Skip to content

User activityExecutionFile access

Saved Application State: macOS Window and Terminal History

macOS Saved Application State (.savedState) restores windows at relaunch and keeps window titles, open documents and even Terminal scrollback text.

Location
~/Library/Saved Application State/<bundle-id>.savedState/
Proves
Which apps were open with which windows, document titles and dock menu entries, and for Terminal, the text visible in each window
Timestamps
File system times of windows.plist and data.data (last state save)
Access
Owning user; readable from an image or with Full Disk Access
Retention
Rewritten while the app runs; kept after quit when Close windows when quitting an app is off; deleted on clean quit otherwise
Collection
mac_apt, ditto, Disk image

What it is

macOS "Resume" reopens apps with the same windows after a logout, restart or crash. To do that, each app using AppKit state restoration serialises its window state into a per-app .savedState folder. The window list is a plain plist, and the detailed state is in an encrypted blob whose keys sit right next to it.

For an investigator, that means window titles (often document names, web page titles or chat names), dock menu recent items and, for Terminal, the actual text of the terminal windows, including commands and output that never reached shell history.

Where it lives

SourcePathNotes
Non-sandboxed apps~/Library/Saved Application State/<bundle-id>.savedState/Terminal, many third-party apps
Sandboxed apps~/Library/Containers/<bundle-id>/Data/Library/Saved Application State/<bundle-id>.savedState/Apple apps and App Store apps; the top-level folder may hold a symlink
Window listwindows.plistPer-window NSTitle, NSWindowID, NSDataKey, NSDockMenu
Encrypted statedata.dataAES-encrypted records, keys from windows.plist
Restorable staterestorecount.plist and other small filesVaries by app and release

What it proves

  • An app was running for this user with specific windows, at or near the last save.
  • Window titles: document names, folder paths, page titles, remote host names in SSH or Screen Sharing windows.
  • Dock menu entries, including Microsoft Office "Open Recent" items, recorded by the app.
  • Terminal: the visible buffer of each window or tab, with commands and their output, restored from data.data.

It does not prove when each window was opened. The state is a snapshot, rewritten as the user works.

Key fields

windows.plist is an array, one dictionary per window:

KeyMeaning
NSTitleWindow title
NSWindowIDID matching records in data.data
NSDataKeyAES key for that window's records in data.data
NSDockMenuDock menu items (and sub items such as recent files)
NSIsFullScreen, NSWindowCloseButtonFrame and similarLayout data

data.data is a sequence of records that start with the magic NSCR1000, followed by a window ID and a length, then ciphertext decrypted with the matching NSDataKey (AES in CBC mode with an all-zero IV, as implemented in mac_apt). The decrypted payload is usually an NSKeyedArchiver plist containing the app's own restoration data.

Timestamps

There are no per-window timestamps. Use the modification time of windows.plist and data.data as "state last saved", and the folder's birth time as the first time that app saved state for the user (reset if the folder was deleted). Pair with KnowledgeC or Biome app focus records to date use of each app.

Retention

  • State is written while the app runs and on quit.
  • If the user quits normally with "Close windows when quitting an application" enabled (a System Settings option), the state is discarded; with Resume in effect, it persists.
  • Force quits, crashes and power loss leave the last state behind, which is often exactly the moment you care about.
  • Old .savedState folders for uninstalled apps can remain for years.

Collection

sudo ditto "/Users/<user>/Library/Saved Application State" ./case/SavedState_<user>
# Sandboxed apps
sudo find /Users/<user>/Library/Containers -path '*Saved Application State*' -maxdepth 6 \
  -exec ditto {} ./case/SavedState_containers_<user>/{} \;

Collect before logging the user out or restarting the Mac: a clean quit can erase the state you are after.

Parsing

# Window titles and dock menus
plutil -p "./case/SavedState_<user>/com.apple.Terminal.savedState/windows.plist"

# mac_apt: all apps, plus decrypted Terminal buffers
python3 mac_apt.py -o out E01 image.E01 SAVEDSTATE TERMINALSTATE

mac_apt's SAVEDSTATE plugin lists window titles and dock items for every app, including sandboxed containers. TERMINALSTATE decrypts com.apple.Terminal.savedState and exports the text of each window.

Investigator tips

  • Terminal saved state is one of the few places where command output survives on macOS: listing results, errors, credentials typed into prompts, curl responses.
  • Check it for root too (/private/var/root/Library/Saved Application State) and for third-party terminals such as iTerm2, which have their own state and session logs.
  • Browser window titles may be saved even for windows whose pages are not in history (for example private windows); test the specific browser and release before relying on it.
  • Compare Office dock menu recents with Recent Items and the Office MRU lists in Microsoft Office and Outlook.

See also