Skip to content

macOS forensic artifacts

One page per artifact: where it lives on each macOS version, what it proves, how its timestamps work, how long it survives, and how to collect and parse it with open-source tools.

macOS version

Execution

Persistence

  • Configuration Profiles and MDM: macOS Managed Settings

    macOS configuration profiles and MDM enrollment records show which policies, certificates, VPNs, TCC grants and extensions were pushed to a Mac, and when.

    /private/var/db/ConfigurationProfiles/

  • cron, at and periodic: macOS Scheduled Job Persistence

    Legacy macOS schedulers (cron tabs, at jobs, periodic scripts, emond rules): where they live, which versions still run them and how to spot abuse.

    /usr/lib/cron/tabs/

  • Kernel and System Extensions: macOS kext Evidence

    Kernel extensions and system extensions on macOS: KextPolicy load history, the SystemExtensions database and what they show about drivers, EDR and rootkits.

    /Library/SystemExtensions/db.plist and /private/var/db/SystemPolicyConfiguration/KextPolicy

  • LaunchAgents and LaunchDaemons: macOS Persistence

    launchd property lists in LaunchAgents and LaunchDaemons folders define what macOS starts at boot, at login or on a schedule, and are the top persistence spot.

    ~/Library/LaunchAgents, /Library/LaunchAgents, /Library/LaunchDaemons

  • Login Items and BTM Database on macOS

    Login Items and the Ventura+ Background Task Management store list login items, agents and daemons, with developer, team ID and approval state.

    /private/var/db/com.apple.backgroundtaskmanagement/BackgroundItems-v*.btm

File access

User activity

  • Apple Mail: Envelope Index and EMLX on macOS

    Apple Mail keeps message metadata in the Envelope Index SQLite database and each message as an .emlx file, showing email sent, received and opened.

    ~/Library/Mail/V10/MailData/Envelope Index

  • Apple Notes NoteStore.sqlite: macOS Notes Forensics

    NoteStore.sqlite holds Apple Notes on macOS: note text as compressed protobuf, folders, accounts, attachments, locked notes and Recently Deleted items.

    ~/Library/Group Containers/group.com.apple.notes/NoteStore.sqlite

  • Biome SEGB Streams: macOS App Focus and Activity

    Biome stores macOS activity streams such as App.InFocus in SEGB files of protobuf records, the successor to many knowledgeC.db streams.

    ~/Library/Biome/streams/restricted/<Stream>/local/

  • Calendar, Contacts and Reminders Databases on macOS

    Where macOS stores Calendar events, Contacts (AddressBook .abcddb) and Reminders, and what they show about meetings, relationships and tasks.

    ~/Library/Application Support/AddressBook/, ~/Library/Group Containers/group.com.apple.reminders/, ~/Library/Calendars/ or group.com.apple.calendar

  • Chrome and Firefox History on macOS

    Chrome History and Firefox places.sqlite on macOS: paths, profiles, key tables and epochs to rebuild visits and downloads outside Safari.

    ~/Library/Application Support/Google/Chrome/Default/History

  • Dock and Finder Plists: macOS User Preference Evidence

    com.apple.dock.plist and com.apple.finder.plist record pinned and recent apps, recent folders, Go to Folder history, servers and searches.

    ~/Library/Preferences/com.apple.finder.plist

  • dslocal User Accounts: macOS Local Users and Groups

    dslocal plists define every local macOS account and group, with creation, password-change and failed-login times that expose rogue or hidden accounts.

    /private/var/db/dslocal/nodes/Default/users/<name>.plist

  • knowledgeC.db: macOS App Usage and Device Activity

    CoreDuet SQLite database recording app usage, focus, display and power state on macOS, used to show when and how long apps were in use.

    /private/var/db/CoreDuet/Knowledge/knowledgeC.db

  • macOS Keychain Files: Metadata for Forensics

    macOS keychains store credentials, keys and certificates; their metadata shows which accounts, services and certificates existed and when items changed.

    ~/Library/Keychains/

  • Messages chat.db: macOS iMessage and SMS History

    chat.db is the macOS Messages SQLite database of iMessage, SMS and RCS conversations, participants, attachments and recently deleted messages.

    ~/Library/Messages/chat.db

  • Notification Center Database: macOS Notification History

    The usernoted SQLite database keeps delivered macOS notifications with app, title, body and time, often preserving message text from other apps.

    ~/Library/Group Containers/group.com.apple.usernoted/db2/db

  • Safari History.db: macOS Browsing History

    Safari History.db, profile databases, Downloads.plist and tab stores on macOS: which pages a user visited, when, and what was deleted.

    ~/Library/Safari/History.db

  • Saved Application State: macOS Window and Terminal History

    macOS Saved Application State (.savedState) restores windows at relaunch and keeps window titles, open documents and even Terminal scrollback text.

    ~/Library/Saved Application State/<bundle-id>.savedState/

  • Screen Time Databases: macOS App Usage Totals

    ScreenTimeAgent RMAdminStore databases on macOS hold per-app and per-domain usage totals, pickups and notification counts per device and user.

    /private/var/folders/<xx>/<id>/0/com.apple.ScreenTimeAgent/Store/

Network

  • netusage.sqlite: macOS Per-Process Network Usage

    netusage.sqlite records which processes used the network on a Mac, with first and last seen times and bytes over Wi-Fi, wired and cellular links.

    /private/var/networkd/db/netusage.sqlite

  • Screen Sharing and Apple Remote Desktop Artifacts

    macOS Screen Sharing and Apple Remote Desktop leave connection history, screensharingd log events and ARD caches that show remote control of a Mac.

    /private/var/db/RemoteManagement/ and ~/Library/Containers/com.apple.ScreenSharing/

  • SSH and Remote Login on macOS: Keys, Hosts and Logs

    macOS Remote Login (sshd) leaves authorized_keys, known_hosts, sshd configuration and Unified Log events that show inbound and outbound SSH activity.

    ~/.ssh/ and /private/etc/ssh/

  • Wi-Fi Known Networks on macOS: Plists and Logs

    macOS known Wi-Fi networks in com.apple.wifi.known-networks.plist, airport preferences, wifi.log and Unified Logs: where a Mac has connected, and when.

    /Library/Preferences/com.apple.wifi.known-networks.plist

USB & devices

  • Bluetooth Devices on macOS: Paired and Seen

    macOS Bluetooth artifacts: com.apple.Bluetooth.plist, MobileBluetooth device plist and LE databases, and bluetoothd logs to show which devices paired and when.

    /Library/Bluetooth/Library/Preferences/com.apple.MobileBluetooth.devices.plist

  • iPhone Backups and Pairing Records on a Mac

    Finder (MobileSync) backups of iPhones and iPads on a Mac, plus lockdown pairing records, show which iOS devices were connected, trusted and backed up.

    ~/Library/Application Support/MobileSync/Backup/<UDID>/

  • USB Devices: macOS Removable Media History

    macOS keeps no USB registry: rebuild removable media history from Unified Logs, DiskArbitration mounts, FSEvents, Spotlight and the device itself.

    /private/var/db/diagnostics/

Anti-forensics

  • macOS Trash and .DS_Store: Deleted File Evidence

    The macOS Trash keeps deleted files with their original location in .DS_Store put-back records, showing what a user deleted, from where and when.

    ~/.Trash/ and /Volumes/<volume>/.Trashes/<uid>/

Logs