Skip to content

USB & devicesUser activity

iPhone Backups and Pairing Records on a Mac

Finder (MobileSync) backups of iPhones and iPads on a Mac, plus lockdown pairing records, show which iOS devices were connected, trusted and backed up.

Location
~/Library/Application Support/MobileSync/Backup/<UDID>/
Proves
Which iPhone or iPad was paired with and backed up to this Mac, when, whether the backup is encrypted, and the full content of the device at backup time
Timestamps
Plist dates in Info.plist and Status.plist; file system times of the backup folder
Access
Owning user for MobileSync (TCC-protected, Full Disk Access needed); root for /private/var/db/lockdown
Retention
Backups persist until deleted in Finder; pairing records until the device is untrusted or the OS is reinstalled
Collection
mac_apt, ditto, Disk image

What it is

Since macOS 10.15 Catalina, Finder (not iTunes) syncs and backs up iPhones and iPads over USB or Wi-Fi. A local backup is a folder named after the device's UDID containing a manifest database and every backed-up file stored under a hashed name. Before the first sync, the device and the Mac exchange pairing keys ("Trust This Computer"), which leaves a pairing record on the Mac.

Two very different questions are answered here. For the Mac, it shows which mobile devices the user connected and trusted. For the case as a whole, a backup can be a near-complete copy of a phone that you may not otherwise be able to acquire.

Where it lives

SourcePathNotes
Backups~/Library/Application Support/MobileSync/Backup/<UDID>/One folder per device; snapshots may add -<date> suffixes
Backup metadataInfo.plist, Manifest.plist, Status.plist, Manifest.dbIn each backup folder
Pairing records/private/var/db/lockdown/<UDID>.plistKeys and host ID for each trusted device, root only
Device info cache~/Library/Preferences/com.apple.iPod.plistConnected devices with serial, IMEI and firmware on many releases
EventsUnified Logs, processes usbmuxd, AMPDevicesAgent, MobileDeviceUpdaterConnection, sync and backup activity

What it proves

  • A specific device (UDID, serial number, IMEI, phone number, device name, iOS version) was trusted by and backed up to this Mac.
  • When the last backup completed (Last Backup Date, Status.plist), whether it was full or incremental, and whether it is encrypted (IsEncrypted in Manifest.plist).
  • The installed apps at backup time and, inside the backup, messages, call history, photos metadata, notes, health data, keychain items (encrypted backups only) and app data.
  • A pairing record without a backup still proves the device was connected and trusted.

Key fields

FileKeys
Info.plistDevice Name, Display Name, Product Type, Product Version, Serial Number, IMEI, Phone Number, Unique Identifier, Last Backup Date, Installed Applications
Manifest.plistIsEncrypted, Lockdown (device info), Date, Applications, BackupKeyBag
Status.plistDate, IsFullBackup, SnapshotState, Version
Manifest.db table FilesfileID (SHA-1 of domain and path), domain, relativePath, flags, file (blob with metadata)

Backed-up files are stored as <first two hex chars of fileID>/<fileID>. Manifest.db maps them back to their iOS domain and path.

Timestamps

Last Backup Date and Date are plist dates (UTC). The backup folder's modification time and the files written in the last session corroborate the backup time. Timestamps inside the backup belong to the iOS databases (for example Mac absolute time in sms.db) and describe activity on the phone, not on the Mac.

Retention

  • Backups persist until the user deletes them in Finder (Manage Backups) or removes the folder.
  • Each new backup of the same device overwrites the previous one in place unless archived.
  • Pairing records persist until the device is untrusted, the record is deleted or the OS is reinstalled.

Collection

sudo ditto "/Users/<user>/Library/Application Support/MobileSync/Backup" ./case/MobileSync_<user>
sudo ditto /private/var/db/lockdown ./case/lockdown

Backups can be tens of gigabytes; check space first. The collector needs Full Disk Access. mac_apt IDEVICEBACKUPS exports backup metadata and IDEVICEINFO reads com.apple.iPod.plist.

Parsing

plutil -p ./case/MobileSync_<user>/<UDID>/Info.plist | head -40
plutil -p ./case/MobileSync_<user>/<UDID>/Manifest.plist | grep IsEncrypted

# Full analysis of the backup contents
python3 ileapp.py -t itunes -i ./case/MobileSync_<user>/<UDID> -o ./out

# Encrypted backup: decrypt (with authorised password), then scan for known spyware indicators
MVT_IOS_BACKUP_PASSWORD='<password>' mvt-ios decrypt-backup -d ./decrypted ./case/MobileSync_<user>/<UDID>
mvt-ios check-backup --output ./mvt_out ./decrypted

iLEAPP also opens encrypted backups directly when given --itunes_password. For encrypted backups without a password, the Hash Extractor converts the Manifest.plist keybag parameters into a crackable hash, where recovery is authorised.

Investigator tips

  • Encrypted backups are more valuable than unencrypted ones: they include keychain items, Health and Wi-Fi passwords.
  • Phone Number and IMEI in Info.plist identify the handset for legal process with the carrier.
  • A backup of a device that is not the user's own (a colleague's or a victim's phone) is a significant finding; compare the device name and Apple ID data.
  • USB connections of iPhones also appear in USB device logs; photos imported from the phone appear in Photos with an import source.

See also