Skip to content

macOS artifacts cheat sheet

Every artifact on one table, grouped by category. Use your browser's print dialog (landscape) or save it as a PDF.

ArtifactLocationProvesTimestampsAccessRetentionParsers
Execution
Crash ReportsmacOS 10.15+/Library/Logs/DiagnosticReports/That a given executable ran on the Mac, from which path, launched by which parent, and when it crashed or hungLocal time with UTC offset in JSON strings and file namesroot, or membership of _analyticsusers (admins are members)Moved to Retired and cleaned up by SubmitDiagInfo; days to weeksjq, mac_apt, Console
Gatekeeper and XProtect Evidence on macOSmacOS 10.15+/var/db/SystemPolicyConfiguration/ExecPolicyWhether macOS assessed, allowed, blocked or remediated a given program, and which behaviors it flaggedUnified log: shown in the time zone recorded with each entry unless --timezone is set; XPdb dt: text date-time; ExecPolicy: Unix secondsroot; Full Disk Access; XPdb is a Data Vault on 26.2+Unified log: days to weeks; databases: until rebuilt (varies)log, mac_apt, sqlite3
InstallHistory.plistmacOS 10.15+/Library/Receipts/InstallHistory.plistWhich software packages and updates were installed, when, and through which installer processPlist date values (UTC); receipt install-time in Unix epoch secondsReadable by all users; InstallHistory.plist is writable by the admin groupUntil deleted; receipts until pkgutil --forget or removalmac_apt, Plaso, pkgutil, plutil
Mounted Disk Images on macOSmacOS 10.15+/Volumes/<name>/ (mount point), plus logs and per-user cachesThat a disk image was mounted, under which volume name, which apps were run from it and where it came fromUnified Log entries in UTC; FSEvents event IDs; file system times of the image and translocation foldersroot for logs and /private/var/folders; owning user for DownloadsLog events follow rotation; the image file, quarantine and FSEvents records persist longerhdiutil, log, FSEventsParser, mac_apt, xattr
Shell History on macOSmacOS 10.15+~/.zsh_historyWhich commands a user typed in an interactive shell, in what order, and in which Terminal windowNone by default; Unix epoch seconds only if EXTENDED_HISTORY (zsh) or HISTTIMEFORMAT (bash) is setFile owner or root; plain files in the home folderzsh default SAVEHIST=1000 lines; Terminal session files deleted after about two weeksmac_apt, grep, sed
sudo LogsmacOS 10.15+/private/var/db/diagnostics/Which account ran which command as root (or another user), from which directory and terminal, and failed attemptsUnified Logs: timestamp with UTC offset; ts files: file mtime plus monotonic countersroot to read the log store, /etc/sudoers and /var/db/sudoUnified Log rotation (days to weeks); ts records until reboot or overwritelog, macos-UnifiedLogs, mac_apt, Plaso
TCC.dbmacOS 10.15+/Library/Application Support/com.apple.TCC/TCC.dbWhich programs requested or were granted sensitive privacy permissions, by whom, and when the decision last changedUnix epoch seconds (UTC) in last_modifiedFull Disk Access to read; system database also SIP-protectedUntil the row is changed, reset (tccutil) or the app is removedmac_apt, Plaso, Velociraptor, sqlite3
Persistence
Configuration Profiles and MDMmacOS 10.15+/private/var/db/ConfigurationProfiles/Which profiles and payloads (certificates, proxies, VPN, TCC/PPPC, system extensions, login items) were installed, by MDM or manually, and whenInstall dates in the profile store (plist dates); Unified Log entries in UTCroot; the profile store is SIP-protected on current releases, read it from an image or with profiles(1) liveProfiles persist until removed; install events follow Unified Log rotationprofiles, log, plutil, macos-UnifiedLogs
cron, at and periodicmacOS 10.15+/usr/lib/cron/tabs/Whether a command was scheduled to run repeatedly or once through a Unix-style scheduler, by which accountFile system times of tab and job files (APFS, UTC); cron schedules are in local timeroot (tabs directory is mode 700)Until the crontab, job or script is removedcrontab, mac_apt, Aftermath
Kernel and System ExtensionsmacOS 10.15+/Library/SystemExtensions/db.plist and /private/var/db/SystemPolicyConfiguration/KextPolicyWhich third-party kernel extensions and system extensions were installed, approved, activated or loaded, by which team ID, and whenKextPolicy created_at / last_seen as date-time values (check the storage type per image); Unified Log entries in UTCroot; KextPolicy is SIP-protected, read it from an image or with Full Disk AccessRecords persist until the extension is removed and often after; Unified Log events follow rotationkmutil, systemextensionsctl, sqlite3, plutil, KnockKnock, APOLLO
LaunchAgents and LaunchDaemonsmacOS 10.15+~/Library/LaunchAgents, /Library/LaunchAgents, /Library/LaunchDaemonsWhat code is configured to start automatically, as which user, on which trigger, and since whenNo internal timestamps; APFS file times (nanoseconds, UTC)User agents: owning user; /Library: root; FDA recommended for collectorUntil the plist is deleted; overrides and BTM records can outlive itmac_apt, Plaso, KnockKnock, plutil
Login Items and BTM Database on macOSmacOS 10.15+/private/var/db/com.apple.backgroundtaskmanagement/BackgroundItems-v*.btmWhich login items, agents and daemons were registered, by which developer, and whether they were allowedNSKeyedArchiver dates (Mac absolute time, UTC) plus file system timesroot and Full Disk Access (BTM store); owning user (legacy backgrounditems.btm)Until the item is removed or sfltool resetbtm rebuilds the storeDumpBTM, bgiparser, Plaso, sfltool
File access
APFS Timestamps and Local Snapshots on macOSmacOS 10.15+/System/Volumes/DataWhen files were created, changed and added to a folder, and how the volume looked hours earlierNanoseconds since 1970-01-01 UTC (Unix epoch)Any user for stat on own files; root plus Full Disk Access to mount snapshotsTimestamps until overwritten; hourly local snapshots kept about 24 hourslibfsapfs, stat, mac_apt
Cloud Storage Clients on MacmacOS 10.15+~/Library/CloudStorage/ plus each client's Application Support, Group Container and log foldersWhich cloud accounts were linked, which files existed in or passed through the synced folders, and when they were uploaded, downloaded or deletedMixed: Unix epoch (seconds or milliseconds) in most client databases, Mac absolute time in File Provider data, local time in some logsOwning user; some client databases are encrypted or obfuscated and need the user's keychainDatabases track the current sync state; logs rotate by size and age; deleted files may remain in the cloud service's own trashsqlite3, FSEventsParser, plutil, grep
CUPS Print Jobs and LogsmacOS 10.15+/private/var/spool/cups/ and /private/var/log/cups/Which user printed which job (document name and application), to which printer, when, and how many pages or copiesIPP attributes time-at-creation / processing / completed in Unix epoch seconds; log lines in local time with UTC offsetroot for the spool and logs; printers.conf readable by rootControl files for up to the configured job history (default 500 jobs); data files usually removed after the job; logs rotate by sizemac_apt, lpstat, grep
FSEvents (.fseventsd)macOS 10.15+/System/Volumes/Data/.fseventsd/Which paths were created, changed, renamed or deleted on a volume, in event orderNone per record; estimate from log file mtime and dated pathsroot; Full Disk Access on a live systemRolling, purged by fseventsd (months observed, varies)FSEventsParser, mac_apt
iCloud Drive (CloudDocs)macOS 10.15+~/Library/Application Support/CloudDocs/session/db/client.dbWhich files were in the user's iCloud Drive, when, and from which of their devicesUnix epoch seconds (UTC) in CloudDocs databasesUser or root; Full Disk Access for the collector on a live systemCurrent sync state; items leave when deleted and purged from iCloudmac_apt, sqlite3
Microsoft Office and Outlook for MacmacOS 10.15+~/Library/Containers/com.microsoft.<App>/ and ~/Library/Group Containers/UBF8T346G9.Office/Which documents were opened in Word, Excel and PowerPoint, from which paths and when, the Office user identity, and the local copy of Outlook mailPlist dates (kLastUsedDateKey); Windows FILETIME in MicrosoftRegistrationDB.reg; Outlook database dates per schemaOwning user; Group Containers and Containers need Full Disk Access to collect on current releasesMRU lists hold a limited number of entries; Outlook caches follow account sync settingsmac_apt, plutil, sqlite3
Photos.sqlitemacOS 10.15+~/Pictures/Photos Library.photoslibrary/database/Photos.sqliteWhen media was captured, added, edited, hidden or trashed, where it was taken and which app or device imported itMac absolute time (seconds since 2001-01-01 UTC); time zone offset per assetTCC-protected library: Full Disk Access (or Photos access) for the collectorUntil deleted; Recently Deleted items are purged after 30 daysosxphotos, exiftool, sqlite3
QuarantineEventsV2 and Quarantine xattr on macOSmacOS 10.15+~/Library/Preferences/com.apple.LaunchServices.QuarantineEventsV2Which files a user downloaded, from which URL and origin page, with which app, and whenDatabase: Mac absolute time (UTC); xattr: hex Unix seconds (UTC)Owning user or root; Full Disk Access recommended for the collectorUntil deleted or cleared (no documented automatic purge)mac_apt, Plaso, Velociraptor, sqlite3
QuickLook Thumbnail CachemacOS 10.15+$(getconf DARWIN_USER_CACHE_DIR)/com.apple.quicklook.ThumbnailsAgent/com.apple.QuickLook.thumbnailcache/That a file existed at a path and was displayed as a thumbnail or preview, with a cached image that can outlive the originallast_hit_date in Mac absolute time; file modification time stored in the version blobOwning user or root; the cache sits under /private/var/folders, collect as rootCache is pruned by size and age and rebuilt with qlmanage -r cache; not a long-term recordmac_apt, sqlite3, plutil
Recent Items (.sfl2/.sfl3)macOS 10.15+~/Library/Application Support/com.apple.sharedfilelist/Which documents, apps and servers a user recently opened, with full paths and source volumesMostly none per item; bookmark dates in Mac absolute time (2001 epoch)User-owned; Full Disk Access for the collector on a live systemRolling lists capped by the Recent Items count (default 10)mac_apt, plutil
Spotlight Store (.Spotlight-V100)macOS 10.15+/System/Volumes/Data/.Spotlight-V100/Store-V2/<UUID>/store.dbWhere a file came from, when it was added and opened, and that it existed even after deletionMac absolute time (seconds since 2001-01-01 UTC); mdls shows UTCroot; Full Disk Access on a live systemUntil the indexer updates or purges the entry, or the index is rebuiltspotlight_parser, mac_apt
Time Machine BackupsmacOS 10.15+/Library/Preferences/com.apple.TimeMachine.plistWhich backup destinations were used, when backups ran, and what files looked like at each backupBackup names YYYY-MM-DD-HHMMSS; plist dates as plist date objectsroot plus Full Disk Access for tmutil listbackups and backup contentsHourly 24 h, daily for a month, weekly after; oldest deleted when fulltmutil, Plaso, plutil
User activity
Apple MailmacOS 10.15+~/Library/Mail/V10/MailData/Envelope IndexWhich emails were sent or received, from and to whom, when, in which mailbox, and which attachments were openedEnvelope Index dates in Unix epoch seconds (UTC); message headers in RFC 5322 local timeTCC-protected (Mail data): Full Disk Access for the collectorUntil deleted or removed from the server; local copies follow account sync settingssqlite3, emlx (Python)
Apple Notes NoteStore.sqlitemacOS 10.15+~/Library/Group Containers/group.com.apple.notes/NoteStore.sqliteWhat a user wrote in Notes, when each note was created and last modified, attachments, folders, iCloud or local account, and deleted notes still in the databaseMac absolute time (seconds since 2001-01-01 UTC)Owning user; the group container is TCC-protected, so the collector needs Full Disk AccessUntil deleted; Recently Deleted keeps notes for about 30 days, and freed pages may survive in the WAL or free listapple_cloud_notes_parser, mac_apt, sqlite3
Biome SEGB StreamsmacOS 12+~/Library/Biome/streams/restricted/<Stream>/local/Which apps were in focus, sites visited, devices and networks connected, with per-record timesMac absolute time (Cocoa) doubles in SEGB records; file names are Cocoa time in microsecondsFull Disk Access (user streams); system streams are SIP-restrictedWeeks for most streams (about 28 days, a figure from iOS research); expired files move to tombstonemac_apt, ccl-segb
Calendar, Contacts and Reminders Databases on macOSmacOS 10.15+~/Library/Application Support/AddressBook/, ~/Library/Group Containers/group.com.apple.reminders/, ~/Library/Calendars/ or group.com.apple.calendarWho the user knew and how to reach them, which meetings and appointments existed, where and with whom, and which tasks were created or completedMac absolute time (seconds since 2001-01-01 UTC) in all three Core Data storesOwning user; each store is TCC-protected (Contacts, Calendars, Reminders), so the collector needs Full Disk AccessUntil deleted locally or through sync; deleted items may persist briefly for sync and in WAL filessqlite3, APOLLO, plutil
Chrome and Firefox History on macOSmacOS 10.15+~/Library/Application Support/Google/Chrome/Default/HistoryWhich sites a user opened in Chrome, Chromium browsers or Firefox, when, and what they downloadedChrome: microseconds since 1601-01-01 UTC; Firefox PRTime: microseconds since 1970-01-01 UTCFile owner or root; give the collector Full Disk Access as wellChrome: about 90 days of visits; Firefox: size-based expiration of old pagesHindsight, mac_apt, sqlite3
Dock and Finder PlistsmacOS 10.15+~/Library/Preferences/com.apple.finder.plistWhich apps a user kept or recently ran in the Dock, and which folders, paths and servers they visited in FinderFew per key; Dock tile dates in HFS+ seconds (1904 epoch)User-owned; Full Disk Access for the collector on a live systemUntil the preference changes or the user resets itmac_apt, plutil
dslocal User AccountsmacOS 10.15+/private/var/db/dslocal/nodes/Default/users/<name>.plistWhich local accounts exist, when they were created, who is admin, and recent password and failed-login activityaccountPolicyData: Unix epoch seconds (UTC)root; Full Disk Access recommended for the collectorUntil the account is deleted; home may survive in /Users/Deleted Usersmac_apt, Velociraptor, plutil, dscl
knowledgeC.dbmacOS 10.15+/private/var/db/CoreDuet/Knowledge/knowledgeC.dbWhich apps were in use, when and for how long, and whether the display was on at the timeMac absolute time (seconds since 2001-01-01 UTC), plus ZSECONDSFROMGMT offsetroot plus SIP limits (system DB); Full Disk Access (user DB)About four weeks of events on typical systems (varies by stream)APOLLO, Plaso, sqlite3
macOS Keychain FilesmacOS 10.15+~/Library/Keychains/Which accounts, services, networks and certificates a user had saved, and when items were created or modifiedFile keychain: UTC strings YYYYMMDDhhmmssZ; keychain-2.db: Mac absolute timeOwning user or root; secrets need user credentials and, for data protection items, the original deviceUntil the item or keychain is deletedsecurity, sqlite3
Messages chat.dbmacOS 10.15+~/Library/Messages/chat.dbWho communicated with whom, what was said, when it was sent, delivered and read, and which files were exchangedNanoseconds since 2001-01-01 UTC (High Sierra+); older rows in secondsTCC-protected (Messages data): Full Disk Access for the collectorUntil deleted; Recently Deleted keeps items up to 30 days (Ventura+)imessage-exporter, mac_apt, Plaso, sqlite3
Notification Center DatabasemacOS 10.15+~/Library/Group Containers/group.com.apple.usernoted/db2/dbWhich app showed which notification text to the user, and when it was deliveredMac absolute time (seconds since 2001-01-01 UTC)Sequoia+: TCC-protected group container (Full Disk Access); older: owning userNot documented by Apple; varies, measure from oldest delivered_datemac_apt, Plaso, sqlite3
Safari History.dbmacOS 10.15+~/Library/Safari/History.dbWhich URLs a macOS user opened in Safari, when, through which redirects, and whether history was clearedMac absolute time (Cocoa, seconds since 2001-01-01 UTC), stored as REALFull Disk Access for the reading process (TCC); root alone is not enoughUser setting, one year by default or kept until cleared manually; download list defaults to one daymac_apt, APOLLO, sqlite3, plutil
Saved Application StatemacOS 10.15+~/Library/Saved Application State/<bundle-id>.savedState/Which apps were open with which windows, document titles and dock menu entries, and for Terminal, the text visible in each windowFile system times of windows.plist and data.data (last state save)Owning user; readable from an image or with Full Disk AccessRewritten while the app runs; kept after quit when Close windows when quitting an app is off; deleted on clean quit otherwisemac_apt, plutil
Screen Time DatabasesmacOS 10.15+/private/var/folders/<xx>/<id>/0/com.apple.ScreenTimeAgent/Store/How much time each app or web domain was used per period, on which device and by which Apple AccountMac absolute time (seconds since 2001-01-01 UTC); durations in secondsOwning user or root; extra protection on current macOS, image collection is most reliableNot documented by Apple; measure from the oldest usage blockmac_apt, APOLLO, sqlite3
Network
netusage.sqlitemacOS 10.15+/private/var/networkd/db/netusage.sqliteThat a process used the network, when it was first and last seen, how much data it moved per interface type, and which networks the Mac attached toMac absolute time (seconds since 2001-01-01 UTC)root; the networkd folder is protected, collect with Full Disk Access or from an imageRows persist for long periods; counters are cumulative and records are pruned by networkd on its own schedulemac_apt, APOLLO, sqlite3
Screen Sharing and Apple Remote Desktop ArtifactsmacOS 10.15+/private/var/db/RemoteManagement/ and ~/Library/Containers/com.apple.ScreenSharing/Who connected to this Mac over VNC / Screen Sharing or ARD, from which address and when, and which hosts this Mac's user controlledUnified Log entries in UTC; plist dates and ARD caches in Mac absolute timeroot for /private/var/db/RemoteManagement and the log store; owning user for the Screen Sharing containerLog events follow Unified Log rotation; connection history and ARD caches persist until clearedlog, mac_apt, plutil, macos-UnifiedLogs
SSH and Remote Login on macOSmacOS 10.15+~/.ssh/ and /private/etc/ssh/Inbound SSH logons (who, from which IP, with which key or password), outbound SSH targets, and key-based persistenceUnified Log entries in UTC; file system times of authorized_keys, known_hosts and host keysOwning user for ~/.ssh; root for /private/etc/ssh and the log storeKey files until edited; sshd events follow Unified Log rotation (days to weeks)log, macos-UnifiedLogs, ssh-keygen, stat, grep
Wi-Fi Known Networks on macOSmacOS 10.15+/Library/Preferences/com.apple.wifi.known-networks.plistWhich Wi-Fi networks and access points a Mac joined, when first added, and when last joined by the user or systemPlist date objects (stored as Mac absolute time, shown in UTC); wifi.log in local timeroot (known-networks plist is 0600 root:wheel on current macOS)Known networks until the user forgets them; wifi.log rotated daily, about 10 archivesmac_apt, plutil
USB & devices
Bluetooth Devices on macOSmacOS 10.15+/Library/Bluetooth/Library/Preferences/com.apple.MobileBluetooth.devices.plistWhich Bluetooth devices were paired with or seen by a Mac, their names and vendors, and when they were last seenLastSeenTime: Unix epoch seconds; legacy plist dates: plist date objects (UTC)root (files under /Library/Bluetooth are root-only on current macOS)Paired devices until removed; LE 'other' cache and logs roll overmac_apt, APOLLO, plutil, sqlite3
iPhone Backups and Pairing Records on a MacmacOS 10.15+~/Library/Application Support/MobileSync/Backup/<UDID>/Which iPhone or iPad was paired with and backed up to this Mac, when, whether the backup is encrypted, and the full content of the device at backup timePlist dates in Info.plist and Status.plist; file system times of the backup folderOwning user for MobileSync (TCC-protected, Full Disk Access needed); root for /private/var/db/lockdownBackups persist until deleted in Finder; pairing records until the device is untrusted or the OS is reinstallediLEAPP, MVT, mac_apt, plutil, sqlite3
USB DevicesmacOS 10.15+/private/var/db/diagnostics/Which USB storage devices were attached, when volumes were mounted, and which files were touched on themUnified Logs UTC instants; FSEvents has no per-record timeroot for the log store and .fseventsd; live commands need no special rightsUnified Log rotation (days to weeks); FSEvents until pages are purgedlog, macos-UnifiedLogs, mac_apt, FSEventsParser
Anti-forensics
macOS Trash and .DS_StoremacOS 10.15+~/.Trash/ and /Volumes/<volume>/.Trashes/<uid>/Which files a user moved to the Trash, their original folder and name, and roughly when they were trashedFile system times of the trashed item (ctime changes on the move); .DS_Store modD/moDD in Mac absolute timeOwning user; ~/.Trash is TCC-protected for other apps, so the collector needs Full Disk AccessUntil the Trash is emptied, or 30 days if Remove items from the Trash after 30 days is enabledmac_apt, DSStoreParser, stat
Logs
System LogsmacOS 10.15+/private/var/log/Install, update, Wi-Fi and legacy syslog activity, often beyond Unified Log retentionLocal time; install.log uses ISO-style time with UTC offset, BSD syslog lines have no yearadmin group or root (system.log and wifi.log are mode 640, group admin)Size or daily rotation set in /etc/asl.conf, /etc/asl/ and /etc/newsyslog.d/Plaso, mac_apt, syslog, grep
Unified LogsmacOS 10.15+/private/var/db/diagnostics/What processes and subsystems reported, and when: logins, privilege use, security checks, devicesMach time converted via timesync records; log show prints ISO 8601 with UTC offsetroot (admin group can read the store); log collect needs sudoSize-based rotation, typically days to a few weekslog, macos-UnifiedLogs, Plaso, mac_apt

Memory acquisition on macOS is out of scope for these pages; see mac-dump: github.com/Cyber-Experts/mac-dump