Skip to content

File accessUser activity

Microsoft Office and Outlook for Mac: MRU and Mailbox Data

Office for Mac keeps recent-file lists in securebookmarks plists and MicrosoftRegistrationDB.reg; Outlook for Mac stores mail in a local profile database.

Location
~/Library/Containers/com.microsoft.<App>/ and ~/Library/Group Containers/UBF8T346G9.Office/
Proves
Which documents were opened in Word, Excel and PowerPoint, from which paths and when, the Office user identity, and the local copy of Outlook mail
Timestamps
Plist dates (kLastUsedDateKey); Windows FILETIME in MicrosoftRegistrationDB.reg; Outlook database dates per schema
Access
Owning user; Group Containers and Containers need Full Disk Access to collect on current releases
Retention
MRU lists hold a limited number of entries; Outlook caches follow account sync settings
Collection
UAC, mac_apt, ditto, Disk image

What it is

Microsoft 365 apps on macOS are sandboxed App Store-style apps. Each keeps its preferences in its own container, and they share data through the UBF8T346G9.Office group container (the prefix is Microsoft's team ID). Two sources matter most for file access:

  • Secure bookmarks: sandboxed apps must keep a security-scoped bookmark for every file the user opened, to reopen it later. Office stores them with a last-used date, which makes a reliable most-recently-used list.
  • MicrosoftRegistrationDB.reg: a SQLite database that emulates the Windows registry for Office, with keys, values and last-write times.

Outlook for Mac stores a local copy of mailboxes in its profile folder. Apple Mail is covered separately in Mail.

Where it lives

SourcePathNotes
Secure bookmarks~/Library/Containers/com.microsoft.<App>/Data/Library/Preferences/com.microsoft.<App>.securebookmarks.plist<App> is Word, Excel, Powerpoint
App preferences~/Library/Containers/com.microsoft.<App>/Data/Library/Preferences/com.microsoft.<App>.plistSettings, some recent data
Office registry~/Library/Group Containers/UBF8T346G9.Office/MicrosoftRegistrationDB.regMay be a symlink to a versioned file
Legacy MRU~/Library/Preferences/com.microsoft.office.plistOffice 2011-era keys such as 14\File MRU\MSWD; still present on upgraded Macs
AutoRecovery~/Library/Containers/com.microsoft.<App>/Data/Library/Preferences/AutoRecovery/Unsaved or recovered document copies
Outlook profile~/Library/Group Containers/UBF8T346G9.Office/Outlook/Outlook 15 Profiles/<Profile>/Data/Outlook.sqlite, message sources, attachments; newer Outlook versions add other stores

What it proves

  • A document was opened in an Office app from a specific path (local, external volume, network share or cloud folder), and when it was last used.
  • The document's creation date and the volume it was on, from the bookmark data.
  • The Office user name and initials configured for this account (from legacy keys), which end up in document metadata.
  • Unsaved work: AutoRecovery copies can hold content the user never saved.
  • Mail sent and received through Outlook, with folders, recipients and attachments, as cached locally.

Key fields

SourceFieldMeaning
securebookmarks plistdictionary keyFile URL of the document
securebookmarks plistkBookmarkDataKeyBookmark blob: path, volume name and UUID, file creation date, user name
securebookmarks plistkLastUsedDateKeyLast use of the document in that app
MicrosoftRegistrationDB.regHKEY_CURRENT_USER and HKEY_CURRENT_USER_values tablesKey path, value name, type, data
MicrosoftRegistrationDB.regwrite_timeKey last-write time
com.microsoft.office.plist14\UserInfo\UserName, 14\File MRU\*Legacy user info and MRU
Outlook Outlook.sqliteMail, Folders, Mail_OwnedBlocks and related tablesMessage metadata; bodies are in separate source files

The bookmark blob is the same format Finder uses in Recent Items, so the same parsers apply.

Timestamps

kLastUsedDateKey is a plist date (UTC). write_time in MicrosoftRegistrationDB.reg is a Windows FILETIME (100-nanosecond intervals since 1601-01-01 UTC), as decoded by mac_apt. Bookmark creation dates are Mac absolute time. Outlook database date columns vary by version; confirm the epoch against a known message.

Retention

  • Secure bookmarks accumulate per app and are pruned by Office; expect dozens to a few hundred entries.
  • The registry database persists across Office updates.
  • AutoRecovery files are removed when a document is saved or closed normally, and remain after a crash.
  • Outlook keeps what the account's sync window allows; Exchange and Microsoft 365 mailboxes can be synced for a limited period only.

Collection

for app in Word Excel Powerpoint; do
  sudo ditto "/Users/<user>/Library/Containers/com.microsoft.$app/Data/Library/Preferences" \
    "./case/office_<user>/$app"
done
sudo ditto "/Users/<user>/Library/Group Containers/UBF8T346G9.Office" ./case/office_gc_<user>

The group container can be large when Outlook caches mail. UAC collects com.microsoft.office.plist and the securebookmarks plists; mac_apt MSOFFICE parses all three MRU sources.

Parsing

python3 mac_apt.py -o out E01 image.E01 MSOFFICE
plutil -p ./case/office_<user>/Word/com.microsoft.Word.securebookmarks.plist | grep -E 'file://|kLastUsedDateKey'
sqlite3 -readonly MicrosoftRegistrationDB.reg '.tables'

Investigator tips

  • Paths under /Volumes/ show documents opened straight from USB drives or mounted images; match volume names with USB devices.
  • Paths under ~/Library/CloudStorage/ link documents to cloud storage clients.
  • Office documents downloaded from the web keep a quarantine record; macro-enabled files with a quarantine record and an MRU entry reconstruct a phishing chain.
  • The dock menu "Open Recent" list in Saved Application State is a second, independent MRU for Office apps.
  • Newer Outlook for Mac builds are moving to a different storage engine; if Outlook.sqlite is small or missing, look for other large files in the profile folder and treat the mailbox server as the authoritative source.

See also