or Firefox, when, and what they downloadedChrome: microseconds since 1601-01-01 UTC; Firefox PRTime: microseconds since 1970-01-01 UTCFile owner or root; give the collector Full Disk Access as wellChrome: about 90 days of visits; Firefox: size-based expiration of old pagesHindsight, mac_apt, sqlite3
Dock and Finder PlistsEnglischmacOS 10.15+~/Library/Preferences/com.apple.finder.plistWhich apps a user kept or recently ran in the Dock, and which folders, paths and servers they visited in FinderFew per key; Dock tile dates in HFS+ seconds (1904 epoch)User-owned; Full Disk Access for the collector on a live systemUntil the preference changes or the user resets itmac_apt, plutil
dslocal User AccountsEnglischmacOS 10.15+/private/var/db/dslocal/nodes/Default/users/<name>.plistWhich local accounts exist, when they were created, who is admin, and recent password and failed-login activityaccountPolicyData: Unix epoch seconds (UTC)root; Full Disk Access recommended for the collectorUntil the account is deleted; home may survive in /Users/Deleted Usersmac_apt, Velociraptor, plutil, dscl
knowledgeC.dbmacOS 10.15+/private/var/db/CoreDuet/Knowledge/knowledgeC.dbWelche Apps wann und wie lange genutzt wurden und ob das Display zu dem Zeitpunkt an warMac Absolute Time (Sekunden seit 2001-01-01 UTC) plus Offset in ZSECONDSFROMGMTroot plus SIP-Einschränkungen (System-DB); Full Disk Access (Benutzer-DB)Auf typischen Systemen etwa vier Wochen an Ereignissen (je nach Stream unterschiedlich)APOLLO, Plaso, sqlite3
macOS Keychain FilesEnglischmacOS 10.15+~/Library/Keychains/Which accounts, services, networks and certificates a user had saved, and when items were created or modifiedFile keychain: UTC strings YYYYMMDDhhmmssZ; keychain-2.db: Mac absolute timeOwning user or root; secrets need user credentials and, for data protection items, the original deviceUntil the item or keychain is deletedsecurity, sqlite3
Messages chat.dbEnglischmacOS 10.15+~/Library/Messages/chat.dbWho communicated with whom, what was said, when it was sent, delivered and read, and which files were exchangedNanoseconds since 2001-01-01 UTC (High Sierra+); older rows in secondsTCC-protected (Messages data): Full Disk Access for the collectorUntil deleted; Recently Deleted keeps items up to 30 days (Ventura+)imessage-exporter, mac_apt, Plaso, sqlite3
Notification Center DatabaseEnglischmacOS 10.15+~/Library/Group Containers/group.com.apple.usernoted/db2/dbWhich app showed which notification text to the user, and when it was deliveredMac absolute time (seconds since 2001-01-01 UTC)Sequoia+: TCC-protected group container (Full Disk Access); older: owning userNot documented by Apple; varies, measure from oldest delivered_datemac_apt, Plaso, sqlite3
Safari History.dbmacOS 10.15+~/Library/Safari/History.dbWelche URLs ein macOS-Benutzer in Safari geöffnet hat, wann, über welche Weiterleitungen und ob der Verlauf gelöscht wurdeMac Absolute Time (Cocoa, Sekunden seit 2001-01-01 UTC), gespeichert als REALFull Disk Access für den lesenden Prozess (TCC); root allein reicht nichtBenutzereinstellung, standardmäßig ein Jahr oder bis zum manuellen Löschen; Download-Liste standardmäßig ein Tagmac_apt, APOLLO, sqlite3, plutil
Saved Application StateEnglischmacOS 10.15+~/Library/Saved Application State/<bundle-id>.savedState/Which apps were open with which windows, document titles and dock menu entries, and for Terminal, the text visible in each windowFile system times of windows.plist and data.data (last state save)Owning user; readable from an image or with Full Disk AccessRewritten while the app runs; kept after quit when Close windows when quitting an app is off; deleted on clean quit otherwisemac_apt, plutil
Screen Time DatabasesEnglischmacOS 10.15+/private/var/folders/<xx>/<id>/0/com.apple.ScreenTimeAgent/Store/How much time each app or web domain was used per period, on which device and by which Apple AccountMac absolute time (seconds since 2001-01-01 UTC); durations in secondsOwning user or root; extra protection on current macOS, image collection is most reliableNot documented by Apple; measure from the oldest usage blockmac_apt, APOLLO, sqlite3
Netzwerk
netusage.sqliteEnglischmacOS 10.15+/private/var/networkd/db/netusage.sqliteThat a process used the network, when it was first and last seen, how much data it moved per interface type, and which networks the Mac attached toMac absolute time (seconds since 2001-01-01 UTC)root; the networkd folder is protected, collect with Full Disk Access or from an imageRows persist for long periods; counters are cumulative and records are pruned by networkd on its own schedulemac_apt, APOLLO, sqlite3
Screen Sharing and Apple Remote Desktop ArtifactsEnglischmacOS 10.15+/private/var/db/RemoteManagement/ and ~/Library/Containers/com.apple.ScreenSharing/Who connected to this Mac over VNC / Screen Sharing or ARD, from which address and when, and which hosts this Mac's user controlledUnified Log entries in UTC; plist dates and ARD caches in Mac absolute timeroot for /private/var/db/RemoteManagement and the log store; owning user for the Screen Sharing containerLog events follow Unified Log rotation; connection history and ARD caches persist until clearedlog, mac_apt, plutil, macos-UnifiedLogs
SSH and Remote Login on macOSEnglischmacOS 10.15+~/.ssh/ and /private/etc/ssh/Inbound SSH logons (who, from which IP, with which key or password), outbound SSH targets, and key-based persistenceUnified Log entries in UTC; file system times of authorized_keys, known_hosts and host keysOwning user for ~/.ssh; root for /private/etc/ssh and the log storeKey files until edited; sshd events follow Unified Log rotation (days to weeks)log, macos-UnifiedLogs, ssh-keygen, stat, grep
Wi-Fi Known Networks on macOSEnglischmacOS 10.15+/Library/Preferences/com.apple.wifi.known-networks.plistWhich Wi-Fi networks and access points a Mac joined, when first added, and when last joined by the user or systemPlist date objects (stored as Mac absolute time, shown in UTC); wifi.log in local timeroot (known-networks plist is 0600 root:wheel on current macOS)Known networks until the user forgets them; wifi.log rotated daily, about 10 archivesmac_apt, plutil
USB & Geräte
Bluetooth Devices on macOSEnglischmacOS 10.15+/Library/Bluetooth/Library/Preferences/com.apple.MobileBluetooth.devices.plistWhich Bluetooth devices were paired with or seen by a Mac, their names and vendors, and when they were last seenLastSeenTime: Unix epoch seconds; legacy plist dates: plist date objects (UTC)root (files under /Library/Bluetooth are root-only on current macOS)Paired devices until removed; LE 'other' cache and logs roll overmac_apt, APOLLO, plutil, sqlite3
iPhone Backups and Pairing Records on a MacEnglischmacOS 10.15+~/Library/Application Support/MobileSync/Backup/<UDID>/Which iPhone or iPad was paired with and backed up to this Mac, when, whether the backup is encrypted, and the full content of the device at backup timePlist dates in Info.plist and Status.plist; file system times of the backup folderOwning user for MobileSync (TCC-protected, Full Disk Access needed); root for /private/var/db/lockdownBackups persist until deleted in Finder; pairing records until the device is untrusted or the OS is reinstallediLEAPP, MVT, mac_apt, plutil, sqlite3
USB DevicesEnglischmacOS 10.15+/private/var/db/diagnostics/Which USB storage devices were attached, when volumes were mounted, and which files were touched on themUnified Logs UTC instants; FSEvents has no per-record timeroot for the log store and .fseventsd; live commands need no special rightsUnified Log rotation (days to weeks); FSEvents until pages are purgedlog, macos-UnifiedLogs, mac_apt, FSEventsParser
Anti-Forensik
macOS Trash and .DS_StoreEnglischmacOS 10.15+~/.Trash/ and /Volumes/<volume>/.Trashes/<uid>/Which files a user moved to the Trash, their original folder and name, and roughly when they were trashedFile system times of the trashed item (ctime changes on the move); .DS_Store modD/moDD in Mac absolute timeOwning user; ~/.Trash is TCC-protected for other apps, so the collector needs Full Disk AccessUntil the Trash is emptied, or 30 days if Remove items from the Trash after 30 days is enabledmac_apt, DSStoreParser, stat
Logs
System LogsEnglischmacOS 10.15+/private/var/log/Install, update, Wi-Fi and legacy syslog activity, often beyond Unified Log retentionLocal time; install.log uses ISO-style time with UTC offset, BSD syslog lines have no yearadmin group or root (system.log and wifi.log are mode 640, group admin)Size or daily rotation set in /etc/asl.conf, /etc/asl/ and /etc/newsyslog.d/Plaso, mac_apt, syslog, grep
Unified LogsmacOS 10.15+/private/var/db/diagnostics/Was Prozesse und Subsysteme wann gemeldet haben: Anmeldungen, Rechteausweitung, Sicherheitsprüfungen, GeräteMach-Zeit, umgerechnet über timesync-Einträge; log show gibt ISO 8601 mit UTC-Offset ausroot (die Gruppe admin kann den Speicher lesen); log collect benötigt sudoGrößenbasierte Rotation, typischerweise einige Tage bis wenige Wochenlog, macos-UnifiedLogs, Plaso, mac_apt

Speichersicherung unter macOS behandeln diese Seiten nicht; siehe mac-dump: github.com/Cyber-Experts/mac-dump