Screen Sharing and Apple Remote Desktop Artifacts
macOS Screen Sharing and Apple Remote Desktop leave connection history, screensharingd log events and ARD caches that show remote control of a Mac.
- Location
- /private/var/db/RemoteManagement/ and ~/Library/Containers/com.apple.ScreenSharing/
- Proves
- Who connected to this Mac over VNC / Screen Sharing or ARD, from which address and when, and which hosts this Mac's user controlled
- Timestamps
- Unified Log entries in UTC; plist dates and ARD caches in Mac absolute time
- Access
- root for /private/var/db/RemoteManagement and the log store; owning user for the Screen Sharing container
- Retention
- Log events follow Unified Log rotation; connection history and ARD caches persist until cleared
- Collection
- Aftermath, log collect, mac_apt, ditto
Tools
Compare all tools- logCLI · built into macOS
- mac_aptCLI · open source
- plutilCLI · built into macOS
- macos-UnifiedLogsLibrary · open source
What it is
macOS has two built-in remote control services that share the same VNC-based engine:
- Screen Sharing (System Settings, Sharing), served by
screensharingd. Any VNC client can connect if "VNC viewers may control screen with password" is enabled. - Remote Management, the Apple Remote Desktop (ARD) agent, which adds inventory, file copy and remote command execution. It is widely used by MDM and IT teams, and abused by intruders because it gives full GUI control.
The client side is the Screen Sharing app (and the ARD admin app), which keeps a history of the hosts it connected to. Third-party tools (TeamViewer, AnyDesk, Splashtop and others) are separate products with their own logs and launchd jobs.
Where it lives
| Source | Path | Notes |
|---|---|---|
| Server log events | Unified Logs, processes screensharingd, ScreensharingAgent | Authentication and session start/stop |
| ARD agent settings | /Library/Preferences/com.apple.RemoteManagement.plist | Allowed users, privileges, VNC settings |
| ARD app usage cache | /private/var/db/RemoteManagement/caches/AppUsage.plist (or .tmp) | Per-app launch records collected for ARD reporting |
| ARD user cache | /private/var/db/RemoteManagement/caches/UserAcct.tmp | Logon sessions collected for ARD reporting |
| Service state | /private/var/db/com.apple.xpc.launchd/disabled.plist | com.apple.screensharing key |
| Client history | ~/Library/Containers/com.apple.ScreenSharing/Data/Library/Preferences/com.apple.ScreenSharing.plist | Hosts, user names, last connection |
| Privacy grants | TCC.db | Screen recording and accessibility for third-party remote tools |
What it proves
- An inbound Screen Sharing or ARD session: successful or failed authentication, the viewer's IP address and the account used.
- That the ARD agent was enabled and which local users or directory groups were allowed to use it.
- Applications launched and users logged on while ARD reporting was active, from the ARD caches.
- Outbound control: hosts the user connected to from the Screen Sharing app, with login name and last connection date.
Screen Sharing sessions do not produce a Terminal or shell history trail: what the remote user did must be reconstructed from app usage (KnowledgeC, Biome), file system activity and the other artifacts on this site.
Key fields
screensharingd authentication messages take a form similar to:
Authentication: SUCCEEDED :: User Name: <name> :: Viewer Address: 192.0.2.15 :: Type: DH
Authentication: FAILED :: User Name: <name> :: Viewer Address: 192.0.2.15 :: Type: DH
The exact wording and the Type value (for example DH for Apple authentication, VNC for password-only VNC clients) vary by release; build predicates on process and loose CONTAINS terms.
| Source | Fields |
|---|---|
com.apple.ScreenSharing.plist (connectionsStore, recent releases) | Host UUID, address, username, displayName, group, lastConnectedDate |
AppUsage.plist | App path, Name, runData with Launched, runLength, Frontmost, wasQuit, userName |
UserAcct.tmp | Per user: uid, then per session type (console or tty) a list with inTime and outTime |
mac_apt's SCREENSHARING plugin parses the connectionsStore structure used by the redesigned Screen Sharing app. Older releases stored client history differently, so check the plist by hand if the plugin returns nothing.
Timestamps
Unified Log entries carry UTC instants. Launched, inTime and outTime values in the ARD caches and lastConnectedDate are Mac absolute time or plist dates; runLength is a duration in seconds. The modification time of com.apple.RemoteManagement.plist approximates the last change to ARD settings.
Retention
screensharingdevents follow Unified Log rotation; collect a log archive early.- ARD caches are refreshed by the agent while it runs and can hold weeks of app usage. They exist only where Remote Management was enabled.
- Client history persists until the user removes hosts from the Screen Sharing app.
Collection
sudo log collect --output ./case/host.logarchive
sudo ditto /private/var/db/RemoteManagement ./case/RemoteManagement
sudo ditto /Library/Preferences/com.apple.RemoteManagement.plist ./case/
sudo ditto "/Users/<user>/Library/Containers/com.apple.ScreenSharing" ./case/ScreenSharing_<user>
Aftermath runs a default screensharing predicate (screensharingd or ScreensharingAgent). mac_apt has ARD and SCREENSHARING plugins.
Parsing
# Inbound authentication, UTC
log show --archive host.logarchive --timezone UTC --style syslog \
--predicate '(process == "screensharingd" OR process == "ScreensharingAgent")
AND eventMessage CONTAINS[c] "authentication"'
# ARD settings and caches
plutil -p ./case/com.apple.RemoteManagement.plist
python3 mac_apt.py -o out E01 image.E01 ARD SCREENSHARING
Investigator tips
- Remote Management enabled with "All users" and full privileges on a Mac that is not IT-managed is a red flag; look for the
kickstartcommand (ARDAgent.app/Contents/Resources/kickstart) in shell history and sudo logs. - A burst of
FAILEDauthentications from one address followed by aSUCCEEDEDis password guessing that worked. - For third-party remote tools, check their launchd jobs in launch agents and daemons, their logs under
/Library/Logsand~/Library/Logs, and the Screen Recording and Accessibility grants in TCC. - Correlate session times with SSH logons: intruders often use one to enable the other.