USB Devices: macOS Removable Media History
macOS keeps no USB registry: rebuild removable media history from Unified Logs, DiskArbitration mounts, FSEvents, Spotlight and the device itself.
- Location
- /private/var/db/diagnostics/
- Proves
- Which USB storage devices were attached, when volumes were mounted, and which files were touched on them
- Timestamps
- Unified Logs UTC instants; FSEvents has no per-record time
- Access
- root for the log store and .fseventsd; live commands need no special rights
- Retention
- Unified Log rotation (days to weeks); FSEvents until pages are purged
- Collection
- log collect, system_profiler, UAC, Aftermath
Tools
Compare all toolsWhat it is
Unlike Windows, macOS has no persistent registry of every USB device ever connected. Device history has to be rebuilt from events: kernel and DiskArbitration messages in the Unified Logs, file system journals on the host, and metadata that macOS writes onto the removable volume itself. On a live system, the IOKit registry shows what is attached right now.
The strongest single source is the Unified Log, but it rotates. Everything else (FSEvents, Spotlight, recent items, Finder preferences) proves that a volume was mounted or used, usually by volume name rather than by serial number.
Where it lives
| Source | Path or command | Versions / notes |
|---|---|---|
| Kernel USB mass storage entries | Unified Logs, eventMessage CONTAINS "USBMSC" | Documented from Sierra; wording varies, verify per release |
| Mount and unmount events | Unified Logs, subsystem com.apple.DiskArbitration.diskarbitrationd | Verified on 26 Tahoe |
| Currently attached devices | system_profiler SPUSBDataType | Earlier releases; confirm with system_profiler -listDataTypes |
| Currently attached devices | system_profiler SPUSBHostDataType | 26 Tahoe (verified on 26.6, where the old type is gone) |
| IOKit registry, live | ioreg -p IOUSB -l -w0 | All; shows idVendor, idProduct, USB Serial Number, USB Product Name |
| Host FSEvents | /System/Volumes/Data/.fseventsd/ | Paths under /Volumes/<name> |
| FSEvents on the device | <volume>/.fseventsd/ | Written if the volume format and settings allow |
| Spotlight on the device | <volume>/.Spotlight-V100/ | Only if indexing was allowed |
The Unified Log store and host .fseventsd need root. Reading a removable volume is best done from a write-blocked copy.
What it proves
- A USB mass storage device with a given serial-like identifier, vendor ID and product ID was attached at a time (kernel
USBMSCentries). - A disk was probed, mounted and unmounted, with BSD device node (
/dev/disk6s2) and file system type (DiskArbitration messages). - Files and folders under
/Volumes/<name>were created, renamed or deleted (host FSEvents), and which host activity touched the device (the device's own FSEvents and Spotlight store). - A volume appeared in recent items or Finder preferences, showing user interaction.
It does not prove that a specific person copied data, and a USBMSC identifier is "non-unique" by design: it is usually the serial number, but some devices report none or a shared value. Mounted disk images also create DiskArbitration events; separate them by device node, file system and the requesting process (for example hdiutil).
Key fields
| Source | Field | Meaning |
|---|---|---|
USBMSC entry | identifier, vendor ID, product ID, version | Serial-like ID and hex VID, PID, device release |
| DiskArbitration | probed disk, id = /dev/diskN, with <fs> | New disk seen and its file system (msdos_fskit, exfat, hfs, apfs, ...) |
| DiskArbitration | mounted disk / unmounted disk ... success | Mount and unmount outcome |
ioreg / system_profiler | idVendor, idProduct, USB Serial Number, Location ID, Link Speed | Live device identity and port |
| FSEvents | path, flags, event ID | /Volumes/<name>/... activity |
Timestamps
Unified Log entries give UTC instants; always print with --timezone UTC. FSEvents records carry no time: date them through event ID ordering, page file times and anchoring log events. FAT-formatted media store local time without a zone (2-second resolution for modification times), so compare them with host UTC timestamps carefully.
Retention
- Unified Logs: size-based rotation, often days to a few weeks. This is the main limit for device history.
- FSEvents: pages persist until purged; see FSEvents.
- Device-side
.fseventsdand.Spotlight-V100stay on the media until it is reformatted or the folders are deleted. system_profilerandioregshow only what is connected at collection time.
Collection
# Live snapshot of attached devices (Tahoe and later / earlier)
system_profiler SPUSBHostDataType -json > usb_now.json 2>/dev/null || \
system_profiler SPUSBDataType -json > usb_now.json
ioreg -p IOUSB -l -w0 > ioreg_usb.txt
# Logs
sudo log collect --output /Volumes/EVIDENCE/host.logarchive
- UAC runs
system_profiler(full report) and collects.fseventsd, Unified Logs and/private/var/log. - Aftermath collects
/var/logfiles and runs Unified Log predicates; add a USB predicate file with--logs. - Image the removable device separately if available, to get its
.fseventsd,.Spotlight-V100and file system timestamps.
Parsing
# USB mass storage arrivals
log show --archive host.logarchive --timezone UTC --style syslog \
--predicate 'eventMessage CONTAINS "USBMSC"'
# Mounts, unmounts and probes (verified on macOS 26)
log show --archive host.logarchive --timezone UTC --style syslog \
--predicate 'subsystem == "com.apple.DiskArbitration.diskarbitrationd"
AND (eventMessage CONTAINS "mounted disk" OR eventMessage CONTAINS "probed disk")'
- macos-UnifiedLogs (
unifiedlog_iterator) for offline parsing on any OS, then filter the JSONL forUSBMSCanddiskarbitrationd. - FSEventsParser (David Cowen, github.com/dlcowen/FSEventsParser) or mac_apt
FSEVENTSfor host and device.fseventsd; filter for/Volumes/. - mac_apt
SPOTLIGHTor spotlight_parser for a device's.Spotlight-V100.
Unified Log Parser opens a .logarchive, the diagnostics and uuidtext folders or a log show export in the browser, applies DFIR triage rules and exports CSV or Timesketch; nothing is uploaded.
Investigator tips
- Build the chain:
USBMSCarrival, thenprobed diskandmounted diskfor the new/dev/diskNwithin seconds, then FSEvents under/Volumes/<name>, thenunmounted disk. - Record VID and PID in hex and look them up in the USB ID database; the identifier alone may not be unique.
- USB devices that are not mass storage (keyboards, network adapters, phones) do not produce
USBMSCentries. Broaden the predicate tokernelandIOUSBHostsenders if you need them, and check wording on the target release. - Tahoe renamed the
system_profilerdata type toSPUSBHostDataType; scripts that callSPUSBDataTypesilently return nothing there. - Volume names can be reused across devices. Tie FSEvents and recent items to the log timeline before naming a device.
- If the media is available, its
.Spotlight-V100(see Spotlight store) can list files that were on it when this or another Mac indexed it.