File accessUSB & devicesAnti-forensics
Time Machine Backups: macOS Configuration and History
Time Machine settings, destinations and backup sets on HFS+ and APFS disks: a source of older file versions and proof of when backups ran.
- Location
- /Library/Preferences/com.apple.TimeMachine.plist
- Proves
- Which backup destinations were used, when backups ran, and what files looked like at each backup
- Timestamps
- Backup names YYYY-MM-DD-HHMMSS; plist dates as plist date objects
- Access
- root plus Full Disk Access for tmutil listbackups and backup contents
- Retention
- Hourly 24 h, daily for a month, weekly after; oldest deleted when full
- Collection
- UAC, tmutil, Disk image
Tools
Compare all tools- Disk Image ParserIn browser
- tmutilCLI · built into macOS
- PlasoCLI · open source
- plutilCLI · built into macOS
What it is
Time Machine is the built-in macOS backup system. It copies the Mac's volumes to an external disk or a network share on a schedule and keeps a history of backups. For an investigator it is two things at once:
- Configuration and history on the Mac: which destinations were set up, which volumes and paths were excluded, and when backups completed.
- An evidence source in its own right: the backup disk holds earlier versions of files, including files the user later deleted or changed on the Mac.
Short-lived local snapshots on the Mac's own disk are covered separately in APFS snapshots and timestamps.
Where it lives
| Item | Path / location | Notes |
|---|---|---|
| Settings | /Library/Preferences/com.apple.TimeMachine.plist | Destinations, exclusions, auto backup flag |
| Sticky exclusions | xattr com.apple.metadata:com_apple_backup_excludeItem on the excluded item | Set by tmutil addexclusion (default mode); indexed by Spotlight |
| HFS+ backup disk (default before 11 Big Sur; existing disks can stay HFS+) | /Volumes/<disk>/Backups.backupdb/<Mac name>/YYYY-MM-DD-HHMMSS/ | Hard-link based; Latest points to the newest backup |
| APFS backup disk (11 Big Sur and later) | Each backup is an APFS snapshot named com.apple.TimeMachine.YYYY-MM-DD-HHMMSS.backup | Finder shows them per datestamp under /Volumes/<backup volume>/; mounted backup snapshots appear under /Volumes/.timemachine/<UUID>/ |
| Network destination | A disk image bundle (<Mac name>.sparsebundle) on the SMB share | Contains an HFS+ or APFS backup volume; Catalina used the name .backupbundle for a while |
| Activity logs | Unified Logs, subsystem com.apple.TimeMachine | Backup start, destination, completion, errors |
Protection: collect the preferences plist as root. tmutil listbackups and latestbackup require root and Full Disk Access. Backup disks can be encrypted, in which case you need the backup password to mount them.
What it proves
- That backups were configured, to which destination (identifier, alias, network URL via
tmutil destinationinfo). - Approximate dates of completed backups, from backup names and plist dates.
- Content and metadata of files at each backup time, including deleted files.
- Deliberate exclusions: folders or volumes kept out of backups, possibly to avoid leaving copies.
It does not prove:
- Anything between backups. Short-lived files created and deleted within an hour may never appear.
- That excluded or system paths had no content; they were simply not copied.
Key fields
com.apple.TimeMachine.plist (keys vary by macOS version):
| Key | Meaning |
|---|---|
Destinations | Array of configured destinations |
Destinations/DestinationID | UUID of the destination |
Destinations/BackupAlias | Alias data pointing to the destination volume |
Destinations/SnapshotDates | Array of backup dates (parsed by Plaso; not present on every version) |
RootVolumeUUID | UUID of the backed-up boot volume |
AutoBackup | Automatic backups enabled |
SkipPaths | Fixed-path exclusions |
IncludedVolumeUUIDs / ExcludedVolumeUUIDs | Volumes included in or excluded from backup |
On the backup disk, APFS destinations contain a hidden backup_manifest.plist describing backups by datestamp.
Timestamps
- Backup folder and snapshot names use
YYYY-MM-DD-HHMMSS. Confirm the Mac's time zone before converting. - Plist dates are native property list date objects (stored in UTC;
plutil -pshows them with+0000). - Files inside a backup keep their original APFS or HFS+ timestamps, so you can compare them with the live copy.
- Unified Log entries are in the log's own timestamp format; see Unified Logs.
Retention
Time Machine keeps hourly backups for the past 24 hours, daily backups for the past month and weekly backups for older months, and deletes the oldest when the disk is full (Apple Support). Since macOS 13 Ventura the user can change the backup frequency (for example to daily or weekly), so gaps are not necessarily suspicious. On APFS destinations, individual files cannot be deleted from a backup; on HFS+ they could be.
Collection
On the Mac (root, terminal with Full Disk Access):
plutil -p /Library/Preferences/com.apple.TimeMachine.plist
tmutil destinationinfo
sudo tmutil listbackups
sudo tmutil latestbackup
tmutil machinedirectory
log show --info --predicate 'subsystem == "com.apple.TimeMachine"' --last 7d > tm_log.txt
mdfind "com_apple_backup_excludeItem = com.apple.backupd"
- UAC
ir_triagerunstmutil listbackups,tmutil machinedirectory,tmutil listlocalsnapshotsandtmutil listlocalsnapshotdates, and collects/Library/Preferences/*.plist. - Backup disks: seize and image the external disk, or copy the sparsebundle from the NAS share. Attach images read-only.
- Ask for the backup disk early: it can hold months of history.
Parsing
- Plaso has a
time_machineplist plugin that extractsDestinationID,BackupAliasandSnapshotDatesfromcom.apple.TimeMachine.plist. plutil -por Pythonplistlibfor the settings;xattr -lto read sticky exclusions.- For backup contents, attach the evidence disk read-only to an analysis Mac and browse the dated backups, or use
tmutil compareto list differences between two backup paths (take them fromtmutil listbackups -d <mount point> -mon the analysis Mac):
sudo tmutil compare -a <backup_path_1> <backup_path_2>
- On APFS destinations, list backup snapshots with
diskutil apfs listSnapshotsagainst the backup volume.
Investigator tips
- Compare a file's backup copies with the live file to show when it changed or when timestamps were rewritten.
- A deleted file on the Mac may still sit in several backups. Check FSEvents for the deletion window, then pick the backup just before it.
- Exclusions added shortly before an incident deserve attention.
SkipPathsand thecom_apple_backup_excludeItemxattr (findable withmdfind) show them. - The destination volume name and connection times help tie a specific external drive to the Mac; correlate with USB devices.
- One backup disk can hold several Macs. On HFS+ disks each has its own folder under
Backups.backupdb. - Time Machine and local snapshots show up in FSEvents and Spotlight paths, which help date other activity.