Skip to content

NetworkLogsExecution

Screen Sharing and Apple Remote Desktop Artifacts

macOS Screen Sharing and Apple Remote Desktop leave connection history, screensharingd log events and ARD caches that show remote control of a Mac.

Location
/private/var/db/RemoteManagement/ and ~/Library/Containers/com.apple.ScreenSharing/
Proves
Who connected to this Mac over VNC / Screen Sharing or ARD, from which address and when, and which hosts this Mac's user controlled
Timestamps
Unified Log entries in UTC; plist dates and ARD caches in Mac absolute time
Access
root for /private/var/db/RemoteManagement and the log store; owning user for the Screen Sharing container
Retention
Log events follow Unified Log rotation; connection history and ARD caches persist until cleared
Collection
Aftermath, log collect, mac_apt, ditto

What it is

macOS has two built-in remote control services that share the same VNC-based engine:

  • Screen Sharing (System Settings, Sharing), served by screensharingd. Any VNC client can connect if "VNC viewers may control screen with password" is enabled.
  • Remote Management, the Apple Remote Desktop (ARD) agent, which adds inventory, file copy and remote command execution. It is widely used by MDM and IT teams, and abused by intruders because it gives full GUI control.

The client side is the Screen Sharing app (and the ARD admin app), which keeps a history of the hosts it connected to. Third-party tools (TeamViewer, AnyDesk, Splashtop and others) are separate products with their own logs and launchd jobs.

Where it lives

SourcePathNotes
Server log eventsUnified Logs, processes screensharingd, ScreensharingAgentAuthentication and session start/stop
ARD agent settings/Library/Preferences/com.apple.RemoteManagement.plistAllowed users, privileges, VNC settings
ARD app usage cache/private/var/db/RemoteManagement/caches/AppUsage.plist (or .tmp)Per-app launch records collected for ARD reporting
ARD user cache/private/var/db/RemoteManagement/caches/UserAcct.tmpLogon sessions collected for ARD reporting
Service state/private/var/db/com.apple.xpc.launchd/disabled.plistcom.apple.screensharing key
Client history~/Library/Containers/com.apple.ScreenSharing/Data/Library/Preferences/com.apple.ScreenSharing.plistHosts, user names, last connection
Privacy grantsTCC.dbScreen recording and accessibility for third-party remote tools

What it proves

  • An inbound Screen Sharing or ARD session: successful or failed authentication, the viewer's IP address and the account used.
  • That the ARD agent was enabled and which local users or directory groups were allowed to use it.
  • Applications launched and users logged on while ARD reporting was active, from the ARD caches.
  • Outbound control: hosts the user connected to from the Screen Sharing app, with login name and last connection date.

Screen Sharing sessions do not produce a Terminal or shell history trail: what the remote user did must be reconstructed from app usage (KnowledgeC, Biome), file system activity and the other artifacts on this site.

Key fields

screensharingd authentication messages take a form similar to:

Authentication: SUCCEEDED :: User Name: <name> :: Viewer Address: 192.0.2.15 :: Type: DH
Authentication: FAILED :: User Name: <name> :: Viewer Address: 192.0.2.15 :: Type: DH

The exact wording and the Type value (for example DH for Apple authentication, VNC for password-only VNC clients) vary by release; build predicates on process and loose CONTAINS terms.

SourceFields
com.apple.ScreenSharing.plist (connectionsStore, recent releases)Host UUID, address, username, displayName, group, lastConnectedDate
AppUsage.plistApp path, Name, runData with Launched, runLength, Frontmost, wasQuit, userName
UserAcct.tmpPer user: uid, then per session type (console or tty) a list with inTime and outTime

mac_apt's SCREENSHARING plugin parses the connectionsStore structure used by the redesigned Screen Sharing app. Older releases stored client history differently, so check the plist by hand if the plugin returns nothing.

Timestamps

Unified Log entries carry UTC instants. Launched, inTime and outTime values in the ARD caches and lastConnectedDate are Mac absolute time or plist dates; runLength is a duration in seconds. The modification time of com.apple.RemoteManagement.plist approximates the last change to ARD settings.

Retention

  • screensharingd events follow Unified Log rotation; collect a log archive early.
  • ARD caches are refreshed by the agent while it runs and can hold weeks of app usage. They exist only where Remote Management was enabled.
  • Client history persists until the user removes hosts from the Screen Sharing app.

Collection

sudo log collect --output ./case/host.logarchive
sudo ditto /private/var/db/RemoteManagement ./case/RemoteManagement
sudo ditto /Library/Preferences/com.apple.RemoteManagement.plist ./case/
sudo ditto "/Users/<user>/Library/Containers/com.apple.ScreenSharing" ./case/ScreenSharing_<user>

Aftermath runs a default screensharing predicate (screensharingd or ScreensharingAgent). mac_apt has ARD and SCREENSHARING plugins.

Parsing

# Inbound authentication, UTC
log show --archive host.logarchive --timezone UTC --style syslog \
  --predicate '(process == "screensharingd" OR process == "ScreensharingAgent")
               AND eventMessage CONTAINS[c] "authentication"'

# ARD settings and caches
plutil -p ./case/com.apple.RemoteManagement.plist
python3 mac_apt.py -o out E01 image.E01 ARD SCREENSHARING

Investigator tips

  • Remote Management enabled with "All users" and full privileges on a Mac that is not IT-managed is a red flag; look for the kickstart command (ARDAgent.app/Contents/Resources/kickstart) in shell history and sudo logs.
  • A burst of FAILED authentications from one address followed by a SUCCEEDED is password guessing that worked.
  • For third-party remote tools, check their launchd jobs in launch agents and daemons, their logs under /Library/Logs and ~/Library/Logs, and the Screen Recording and Accessibility grants in TCC.
  • Correlate session times with SSH logons: intruders often use one to enable the other.

See also