User activityExecutionFile access
Saved Application State: macOS Window and Terminal History
macOS Saved Application State (.savedState) restores windows at relaunch and keeps window titles, open documents and even Terminal scrollback text.
- Location
- ~/Library/Saved Application State/<bundle-id>.savedState/
- Proves
- Which apps were open with which windows, document titles and dock menu entries, and for Terminal, the text visible in each window
- Timestamps
- File system times of windows.plist and data.data (last state save)
- Access
- Owning user; readable from an image or with Full Disk Access
- Retention
- Rewritten while the app runs; kept after quit when Close windows when quitting an app is off; deleted on clean quit otherwise
- Collection
- mac_apt, ditto, Disk image
Tools
Compare all tools- mac_aptCLI · open source
- plutilCLI · built into macOS
What it is
macOS "Resume" reopens apps with the same windows after a logout, restart or crash. To do that, each app using AppKit state restoration serialises its window state into a per-app .savedState folder. The window list is a plain plist, and the detailed state is in an encrypted blob whose keys sit right next to it.
For an investigator, that means window titles (often document names, web page titles or chat names), dock menu recent items and, for Terminal, the actual text of the terminal windows, including commands and output that never reached shell history.
Where it lives
| Source | Path | Notes |
|---|---|---|
| Non-sandboxed apps | ~/Library/Saved Application State/<bundle-id>.savedState/ | Terminal, many third-party apps |
| Sandboxed apps | ~/Library/Containers/<bundle-id>/Data/Library/Saved Application State/<bundle-id>.savedState/ | Apple apps and App Store apps; the top-level folder may hold a symlink |
| Window list | windows.plist | Per-window NSTitle, NSWindowID, NSDataKey, NSDockMenu |
| Encrypted state | data.data | AES-encrypted records, keys from windows.plist |
| Restorable state | restorecount.plist and other small files | Varies by app and release |
What it proves
- An app was running for this user with specific windows, at or near the last save.
- Window titles: document names, folder paths, page titles, remote host names in SSH or Screen Sharing windows.
- Dock menu entries, including Microsoft Office "Open Recent" items, recorded by the app.
- Terminal: the visible buffer of each window or tab, with commands and their output, restored from
data.data.
It does not prove when each window was opened. The state is a snapshot, rewritten as the user works.
Key fields
windows.plist is an array, one dictionary per window:
| Key | Meaning |
|---|---|
NSTitle | Window title |
NSWindowID | ID matching records in data.data |
NSDataKey | AES key for that window's records in data.data |
NSDockMenu | Dock menu items (and sub items such as recent files) |
NSIsFullScreen, NSWindowCloseButtonFrame and similar | Layout data |
data.data is a sequence of records that start with the magic NSCR1000, followed by a window ID and a length, then ciphertext decrypted with the matching NSDataKey (AES in CBC mode with an all-zero IV, as implemented in mac_apt). The decrypted payload is usually an NSKeyedArchiver plist containing the app's own restoration data.
Timestamps
There are no per-window timestamps. Use the modification time of windows.plist and data.data as "state last saved", and the folder's birth time as the first time that app saved state for the user (reset if the folder was deleted). Pair with KnowledgeC or Biome app focus records to date use of each app.
Retention
- State is written while the app runs and on quit.
- If the user quits normally with "Close windows when quitting an application" enabled (a System Settings option), the state is discarded; with Resume in effect, it persists.
- Force quits, crashes and power loss leave the last state behind, which is often exactly the moment you care about.
- Old
.savedStatefolders for uninstalled apps can remain for years.
Collection
sudo ditto "/Users/<user>/Library/Saved Application State" ./case/SavedState_<user>
# Sandboxed apps
sudo find /Users/<user>/Library/Containers -path '*Saved Application State*' -maxdepth 6 \
-exec ditto {} ./case/SavedState_containers_<user>/{} \;
Collect before logging the user out or restarting the Mac: a clean quit can erase the state you are after.
Parsing
# Window titles and dock menus
plutil -p "./case/SavedState_<user>/com.apple.Terminal.savedState/windows.plist"
# mac_apt: all apps, plus decrypted Terminal buffers
python3 mac_apt.py -o out E01 image.E01 SAVEDSTATE TERMINALSTATE
mac_apt's SAVEDSTATE plugin lists window titles and dock items for every app, including sandboxed containers. TERMINALSTATE decrypts com.apple.Terminal.savedState and exports the text of each window.
Investigator tips
- Terminal saved state is one of the few places where command output survives on macOS: listing results, errors, credentials typed into prompts,
curlresponses. - Check it for
roottoo (/private/var/root/Library/Saved Application State) and for third-party terminals such as iTerm2, which have their own state and session logs. - Browser window titles may be saved even for windows whose pages are not in history (for example private windows); test the specific browser and release before relying on it.
- Compare Office dock menu recents with Recent Items and the Office MRU lists in Microsoft Office and Outlook.