User activityFile accessExecution
Dock and Finder Plists: macOS User Preference Evidence
com.apple.dock.plist and com.apple.finder.plist record pinned and recent apps, recent folders, Go to Folder history, servers and searches.
- Location
- ~/Library/Preferences/com.apple.finder.plist
- Proves
- Which apps a user kept or recently ran in the Dock, and which folders, paths and servers they visited in Finder
- Timestamps
- Few per key; Dock tile dates in HFS+ seconds (1904 epoch)
- Access
- User-owned; Full Disk Access for the collector on a live system
- Retention
- Until the preference changes or the user resets it
- Collection
- UAC, mac_apt, Disk image, defaults export
Tools
Compare all tools- mac_aptCLI · open source
- plutilCLI · built into macOS
What it is
The Dock and Finder keep their per-user settings in standard preference property lists. Beyond appearance settings, both store user history:
com.apple.dock.plist: apps pinned in the Dock, the "recent applications" section (Mojave and later), and folders or stacks on the right-hand side.com.apple.finder.plist: recently visited folders, the Go to Folder history, the last Connect to Server URL, recent move and copy destinations, recent Finder searches, and desktop positions of mounted volumes.
They are small, quick to check and rarely cleaned by users, which makes them good corroboration for app usage and file browsing.
Where it lives
| File | Path | Notes |
|---|---|---|
| Dock | ~/Library/Preferences/com.apple.dock.plist | Binary plist |
| Finder | ~/Library/Preferences/com.apple.finder.plist | Binary plist |
| Global prefs | ~/Library/Preferences/.GlobalPreferences.plist | NSNavRecentPlaces (recent places in Open and Save dialogs) |
| Sidebar (older macOS) | ~/Library/Preferences/com.apple.sidebarlists.plist | favoriteservers, systemitems / VolumesList; replaced by Shared File Lists on newer versions |
Protection: user-owned files. On a live system the collector needs Full Disk Access to read other users' Library folders reliably. Preferences are cached by cfprefsd, so the on-disk file can lag behind the live value; defaults read shows the current value.
What it proves
- Apps the user pinned to the Dock, and up to the last few apps launched that were not pinned (
recent-apps). - Folders the user browsed recently in Finder (
FXRecentFolders), including on external volumes. - Paths typed into Go to Folder (
GoToField,GoToFieldHistory): strong evidence of deliberate navigation, often to hidden locations. - The last server address typed into Connect to Server (
FXConnectToLastURL). - Recent move and copy targets (
RecentMoveAndCopyDestinations) and recent Finder searches (SGTRecentFileSearches). - Volumes that were shown on the desktop, with a volume creation date encoded in the key (
FXDesktopVolumePositions).
It does not prove:
- When most of these actions happened. Keys generally carry no timestamp.
- That a pinned app was ever used; it may be a default Dock item.
Key fields
com.apple.dock.plist
| Key | Meaning |
|---|---|
persistent-apps | Pinned apps (left side of the Dock) |
recent-apps | Recently used apps section (Mojave and later) |
persistent-others | Folders, stacks and files on the right side |
show-recents | Whether the recent apps section is enabled |
…/GUID | Tile identifier |
…/tile-data/file-label | Displayed name |
…/tile-data/bundle-identifier | App bundle ID |
…/tile-data/file-data/_CFURLString | Path or URL of the item |
…/tile-data/file-type | Tile type code |
…/tile-data/file-mod-date, parent-mod-date | Modification dates of the item and its parent folder |
com.apple.finder.plist
| Key | Meaning |
|---|---|
FXRecentFolders | Array of recent folders: name plus file-bookmark (older versions: file-data with _CFURLAliasData) |
GoToField | Last path typed in Go to Folder |
GoToFieldHistory | Earlier Go to Folder paths |
FXConnectToLastURL | Last Connect to Server URL |
RecentMoveAndCopyDestinations | Recent destinations for move and copy |
SGTRecentFileSearches | Recent Finder searches (name, type) |
FXDesktopVolumePositions | Desktop icon positions per volume; key is the volume name plus a hex timestamp |
NSNavLastRootDirectory, NSNavLastCurrentDirectory | Last directories in Open and Save dialogs |
BulkRename* (for example BulkRenameFindText, BulkRenameReplaceText) | Last batch-rename settings |
Timestamps
- Dock
file-mod-dateandparent-mod-date: mac_apt treats them as HFS+ time (seconds since 1904-01-01) and, on High Sierra and later, uses only the lower 32 bits of the stored value. Subtract 2082844800 to get Unix time. FXDesktopVolumePositionskey suffix: the hex value after the last underscore is decoded by mac_apt as Mac absolute time (seconds since 2001-01-01 UTC), reported as the volume creation date.- Bookmarks in
FXRecentFoldershold dates in Mac absolute time. - Otherwise, use the plist file's modification time to show when preferences last changed.
# HFS+ seconds to UTC
date -u -r $(( 3840000000 - 2082844800 ))
Retention
Values persist until overwritten. recent-apps holds a short rolling set, FXRecentFolders and GoToFieldHistory are bounded lists, and new entries push out old ones. Resetting the Dock or deleting the plist wipes history; earlier states can be recovered from snapshots and Time Machine.
Collection
# Live: export current values (reads through cfprefsd) and copy the files
defaults export com.apple.dock /Volumes/CASE/MBP01/alice_dock.plist
defaults export com.apple.finder /Volumes/CASE/MBP01/alice_finder.plist
ditto ~/Library/Preferences /Volumes/CASE/MBP01/alice_Preferences
- UAC collects every user's
~/Library/Preferences/*.plist(files/system/library_preferences.yaml) and the Finder plist again under its MRU artifact, both inir_triage. - mac_apt
DOCKITEMSandRECENTITEMSread these files for every user from an image. - Copy the plist files as well as exporting them, to keep file timestamps.
Parsing
plutil -p alice_finder.plist | grep -A5 -E "GoToField|FXRecentFolders|FXConnectToLastURL"
python3 mac_apt.py -o /cases/MBP01/mac_apt E01 /cases/MBP01.E01 DOCKITEMS RECENTITEMS
python3 mac_apt_artifact_only.py -i /cases/MBP01/alice_Preferences/com.apple.dock.plist -o /cases/MBP01/out DOCKITEMS
mac_apt DOCKITEMS outputs File Label, Parent Modified, File Modified, Recently Used (set for recent-apps entries), File Type, File Path, GUID and Bundle Identifier. RECENTITEMS decodes FXRecentFolders bookmarks and lists the other Finder keys with their source.
Investigator tips
GoToFieldHistoryentries such as~/Library/LaunchAgentsor/private/tmpshow a user who knew where to look. Cross-check with shell history.- A
recent-appstile for a remote access tool, archiver or wiping utility is a lead even if the app was deleted; itsfile-datapath shows where it ran from. FXRecentFoldersandFXDesktopVolumePositionsentries naming external volumes support USB device findings.FXConnectToLastURLwithsmb://orafp://complementsRecentServersin recent items.- Because of
cfprefsdcaching, a plist copied from a live system may not contain the latest change. Export withdefaultstoo. - Add time with KnowledgeC or Biome app usage, since these plists mostly lack timestamps.