iPhone Backups and Pairing Records on a Mac
Finder (MobileSync) backups of iPhones and iPads on a Mac, plus lockdown pairing records, show which iOS devices were connected, trusted and backed up.
- Location
- ~/Library/Application Support/MobileSync/Backup/<UDID>/
- Proves
- Which iPhone or iPad was paired with and backed up to this Mac, when, whether the backup is encrypted, and the full content of the device at backup time
- Timestamps
- Plist dates in Info.plist and Status.plist; file system times of the backup folder
- Access
- Owning user for MobileSync (TCC-protected, Full Disk Access needed); root for /private/var/db/lockdown
- Retention
- Backups persist until deleted in Finder; pairing records until the device is untrusted or the OS is reinstalled
- Collection
- mac_apt, ditto, Disk image
Tools
Compare all tools- Hash ExtractorIn browser
- iLEAPPCLI · open source
- MVTCLI
- mac_aptCLI · open source
- plutilCLI · built into macOS
- sqlite3CLI · built into macOS
What it is
Since macOS 10.15 Catalina, Finder (not iTunes) syncs and backs up iPhones and iPads over USB or Wi-Fi. A local backup is a folder named after the device's UDID containing a manifest database and every backed-up file stored under a hashed name. Before the first sync, the device and the Mac exchange pairing keys ("Trust This Computer"), which leaves a pairing record on the Mac.
Two very different questions are answered here. For the Mac, it shows which mobile devices the user connected and trusted. For the case as a whole, a backup can be a near-complete copy of a phone that you may not otherwise be able to acquire.
Where it lives
| Source | Path | Notes |
|---|---|---|
| Backups | ~/Library/Application Support/MobileSync/Backup/<UDID>/ | One folder per device; snapshots may add -<date> suffixes |
| Backup metadata | Info.plist, Manifest.plist, Status.plist, Manifest.db | In each backup folder |
| Pairing records | /private/var/db/lockdown/<UDID>.plist | Keys and host ID for each trusted device, root only |
| Device info cache | ~/Library/Preferences/com.apple.iPod.plist | Connected devices with serial, IMEI and firmware on many releases |
| Events | Unified Logs, processes usbmuxd, AMPDevicesAgent, MobileDeviceUpdater | Connection, sync and backup activity |
What it proves
- A specific device (UDID, serial number, IMEI, phone number, device name, iOS version) was trusted by and backed up to this Mac.
- When the last backup completed (
Last Backup Date,Status.plist), whether it was full or incremental, and whether it is encrypted (IsEncryptedinManifest.plist). - The installed apps at backup time and, inside the backup, messages, call history, photos metadata, notes, health data, keychain items (encrypted backups only) and app data.
- A pairing record without a backup still proves the device was connected and trusted.
Key fields
| File | Keys |
|---|---|
Info.plist | Device Name, Display Name, Product Type, Product Version, Serial Number, IMEI, Phone Number, Unique Identifier, Last Backup Date, Installed Applications |
Manifest.plist | IsEncrypted, Lockdown (device info), Date, Applications, BackupKeyBag |
Status.plist | Date, IsFullBackup, SnapshotState, Version |
Manifest.db table Files | fileID (SHA-1 of domain and path), domain, relativePath, flags, file (blob with metadata) |
Backed-up files are stored as <first two hex chars of fileID>/<fileID>. Manifest.db maps them back to their iOS domain and path.
Timestamps
Last Backup Date and Date are plist dates (UTC). The backup folder's modification time and the files written in the last session corroborate the backup time. Timestamps inside the backup belong to the iOS databases (for example Mac absolute time in sms.db) and describe activity on the phone, not on the Mac.
Retention
- Backups persist until the user deletes them in Finder (Manage Backups) or removes the folder.
- Each new backup of the same device overwrites the previous one in place unless archived.
- Pairing records persist until the device is untrusted, the record is deleted or the OS is reinstalled.
Collection
sudo ditto "/Users/<user>/Library/Application Support/MobileSync/Backup" ./case/MobileSync_<user>
sudo ditto /private/var/db/lockdown ./case/lockdown
Backups can be tens of gigabytes; check space first. The collector needs Full Disk Access. mac_apt IDEVICEBACKUPS exports backup metadata and IDEVICEINFO reads com.apple.iPod.plist.
Parsing
plutil -p ./case/MobileSync_<user>/<UDID>/Info.plist | head -40
plutil -p ./case/MobileSync_<user>/<UDID>/Manifest.plist | grep IsEncrypted
# Full analysis of the backup contents
python3 ileapp.py -t itunes -i ./case/MobileSync_<user>/<UDID> -o ./out
# Encrypted backup: decrypt (with authorised password), then scan for known spyware indicators
MVT_IOS_BACKUP_PASSWORD='<password>' mvt-ios decrypt-backup -d ./decrypted ./case/MobileSync_<user>/<UDID>
mvt-ios check-backup --output ./mvt_out ./decrypted
iLEAPP also opens encrypted backups directly when given --itunes_password. For encrypted backups without a password, the Hash Extractor converts the Manifest.plist keybag parameters into a crackable hash, where recovery is authorised.
Investigator tips
- Encrypted backups are more valuable than unencrypted ones: they include keychain items, Health and Wi-Fi passwords.
Phone NumberandIMEIinInfo.plistidentify the handset for legal process with the carrier.- A backup of a device that is not the user's own (a colleague's or a victim's phone) is a significant finding; compare the device name and Apple ID data.
- USB connections of iPhones also appear in USB device logs; photos imported from the phone appear in Photos with an import source.