Skip to content

User activityFile accessExecution

Dock and Finder Plists: macOS User Preference Evidence

com.apple.dock.plist and com.apple.finder.plist record pinned and recent apps, recent folders, Go to Folder history, servers and searches.

Location
~/Library/Preferences/com.apple.finder.plist
Proves
Which apps a user kept or recently ran in the Dock, and which folders, paths and servers they visited in Finder
Timestamps
Few per key; Dock tile dates in HFS+ seconds (1904 epoch)
Access
User-owned; Full Disk Access for the collector on a live system
Retention
Until the preference changes or the user resets it
Collection
UAC, mac_apt, Disk image, defaults export

What it is

The Dock and Finder keep their per-user settings in standard preference property lists. Beyond appearance settings, both store user history:

  • com.apple.dock.plist: apps pinned in the Dock, the "recent applications" section (Mojave and later), and folders or stacks on the right-hand side.
  • com.apple.finder.plist: recently visited folders, the Go to Folder history, the last Connect to Server URL, recent move and copy destinations, recent Finder searches, and desktop positions of mounted volumes.

They are small, quick to check and rarely cleaned by users, which makes them good corroboration for app usage and file browsing.

Where it lives

FilePathNotes
Dock~/Library/Preferences/com.apple.dock.plistBinary plist
Finder~/Library/Preferences/com.apple.finder.plistBinary plist
Global prefs~/Library/Preferences/.GlobalPreferences.plistNSNavRecentPlaces (recent places in Open and Save dialogs)
Sidebar (older macOS)~/Library/Preferences/com.apple.sidebarlists.plistfavoriteservers, systemitems / VolumesList; replaced by Shared File Lists on newer versions

Protection: user-owned files. On a live system the collector needs Full Disk Access to read other users' Library folders reliably. Preferences are cached by cfprefsd, so the on-disk file can lag behind the live value; defaults read shows the current value.

What it proves

  • Apps the user pinned to the Dock, and up to the last few apps launched that were not pinned (recent-apps).
  • Folders the user browsed recently in Finder (FXRecentFolders), including on external volumes.
  • Paths typed into Go to Folder (GoToField, GoToFieldHistory): strong evidence of deliberate navigation, often to hidden locations.
  • The last server address typed into Connect to Server (FXConnectToLastURL).
  • Recent move and copy targets (RecentMoveAndCopyDestinations) and recent Finder searches (SGTRecentFileSearches).
  • Volumes that were shown on the desktop, with a volume creation date encoded in the key (FXDesktopVolumePositions).

It does not prove:

  • When most of these actions happened. Keys generally carry no timestamp.
  • That a pinned app was ever used; it may be a default Dock item.

Key fields

com.apple.dock.plist

KeyMeaning
persistent-appsPinned apps (left side of the Dock)
recent-appsRecently used apps section (Mojave and later)
persistent-othersFolders, stacks and files on the right side
show-recentsWhether the recent apps section is enabled
…/GUIDTile identifier
…/tile-data/file-labelDisplayed name
…/tile-data/bundle-identifierApp bundle ID
…/tile-data/file-data/_CFURLStringPath or URL of the item
…/tile-data/file-typeTile type code
…/tile-data/file-mod-date, parent-mod-dateModification dates of the item and its parent folder

com.apple.finder.plist

KeyMeaning
FXRecentFoldersArray of recent folders: name plus file-bookmark (older versions: file-data with _CFURLAliasData)
GoToFieldLast path typed in Go to Folder
GoToFieldHistoryEarlier Go to Folder paths
FXConnectToLastURLLast Connect to Server URL
RecentMoveAndCopyDestinationsRecent destinations for move and copy
SGTRecentFileSearchesRecent Finder searches (name, type)
FXDesktopVolumePositionsDesktop icon positions per volume; key is the volume name plus a hex timestamp
NSNavLastRootDirectory, NSNavLastCurrentDirectoryLast directories in Open and Save dialogs
BulkRename* (for example BulkRenameFindText, BulkRenameReplaceText)Last batch-rename settings

Timestamps

  • Dock file-mod-date and parent-mod-date: mac_apt treats them as HFS+ time (seconds since 1904-01-01) and, on High Sierra and later, uses only the lower 32 bits of the stored value. Subtract 2082844800 to get Unix time.
  • FXDesktopVolumePositions key suffix: the hex value after the last underscore is decoded by mac_apt as Mac absolute time (seconds since 2001-01-01 UTC), reported as the volume creation date.
  • Bookmarks in FXRecentFolders hold dates in Mac absolute time.
  • Otherwise, use the plist file's modification time to show when preferences last changed.
# HFS+ seconds to UTC
date -u -r $(( 3840000000 - 2082844800 ))

Retention

Values persist until overwritten. recent-apps holds a short rolling set, FXRecentFolders and GoToFieldHistory are bounded lists, and new entries push out old ones. Resetting the Dock or deleting the plist wipes history; earlier states can be recovered from snapshots and Time Machine.

Collection

# Live: export current values (reads through cfprefsd) and copy the files
defaults export com.apple.dock /Volumes/CASE/MBP01/alice_dock.plist
defaults export com.apple.finder /Volumes/CASE/MBP01/alice_finder.plist
ditto ~/Library/Preferences /Volumes/CASE/MBP01/alice_Preferences
  • UAC collects every user's ~/Library/Preferences/*.plist (files/system/library_preferences.yaml) and the Finder plist again under its MRU artifact, both in ir_triage.
  • mac_apt DOCKITEMS and RECENTITEMS read these files for every user from an image.
  • Copy the plist files as well as exporting them, to keep file timestamps.

Parsing

plutil -p alice_finder.plist | grep -A5 -E "GoToField|FXRecentFolders|FXConnectToLastURL"
python3 mac_apt.py -o /cases/MBP01/mac_apt E01 /cases/MBP01.E01 DOCKITEMS RECENTITEMS
python3 mac_apt_artifact_only.py -i /cases/MBP01/alice_Preferences/com.apple.dock.plist -o /cases/MBP01/out DOCKITEMS

mac_apt DOCKITEMS outputs File Label, Parent Modified, File Modified, Recently Used (set for recent-apps entries), File Type, File Path, GUID and Bundle Identifier. RECENTITEMS decodes FXRecentFolders bookmarks and lists the other Finder keys with their source.

Investigator tips

  • GoToFieldHistory entries such as ~/Library/LaunchAgents or /private/tmp show a user who knew where to look. Cross-check with shell history.
  • A recent-apps tile for a remote access tool, archiver or wiping utility is a lead even if the app was deleted; its file-data path shows where it ran from.
  • FXRecentFolders and FXDesktopVolumePositions entries naming external volumes support USB device findings.
  • FXConnectToLastURL with smb:// or afp:// complements RecentServers in recent items.
  • Because of cfprefsd caching, a plist copied from a live system may not contain the latest change. Export with defaults too.
  • Add time with KnowledgeC or Biome app usage, since these plists mostly lack timestamps.

See also