Skip to content

File accessUSB & devicesAnti-forensics

Time Machine Backups: macOS Configuration and History

Time Machine settings, destinations and backup sets on HFS+ and APFS disks: a source of older file versions and proof of when backups ran.

Location
/Library/Preferences/com.apple.TimeMachine.plist
Proves
Which backup destinations were used, when backups ran, and what files looked like at each backup
Timestamps
Backup names YYYY-MM-DD-HHMMSS; plist dates as plist date objects
Access
root plus Full Disk Access for tmutil listbackups and backup contents
Retention
Hourly 24 h, daily for a month, weekly after; oldest deleted when full
Collection
UAC, tmutil, Disk image

What it is

Time Machine is the built-in macOS backup system. It copies the Mac's volumes to an external disk or a network share on a schedule and keeps a history of backups. For an investigator it is two things at once:

  • Configuration and history on the Mac: which destinations were set up, which volumes and paths were excluded, and when backups completed.
  • An evidence source in its own right: the backup disk holds earlier versions of files, including files the user later deleted or changed on the Mac.

Short-lived local snapshots on the Mac's own disk are covered separately in APFS snapshots and timestamps.

Where it lives

ItemPath / locationNotes
Settings/Library/Preferences/com.apple.TimeMachine.plistDestinations, exclusions, auto backup flag
Sticky exclusionsxattr com.apple.metadata:com_apple_backup_excludeItem on the excluded itemSet by tmutil addexclusion (default mode); indexed by Spotlight
HFS+ backup disk (default before 11 Big Sur; existing disks can stay HFS+)/Volumes/<disk>/Backups.backupdb/<Mac name>/YYYY-MM-DD-HHMMSS/Hard-link based; Latest points to the newest backup
APFS backup disk (11 Big Sur and later)Each backup is an APFS snapshot named com.apple.TimeMachine.YYYY-MM-DD-HHMMSS.backupFinder shows them per datestamp under /Volumes/<backup volume>/; mounted backup snapshots appear under /Volumes/.timemachine/<UUID>/
Network destinationA disk image bundle (<Mac name>.sparsebundle) on the SMB shareContains an HFS+ or APFS backup volume; Catalina used the name .backupbundle for a while
Activity logsUnified Logs, subsystem com.apple.TimeMachineBackup start, destination, completion, errors

Protection: collect the preferences plist as root. tmutil listbackups and latestbackup require root and Full Disk Access. Backup disks can be encrypted, in which case you need the backup password to mount them.

What it proves

  • That backups were configured, to which destination (identifier, alias, network URL via tmutil destinationinfo).
  • Approximate dates of completed backups, from backup names and plist dates.
  • Content and metadata of files at each backup time, including deleted files.
  • Deliberate exclusions: folders or volumes kept out of backups, possibly to avoid leaving copies.

It does not prove:

  • Anything between backups. Short-lived files created and deleted within an hour may never appear.
  • That excluded or system paths had no content; they were simply not copied.

Key fields

com.apple.TimeMachine.plist (keys vary by macOS version):

KeyMeaning
DestinationsArray of configured destinations
Destinations/DestinationIDUUID of the destination
Destinations/BackupAliasAlias data pointing to the destination volume
Destinations/SnapshotDatesArray of backup dates (parsed by Plaso; not present on every version)
RootVolumeUUIDUUID of the backed-up boot volume
AutoBackupAutomatic backups enabled
SkipPathsFixed-path exclusions
IncludedVolumeUUIDs / ExcludedVolumeUUIDsVolumes included in or excluded from backup

On the backup disk, APFS destinations contain a hidden backup_manifest.plist describing backups by datestamp.

Timestamps

  • Backup folder and snapshot names use YYYY-MM-DD-HHMMSS. Confirm the Mac's time zone before converting.
  • Plist dates are native property list date objects (stored in UTC; plutil -p shows them with +0000).
  • Files inside a backup keep their original APFS or HFS+ timestamps, so you can compare them with the live copy.
  • Unified Log entries are in the log's own timestamp format; see Unified Logs.

Retention

Time Machine keeps hourly backups for the past 24 hours, daily backups for the past month and weekly backups for older months, and deletes the oldest when the disk is full (Apple Support). Since macOS 13 Ventura the user can change the backup frequency (for example to daily or weekly), so gaps are not necessarily suspicious. On APFS destinations, individual files cannot be deleted from a backup; on HFS+ they could be.

Collection

On the Mac (root, terminal with Full Disk Access):

plutil -p /Library/Preferences/com.apple.TimeMachine.plist
tmutil destinationinfo
sudo tmutil listbackups
sudo tmutil latestbackup
tmutil machinedirectory
log show --info --predicate 'subsystem == "com.apple.TimeMachine"' --last 7d > tm_log.txt
mdfind "com_apple_backup_excludeItem = com.apple.backupd"
  • UAC ir_triage runs tmutil listbackups, tmutil machinedirectory, tmutil listlocalsnapshots and tmutil listlocalsnapshotdates, and collects /Library/Preferences/*.plist.
  • Backup disks: seize and image the external disk, or copy the sparsebundle from the NAS share. Attach images read-only.
  • Ask for the backup disk early: it can hold months of history.

Parsing

  • Plaso has a time_machine plist plugin that extracts DestinationID, BackupAlias and SnapshotDates from com.apple.TimeMachine.plist.
  • plutil -p or Python plistlib for the settings; xattr -l to read sticky exclusions.
  • For backup contents, attach the evidence disk read-only to an analysis Mac and browse the dated backups, or use tmutil compare to list differences between two backup paths (take them from tmutil listbackups -d <mount point> -m on the analysis Mac):
sudo tmutil compare -a <backup_path_1> <backup_path_2>
  • On APFS destinations, list backup snapshots with diskutil apfs listSnapshots against the backup volume.

Investigator tips

  • Compare a file's backup copies with the live file to show when it changed or when timestamps were rewritten.
  • A deleted file on the Mac may still sit in several backups. Check FSEvents for the deletion window, then pick the backup just before it.
  • Exclusions added shortly before an incident deserve attention. SkipPaths and the com_apple_backup_excludeItem xattr (findable with mdfind) show them.
  • The destination volume name and connection times help tie a specific external drive to the Mac; correlate with USB devices.
  • One backup disk can hold several Macs. On HFS+ disks each has its own folder under Backups.backupdb.
  • Time Machine and local snapshots show up in FSEvents and Spotlight paths, which help date other activity.

See also