File accessUser activityExecution
Recent Items (.sfl2/.sfl3): macOS Shared File Lists
sharedfilelistd lists of recent documents, apps, servers and per-app Open Recent entries, stored as NSKeyedArchiver plists with bookmarks.
- Location
- ~/Library/Application Support/com.apple.sharedfilelist/
- Proves
- Which documents, apps and servers a user recently opened, with full paths and source volumes
- Timestamps
- Mostly none per item; bookmark dates in Mac absolute time (2001 epoch)
- Access
- User-owned; Full Disk Access for the collector on a live system
- Retention
- Rolling lists capped by the Recent Items count (default 10)
- Collection
- UAC, mac_apt, Disk image, ditto
Tools
Compare all tools- mac_aptCLI · open source
- plutilCLI · built into macOS
What it is
sharedfilelistd is a per-user agent that maintains the lists behind Apple menu > Recent Items, each application's File > Open Recent menu, parts of the Finder sidebar, and recent and favorite servers. It saves each list as a Shared File List file: a binary property list wrapping an NSKeyedArchiver object graph. Each entry carries a name and, for files, a bookmark blob that records the full path, the volume name and UUID, and creation dates.
These lists are classic "most recently used" (MRU) evidence. They show that a user opened a specific document, which may since have been deleted or lived on a USB stick or network share, and which app opened it.
Where it lives
All paths are per user under ~/Library/.
| macOS | Path | Format |
|---|---|---|
| 10.10 and earlier | Preferences/com.apple.recentitems.plist; per app Preferences/<bundle id>.LSSharedFileList.plist | Plain plist (CustomListItems) |
| 10.11 El Capitan, 10.12 Sierra | Application Support/com.apple.sharedfilelist/*.sfl | NSKeyedArchiver, .sfl |
| 10.13 High Sierra to 13 Ventura | Application Support/com.apple.sharedfilelist/*.sfl2 | NSKeyedArchiver, .sfl2 |
| 14 Sonoma and later | Application Support/com.apple.sharedfilelist/*.sfl3 | Extension changed to .sfl3 |
| 10.11 and later, per app | Application Support/com.apple.sharedfilelist/com.apple.LSSharedFileList.ApplicationRecentDocuments/<bundle id>.sfl* | One file per app |
Typical global lists (prefix com.apple.LSSharedFileList.): RecentApplications, RecentDocuments, RecentServers, RecentHosts, FavoriteItems, FavoriteServers, FavoriteVolumes, ProjectsItems (Finder tags), iCloudItems, NetworkBrowser. Not every list exists on every version, and parsers also accept later extensions such as .sfl4.
Protection: the files belong to the user. On a live system, collect with a tool that has Full Disk Access.
What it proves
- A document was opened recently through standard open or save flows, with its full path at the time (
RecentDocuments, per-appApplicationRecentDocuments). - Which app opened it: the per-app file name is the app's bundle ID.
- Apps recently launched (
RecentApplications) and servers connected via Finder (RecentServers,FavoriteServers). - The volume a file lived on (volume name, UUID, size, creation date in the bookmark), which ties files to external or network media.
It does not prove:
- When a document was opened, for most lists. There is no per-item access time in
RecentDocuments; you get list membership and order. - That the file still exists, or that it was read by anything other than the listed app.
- Activity from command-line tools, which do not update these lists.
Key fields
.sfl2 / .sfl3 root object:
| Key | Meaning |
|---|---|
items | Array of list entries |
items[].Name | Display name of the item |
items[].uuid | Entry identifier |
items[].Bookmark | Bookmark blob (starts with book) resolving to the target |
items[].CustomItemProperties | Optional dictionary; some lists include com.apple.LSSharedFileList.DateLastSeen |
Bookmark contents decoded by mac_apt: target path (or smb://, afp:// URL for network items), target file creation date, volume name, volume size, volume UUID, volume creation date.
Older .sfl files use a root with items and a version value; each item has name and a URL (NS.relative).
Timestamps
- Bookmark dates (target creation, volume creation) are stored as big-endian doubles in Mac absolute time: seconds since 2001-01-01 00:00:00 UTC.
DateLastSeen, where present, is an archived date in the same epoch.- File system times of the
.sfl*file: its modification time shows when that list last changed.
# Mac absolute time to UTC
date -u -r $(( 780000000 + 978307200 ))
Retention
Each list is capped by the "Recent items" count setting, which defaults to 10, so new entries push out old ones. Users can also clear recent lists from the menus. Older versions of the lists survive in snapshots and Time Machine backups.
Collection
# Live, terminal with Full Disk Access
ditto ~/Library/Application\ Support/com.apple.sharedfilelist /Volumes/CASE/MBP01/sharedfilelist_alice
stat -f "%Sm %N" -t "%Y-%m-%d %H:%M:%S %z" ~/Library/Application\ Support/com.apple.sharedfilelist/*.sfl* > /Volumes/CASE/MBP01/sfl_mtimes.txt
- UAC collects the whole
com.apple.sharedfilelistfolder plus*.LSSharedFileList.plist,com.apple.recentitems.plistandcom.apple.finder.plist(artifactfiles/system/macos_mru.yaml, inir_triage). - mac_apt
RECENTITEMSreads them for every user straight from an image. - Preserve file modification times; they are the main time anchor.
Parsing
mac_apt RECENTITEMS handles .sfl, .sfl2, .sfl3 and later extensions, decodes bookmarks, and also pulls related entries from com.apple.finder.plist, .GlobalPreferences.plist and com.apple.sidebarlists.plist:
python3 mac_apt.py -o /cases/MBP01/mac_apt E01 /cases/MBP01.E01 RECENTITEMS
python3 mac_apt_artifact_only.py -i /cases/MBP01/sharedfilelist_alice/com.apple.LSSharedFileList.RecentDocuments.sfl3 -o /cases/MBP01/out RECENTITEMS
Output columns include Type, Name, URL, Date Last Seen, Date Target Created, Volume Name, Volume UUID, Volume Creation Date, User and Source. mac_apt skips ProjectsItems lists, which only hold tag information.
For a quick look, plutil -p <file>.sfl3 prints the raw archive; bookmark blobs appear as hex data and need a parser.
Investigator tips
- A path under
/Volumes/<name>/with a volume UUID ties a document to a specific external disk. Match the UUID with USB device evidence. smb://andafp://entries inRecentServersshow file-share connections; compare with Dock and Finder plists (FXConnectToLastURL).- A per-app list for a tool you did not expect (an archiver, a remote access app) is a lead even if the app is gone.
- Add times from KnowledgeC or Biome app usage to place list entries in time.
- Bookmarks store the path at creation; the file may have been renamed or moved since. Check Spotlight and FSEvents.