Skip to content

File accessUser activityExecution

Recent Items (.sfl2/.sfl3): macOS Shared File Lists

sharedfilelistd lists of recent documents, apps, servers and per-app Open Recent entries, stored as NSKeyedArchiver plists with bookmarks.

Location
~/Library/Application Support/com.apple.sharedfilelist/
Proves
Which documents, apps and servers a user recently opened, with full paths and source volumes
Timestamps
Mostly none per item; bookmark dates in Mac absolute time (2001 epoch)
Access
User-owned; Full Disk Access for the collector on a live system
Retention
Rolling lists capped by the Recent Items count (default 10)
Collection
UAC, mac_apt, Disk image, ditto

What it is

sharedfilelistd is a per-user agent that maintains the lists behind Apple menu > Recent Items, each application's File > Open Recent menu, parts of the Finder sidebar, and recent and favorite servers. It saves each list as a Shared File List file: a binary property list wrapping an NSKeyedArchiver object graph. Each entry carries a name and, for files, a bookmark blob that records the full path, the volume name and UUID, and creation dates.

These lists are classic "most recently used" (MRU) evidence. They show that a user opened a specific document, which may since have been deleted or lived on a USB stick or network share, and which app opened it.

Where it lives

All paths are per user under ~/Library/.

macOSPathFormat
10.10 and earlierPreferences/com.apple.recentitems.plist; per app Preferences/<bundle id>.LSSharedFileList.plistPlain plist (CustomListItems)
10.11 El Capitan, 10.12 SierraApplication Support/com.apple.sharedfilelist/*.sflNSKeyedArchiver, .sfl
10.13 High Sierra to 13 VenturaApplication Support/com.apple.sharedfilelist/*.sfl2NSKeyedArchiver, .sfl2
14 Sonoma and laterApplication Support/com.apple.sharedfilelist/*.sfl3Extension changed to .sfl3
10.11 and later, per appApplication Support/com.apple.sharedfilelist/com.apple.LSSharedFileList.ApplicationRecentDocuments/<bundle id>.sfl*One file per app

Typical global lists (prefix com.apple.LSSharedFileList.): RecentApplications, RecentDocuments, RecentServers, RecentHosts, FavoriteItems, FavoriteServers, FavoriteVolumes, ProjectsItems (Finder tags), iCloudItems, NetworkBrowser. Not every list exists on every version, and parsers also accept later extensions such as .sfl4.

Protection: the files belong to the user. On a live system, collect with a tool that has Full Disk Access.

What it proves

  • A document was opened recently through standard open or save flows, with its full path at the time (RecentDocuments, per-app ApplicationRecentDocuments).
  • Which app opened it: the per-app file name is the app's bundle ID.
  • Apps recently launched (RecentApplications) and servers connected via Finder (RecentServers, FavoriteServers).
  • The volume a file lived on (volume name, UUID, size, creation date in the bookmark), which ties files to external or network media.

It does not prove:

  • When a document was opened, for most lists. There is no per-item access time in RecentDocuments; you get list membership and order.
  • That the file still exists, or that it was read by anything other than the listed app.
  • Activity from command-line tools, which do not update these lists.

Key fields

.sfl2 / .sfl3 root object:

KeyMeaning
itemsArray of list entries
items[].NameDisplay name of the item
items[].uuidEntry identifier
items[].BookmarkBookmark blob (starts with book) resolving to the target
items[].CustomItemPropertiesOptional dictionary; some lists include com.apple.LSSharedFileList.DateLastSeen

Bookmark contents decoded by mac_apt: target path (or smb://, afp:// URL for network items), target file creation date, volume name, volume size, volume UUID, volume creation date.

Older .sfl files use a root with items and a version value; each item has name and a URL (NS.relative).

Timestamps

  • Bookmark dates (target creation, volume creation) are stored as big-endian doubles in Mac absolute time: seconds since 2001-01-01 00:00:00 UTC.
  • DateLastSeen, where present, is an archived date in the same epoch.
  • File system times of the .sfl* file: its modification time shows when that list last changed.
# Mac absolute time to UTC
date -u -r $(( 780000000 + 978307200 ))

Retention

Each list is capped by the "Recent items" count setting, which defaults to 10, so new entries push out old ones. Users can also clear recent lists from the menus. Older versions of the lists survive in snapshots and Time Machine backups.

Collection

# Live, terminal with Full Disk Access
ditto ~/Library/Application\ Support/com.apple.sharedfilelist /Volumes/CASE/MBP01/sharedfilelist_alice
stat -f "%Sm %N" -t "%Y-%m-%d %H:%M:%S %z" ~/Library/Application\ Support/com.apple.sharedfilelist/*.sfl* > /Volumes/CASE/MBP01/sfl_mtimes.txt
  • UAC collects the whole com.apple.sharedfilelist folder plus *.LSSharedFileList.plist, com.apple.recentitems.plist and com.apple.finder.plist (artifact files/system/macos_mru.yaml, in ir_triage).
  • mac_apt RECENTITEMS reads them for every user straight from an image.
  • Preserve file modification times; they are the main time anchor.

Parsing

mac_apt RECENTITEMS handles .sfl, .sfl2, .sfl3 and later extensions, decodes bookmarks, and also pulls related entries from com.apple.finder.plist, .GlobalPreferences.plist and com.apple.sidebarlists.plist:

python3 mac_apt.py -o /cases/MBP01/mac_apt E01 /cases/MBP01.E01 RECENTITEMS
python3 mac_apt_artifact_only.py -i /cases/MBP01/sharedfilelist_alice/com.apple.LSSharedFileList.RecentDocuments.sfl3 -o /cases/MBP01/out RECENTITEMS

Output columns include Type, Name, URL, Date Last Seen, Date Target Created, Volume Name, Volume UUID, Volume Creation Date, User and Source. mac_apt skips ProjectsItems lists, which only hold tag information.

For a quick look, plutil -p <file>.sfl3 prints the raw archive; bookmark blobs appear as hex data and need a parser.

Investigator tips

  • A path under /Volumes/<name>/ with a volume UUID ties a document to a specific external disk. Match the UUID with USB device evidence.
  • smb:// and afp:// entries in RecentServers show file-share connections; compare with Dock and Finder plists (FXConnectToLastURL).
  • A per-app list for a tool you did not expect (an archiver, a remote access app) is a lead even if the app is gone.
  • Add times from KnowledgeC or Biome app usage to place list entries in time.
  • Bookmarks store the path at creation; the file may have been renamed or moved since. Check Spotlight and FSEvents.

See also