Skip to content

USB & devicesUser activity

Bluetooth Devices on macOS: Paired and Seen

macOS Bluetooth artifacts: com.apple.Bluetooth.plist, MobileBluetooth device plist and LE databases, and bluetoothd logs to show which devices paired and when.

Location
/Library/Bluetooth/Library/Preferences/com.apple.MobileBluetooth.devices.plist
Proves
Which Bluetooth devices were paired with or seen by a Mac, their names and vendors, and when they were last seen
Timestamps
LastSeenTime: Unix epoch seconds; legacy plist dates: plist date objects (UTC)
Access
root (files under /Library/Bluetooth are root-only on current macOS)
Retention
Paired devices until removed; LE 'other' cache and logs roll over
Collection
mac_apt, UAC, log collect

What it is

Bluetooth evidence on a Mac shows which keyboards, mice, headphones, phones, watches and other peripherals were paired with or connected to the machine. That matters for attribution (whose AirPods or iPhone were near the Mac), for data-exfiltration questions (a phone paired during the incident window) and for establishing presence.

Storage changed over time. Older macOS kept a device cache in /Library/Preferences/com.apple.Bluetooth.plist. Current macOS uses the same "MobileBluetooth" files as iOS under /Library/Bluetooth: a property list of classic Bluetooth devices and two SQLite databases for Bluetooth Low Energy (LE) devices. Community reports place the disappearance of the DeviceCache key at macOS 12 Monterey; on macOS 26 the preferences file only holds Bluetooth settings.

Where it lives

FilePathVersions / protection
Legacy device cache/Library/Preferences/com.apple.Bluetooth.plist (DeviceCache, PairedDevices)Up to about macOS 11; later releases keep only settings here
Device list/Library/Bluetooth/Library/Preferences/com.apple.MobileBluetooth.devices.plistCurrent macOS; mode 0600 root:wheel (observed on macOS 26)
Paired LE devices/Library/Bluetooth/com.apple.MobileBluetooth.ledevices.paired.db (+ -wal, -shm)Current macOS; 0640 root:wheel
Other LE devices seen/Library/Bluetooth/com.apple.MobileBluetooth.ledevices.other.db (+ -wal, -shm)Current macOS; 0640 root:wheel
Unified Logs/private/var/db/diagnosticsProcess bluetoothd, subsystem com.apple.bluetooth
KnowledgeCknowledgeC.db (see KnowledgeC)/bluetooth/isConnected stream on versions that populate it

The files sit on the Data volume, outside TCC protection but readable only by root. On a mounted image, ownership does not stop you; on a live system use sudo and a collector with Full Disk Access.

What it proves

  • That a device with a given Bluetooth address and name was paired with, or cached by, the Mac.
  • The device's user-visible name, default name, vendor and product IDs and class of device (headset, phone, keyboard and so on).
  • When the device was last seen (LastSeenTime), and on legacy systems when its name and services were last updated.
  • From logs and KnowledgeC: individual connect and disconnect events with times.
  • From the LE "other" database: that nearby LE devices were observed, which can place other people's devices near the Mac.

It does not prove:

  • That data was transferred: pairing and connection are not file transfer (look at AirDrop and file system artifacts for that).
  • Ownership of the device: a name like "Anna's iPhone" is user-editable.
  • A full history: the plists hold the latest state, not every connection.

Key fields

com.apple.MobileBluetooth.devices.plist (one dictionary per device, keyed by Bluetooth address):

KeyMeaning
DefaultNameName the device advertised
NameName as stored/displayed
UserNameKeyUser-assigned name, where set
DeviceIdVendor, DeviceIdProductVendor and product identifiers
DeviceClassClass of device (4-byte little-endian value)
LastSeenTimeLast time the device was seen, Unix epoch seconds

Legacy com.apple.Bluetooth.plist:

KeyMeaning
PairedDevicesArray of paired device addresses
DeviceCacheDictionary keyed by address: Name, displayName, UserNameKey, Manufacturer, BatteryPercent, VendorID, ProductID, ClassOfDevice, Services, SupportedFeatures, LastNameUpdate, LastServicesUpdate

The LE databases hold device records with names, addresses and last-seen data (on iOS the tables are PairedDevices and OtherDevices). Run .tables and .schema on the macOS copy before querying, since column names are not publicly documented by Apple.

Timestamps

  • LastSeenTime is a Unix epoch value in seconds; mac_apt converts it as Unix time. Research on the iOS version of this plist found the value can reflect local wall-clock time rather than strict UTC, so validate against a log entry for the same device before relying on the offset.
  • Legacy plist dates (LastNameUpdate, LastServicesUpdate) are plist date objects stored as Mac absolute time; plutil -p shows them in UTC.
  • Unified Log times print in the examiner's local time unless --timezone is used.
date -u -r 1790000000        # convert a LastSeenTime value

Retention

  • Paired devices persist until the user removes them ("Forget This Device") or Bluetooth settings are reset.
  • The LE "other" database is a cache of nearby devices and churns with normal use; recent changes may sit only in its -wal file.
  • Unified Log bluetoothd messages are high-volume, so they roll out faster than most subsystems; collect early.

Collection

sudo ditto /Library/Bluetooth /cases/host01/Bluetooth          # plist + LE databases with WAL files
sudo ditto /Library/Preferences/com.apple.Bluetooth.plist /cases/host01/Bluetooth/ 2>/dev/null
sudo log collect --output /cases/host01/system_logs.logarchive
system_profiler SPBluetoothDataType > /cases/host01/bt_live.txt  # live: controller, connected and not-connected devices
  • mac_apt: the BLUETOOTH plugin reads both com.apple.Bluetooth.plist and com.apple.MobileBluetooth.devices.plist.
  • UAC: its bluetooth.yaml artifact collects /Library/Bluetooth/com.apple.MobileBluetooth.ledevices.*; add the device plist under /Library/Bluetooth/Library/Preferences yourself if your profile does not include it.
  • log collect or sysdiagnose for the bluetoothd log history.

Parsing

  • mac_apt BLUETOOTH plugin: merges the legacy cache and the MobileBluetooth plist, decodes class of device, and maps Bluetooth company identifiers to manufacturer names.
  • sudo plutil -p com.apple.MobileBluetooth.devices.plist for a quick look.
  • sqlite3 on copies of the LE databases (keep -wal and -shm beside them).
  • APOLLO: the knowledge_audio_bluetooth_connected module extracts /bluetooth/isConnected events from knowledgeC.db on supported versions.
  • Unified Logs:
log show system_logs.logarchive --style syslog \
  --predicate 'process == "bluetoothd" AND subsystem == "com.apple.bluetooth"' \
  --start '2026-09-01 08:00:00' --end '2026-09-01 12:00:00' | grep -iE 'connect|pair'

Unified Log Parser opens a .logarchive, the diagnostics and uuidtext folders or a log show export in the browser, applies DFIR triage rules and exports CSV or Timesketch; nothing is uploaded.

Investigator tips

  • Bluetooth addresses of Apple devices often rotate for LE privacy, so the same phone can appear under several addresses in the "other" database. Rely on paired entries and names for identity.
  • Match LastSeenTime and log connect events with KnowledgeC and Wi-Fi joins to build a presence timeline.
  • A phone or unknown keyboard paired shortly before suspicious activity deserves attention: consider HID injection or remote control scenarios alongside exfiltration.
  • For removable storage and wired peripherals use USB devices; Bluetooth files do not cover them.
  • An empty /Library/Bluetooth on a Mac known to use AirPods or a Magic Keyboard suggests a Bluetooth reset or deliberate cleanup; check local snapshots and the logs.

See also