Bluetooth Devices on macOS: Paired and Seen
macOS Bluetooth artifacts: com.apple.Bluetooth.plist, MobileBluetooth device plist and LE databases, and bluetoothd logs to show which devices paired and when.
- Location
- /Library/Bluetooth/Library/Preferences/com.apple.MobileBluetooth.devices.plist
- Proves
- Which Bluetooth devices were paired with or seen by a Mac, their names and vendors, and when they were last seen
- Timestamps
- LastSeenTime: Unix epoch seconds; legacy plist dates: plist date objects (UTC)
- Access
- root (files under /Library/Bluetooth are root-only on current macOS)
- Retention
- Paired devices until removed; LE 'other' cache and logs roll over
- Collection
- mac_apt, UAC, log collect
Tools
Compare all tools- mac_aptCLI · open source
- APOLLOCLI · open source
- plutilCLI · built into macOS
- sqlite3CLI · built into macOS
What it is
Bluetooth evidence on a Mac shows which keyboards, mice, headphones, phones, watches and other peripherals were paired with or connected to the machine. That matters for attribution (whose AirPods or iPhone were near the Mac), for data-exfiltration questions (a phone paired during the incident window) and for establishing presence.
Storage changed over time. Older macOS kept a device cache in /Library/Preferences/com.apple.Bluetooth.plist. Current macOS uses the same "MobileBluetooth" files as iOS under /Library/Bluetooth: a property list of classic Bluetooth devices and two SQLite databases for Bluetooth Low Energy (LE) devices. Community reports place the disappearance of the DeviceCache key at macOS 12 Monterey; on macOS 26 the preferences file only holds Bluetooth settings.
Where it lives
| File | Path | Versions / protection |
|---|---|---|
| Legacy device cache | /Library/Preferences/com.apple.Bluetooth.plist (DeviceCache, PairedDevices) | Up to about macOS 11; later releases keep only settings here |
| Device list | /Library/Bluetooth/Library/Preferences/com.apple.MobileBluetooth.devices.plist | Current macOS; mode 0600 root:wheel (observed on macOS 26) |
| Paired LE devices | /Library/Bluetooth/com.apple.MobileBluetooth.ledevices.paired.db (+ -wal, -shm) | Current macOS; 0640 root:wheel |
| Other LE devices seen | /Library/Bluetooth/com.apple.MobileBluetooth.ledevices.other.db (+ -wal, -shm) | Current macOS; 0640 root:wheel |
| Unified Logs | /private/var/db/diagnostics | Process bluetoothd, subsystem com.apple.bluetooth |
| KnowledgeC | knowledgeC.db (see KnowledgeC) | /bluetooth/isConnected stream on versions that populate it |
The files sit on the Data volume, outside TCC protection but readable only by root. On a mounted image, ownership does not stop you; on a live system use sudo and a collector with Full Disk Access.
What it proves
- That a device with a given Bluetooth address and name was paired with, or cached by, the Mac.
- The device's user-visible name, default name, vendor and product IDs and class of device (headset, phone, keyboard and so on).
- When the device was last seen (
LastSeenTime), and on legacy systems when its name and services were last updated. - From logs and KnowledgeC: individual connect and disconnect events with times.
- From the LE "other" database: that nearby LE devices were observed, which can place other people's devices near the Mac.
It does not prove:
- That data was transferred: pairing and connection are not file transfer (look at AirDrop and file system artifacts for that).
- Ownership of the device: a name like "Anna's iPhone" is user-editable.
- A full history: the plists hold the latest state, not every connection.
Key fields
com.apple.MobileBluetooth.devices.plist (one dictionary per device, keyed by Bluetooth address):
| Key | Meaning |
|---|---|
DefaultName | Name the device advertised |
Name | Name as stored/displayed |
UserNameKey | User-assigned name, where set |
DeviceIdVendor, DeviceIdProduct | Vendor and product identifiers |
DeviceClass | Class of device (4-byte little-endian value) |
LastSeenTime | Last time the device was seen, Unix epoch seconds |
Legacy com.apple.Bluetooth.plist:
| Key | Meaning |
|---|---|
PairedDevices | Array of paired device addresses |
DeviceCache | Dictionary keyed by address: Name, displayName, UserNameKey, Manufacturer, BatteryPercent, VendorID, ProductID, ClassOfDevice, Services, SupportedFeatures, LastNameUpdate, LastServicesUpdate |
The LE databases hold device records with names, addresses and last-seen data (on iOS the tables are PairedDevices and OtherDevices). Run .tables and .schema on the macOS copy before querying, since column names are not publicly documented by Apple.
Timestamps
LastSeenTimeis a Unix epoch value in seconds; mac_apt converts it as Unix time. Research on the iOS version of this plist found the value can reflect local wall-clock time rather than strict UTC, so validate against a log entry for the same device before relying on the offset.- Legacy plist dates (
LastNameUpdate,LastServicesUpdate) are plist date objects stored as Mac absolute time;plutil -pshows them in UTC. - Unified Log times print in the examiner's local time unless
--timezoneis used.
date -u -r 1790000000 # convert a LastSeenTime value
Retention
- Paired devices persist until the user removes them ("Forget This Device") or Bluetooth settings are reset.
- The LE "other" database is a cache of nearby devices and churns with normal use; recent changes may sit only in its
-walfile. - Unified Log
bluetoothdmessages are high-volume, so they roll out faster than most subsystems; collect early.
Collection
sudo ditto /Library/Bluetooth /cases/host01/Bluetooth # plist + LE databases with WAL files
sudo ditto /Library/Preferences/com.apple.Bluetooth.plist /cases/host01/Bluetooth/ 2>/dev/null
sudo log collect --output /cases/host01/system_logs.logarchive
system_profiler SPBluetoothDataType > /cases/host01/bt_live.txt # live: controller, connected and not-connected devices
- mac_apt: the
BLUETOOTHplugin reads bothcom.apple.Bluetooth.plistandcom.apple.MobileBluetooth.devices.plist. - UAC: its
bluetooth.yamlartifact collects/Library/Bluetooth/com.apple.MobileBluetooth.ledevices.*; add the device plist under/Library/Bluetooth/Library/Preferencesyourself if your profile does not include it. log collector sysdiagnose for thebluetoothdlog history.
Parsing
- mac_apt
BLUETOOTHplugin: merges the legacy cache and the MobileBluetooth plist, decodes class of device, and maps Bluetooth company identifiers to manufacturer names. sudo plutil -p com.apple.MobileBluetooth.devices.plistfor a quick look.sqlite3on copies of the LE databases (keep-waland-shmbeside them).- APOLLO: the
knowledge_audio_bluetooth_connectedmodule extracts/bluetooth/isConnectedevents from knowledgeC.db on supported versions. - Unified Logs:
log show system_logs.logarchive --style syslog \
--predicate 'process == "bluetoothd" AND subsystem == "com.apple.bluetooth"' \
--start '2026-09-01 08:00:00' --end '2026-09-01 12:00:00' | grep -iE 'connect|pair'
Unified Log Parser opens a .logarchive, the diagnostics and uuidtext folders or a log show export in the browser, applies DFIR triage rules and exports CSV or Timesketch; nothing is uploaded.
Investigator tips
- Bluetooth addresses of Apple devices often rotate for LE privacy, so the same phone can appear under several addresses in the "other" database. Rely on paired entries and names for identity.
- Match
LastSeenTimeand log connect events with KnowledgeC and Wi-Fi joins to build a presence timeline. - A phone or unknown keyboard paired shortly before suspicious activity deserves attention: consider HID injection or remote control scenarios alongside exfiltration.
- For removable storage and wired peripherals use USB devices; Bluetooth files do not cover them.
- An empty
/Library/Bluetoothon a Mac known to use AirPods or a Magic Keyboard suggests a Bluetooth reset or deliberate cleanup; check local snapshots and the logs.