Wi-Fi Known Networks on macOS: Plists and Logs
macOS known Wi-Fi networks in com.apple.wifi.known-networks.plist, airport preferences, wifi.log and Unified Logs: where a Mac has connected, and when.
- Location
- /Library/Preferences/com.apple.wifi.known-networks.plist
- Proves
- Which Wi-Fi networks and access points a Mac joined, when first added, and when last joined by the user or system
- Timestamps
- Plist date objects (stored as Mac absolute time, shown in UTC); wifi.log in local time
- Access
- root (known-networks plist is 0600 root:wheel on current macOS)
- Retention
- Known networks until the user forgets them; wifi.log rotated daily, about 10 archives
- Collection
- UAC, Aftermath, mac_apt
Tools
Compare all tools- mac_aptCLI · open source
- plutilCLI · built into macOS
What it is
macOS remembers every Wi-Fi network it has joined so it can rejoin automatically. On current releases that list lives in a dedicated property list, /Library/Preferences/com.apple.wifi.known-networks.plist, with one entry per network holding the SSID, security type, several "joined at" dates and a list of access point BSSIDs. Older releases kept the same information in the KnownNetworks dictionary of com.apple.airport.preferences.plist. Sources disagree on whether the split came with macOS 11 Big Sur or macOS 12 Monterey, so check which file holds the data on your evidence.
The configuration plists answer "which networks, first and last when". Connection-by-connection detail comes from logs: the Wi-Fi daemon airportd logs to the Unified Logs, and current macOS also keeps a text wifi.log. The network passphrases themselves are not in these plists; they are keychain items (see Keychain).
Where it lives
| File | Path | Versions / protection |
|---|---|---|
| Known networks | /Library/Preferences/com.apple.wifi.known-networks.plist | macOS 11/12 and later; mode 0600 root:wheel (observed on macOS 26) |
| Airport preferences | /Library/Preferences/SystemConfiguration/com.apple.airport.preferences.plist | All versions; holds KnownNetworks on older releases, only global Wi-Fi settings and PreferredOrder on current ones |
| Airport preferences backup | /Library/Preferences/SystemConfiguration/com.apple.airport.preferences.plist.backup | When present |
| Network services | /Library/Preferences/SystemConfiguration/preferences.plist | Network sets, services, locations |
| Network interfaces | /Library/Preferences/SystemConfiguration/NetworkInterfaces.plist | Interface list with BSD names and MAC addresses |
| Wi-Fi text log | /var/log/wifi.log and wifi.log.N.bz2 | Present on current macOS (verified on macOS 26); 0640 root:admin |
| Unified Logs | /private/var/db/diagnostics | Process airportd, subsystem com.apple.WiFiManager |
All of these are on the Data volume. They are not TCC-protected, but the known-networks plist needs root and wifi.log is readable only by root and the admin group. A macOS upgrade can leave *-pre-upgrade-* copies of preferences.plist and NetworkInterfaces.plist in the same folder, which preserve the configuration before the upgrade.
What it proves
- That the Mac saved (and therefore joined or was configured for) a named network: SSID, security type, hidden-network flag.
- When the network was first added (
AddedAt) and when it was last joined by the user (JoinedByUserAt) or automatically by the system (JoinedBySystemAt). - Which access points (BSSIDs) were used, with per-BSS association dates; these can support a physical location when matched to a known access point.
- Personal Hotspot and captive-portal networks, which point to phones and public venues.
- With logs: individual association, disconnection and roaming events around an incident time.
It does not prove:
- Who was at the keyboard, or that traffic crossed the network.
- A complete connection history: the plist keeps the latest dates per network, not every join.
- That the network was joined on this Mac: networks can arrive through configuration profiles, and iCloud Keychain can sync known networks between a user's devices. Check
AddReasonand corroborate with logs.
Key fields
com.apple.wifi.known-networks.plist (one dictionary per network, keyed by a network identifier string):
| Key | Meaning |
|---|---|
SSID | Network name (data) |
SupportedSecurityTypes | Security mode(s) |
AddedAt | When the network was added to the list |
AddReason | Why it was added |
JoinedByUserAt | Last manual join |
JoinedBySystemAt | Last automatic join |
UpdatedAt | Last change to the entry |
LastDiscoveredAt | Last time seen in a scan (seen on macOS 13+) |
SystemMode, PossiblyHiddenNetwork | Join mode, hidden SSID flag |
BSSList | Per-access-point entries: BSSID, LastAssociatedAt, optional Location (LocationLatitude, LocationLongitude, LocationTimestamp, LocationAccuracy) |
__OSSpecific__ | Extra data such as ChannelHistory, CollocatedGroup, RoamingProfileType, CaptiveProfile, TemporarilyDisabled |
Older com.apple.airport.preferences.plist KnownNetworks entries use SSIDString, SecurityType, LastConnected, AutoLogin, Captive, Closed, Disabled, PersonalHotspot, PossiblyHiddenNetwork, ChannelHistory and, in some versions, BSSIDHistory. Very old releases used a RememberedNetworks array, and UpdateHistory can preserve a previous copy of the list.
Timestamps
- Plist dates are native date objects. In binary plists they are stored as Mac absolute time (seconds since 2001-01-01 UTC);
plutil -pprints them as UTC with+0000. wifi.loglines are written in the system's local time. Record the Mac's time zone before merging them into a UTC timeline.- Unified Log entries carry full-precision timestamps;
log showprints them in local time unless you pass--timezone.
sudo plutil -p /Library/Preferences/com.apple.wifi.known-networks.plist | \
grep -E '"(SSID|AddedAt|JoinedByUserAt|JoinedBySystemAt|LastAssociatedAt)"'
Retention
- Known networks stay until the user removes them ("Forget This Network") or the file is reset.
AddedAtcan therefore be years old. wifi.logis rotated by newsyslog (/etc/newsyslog.d/wifi.conf): daily ($D0, midnight), bzip2-compressed, a count of 10 archives, so roughly ten days of text history.- Unified Log retention depends on volume and log level; expect days to a few weeks for
airportdmessages.
Collection
sudo ditto /Library/Preferences/com.apple.wifi.known-networks.plist /cases/host01/wifi/
sudo ditto /Library/Preferences/SystemConfiguration /cases/host01/wifi/SystemConfiguration
sudo ditto /var/log /cases/host01/var_log # includes wifi.log*
sudo log collect --output /cases/host01/system_logs.logarchive
- UAC:
library_preferences.yamlcollects/Library/Preferencesplists; its macOS network preferences live-response artifact dumpspreferences.plist. - Aftermath: collects airport preferences and log files (root plus Full Disk Access).
- mac_apt: the
WIFIplugin parsescom.apple.airport.preferences.plist, its.backup, andcom.apple.wifi.known-networks.plistinto one table.
Parsing
plutil -porplutil -convert xml1 -o - <file>for quick reading.- mac_apt
WIFIplugin: SSIDs, security, all join dates, BSSIDs with association dates and any stored coordinates. - Unified Logs for connection events:
log show system_logs.logarchive --style syslog \
--predicate 'process == "airportd" AND subsystem == "com.apple.WiFiManager"' \
--start '2026-09-01 00:00:00' --end '2026-09-02 00:00:00'
Unified Log Parser opens a .logarchive, the diagnostics and uuidtext folders or a log show export in the browser, applies DFIR triage rules and exports CSV or Timesketch; nothing is uploaded.
Investigator tips
- Put
AddedAtnext to the user account creation and OS install dates: networks added before the Mac was issued to the user may come from migration or sync. - Coffee-shop, hotel and airport SSIDs with
JoinedByUserAtinside the incident window are strong location leads; confirm them with BSSIDs andwifi.log. - Personal Hotspot entries identify a phone, useful when exfiltration may have bypassed the corporate network.
- A known-networks list that is nearly empty on an old, heavily used laptop suggests a reset or deliberate forgetting; check
*.backupand*-pre-upgrade-*files and local snapshots. - Correlate with Bluetooth connections and system logs to place the device in time and space.
- Private Wi-Fi address settings (
PrivateMACAddress*keys in the airport preferences on recent releases) mean the MAC seen by an access point may not match the hardware address inNetworkInterfaces.plist.