Skip to content

NetworkUser activity

Wi-Fi Known Networks on macOS: Plists and Logs

macOS known Wi-Fi networks in com.apple.wifi.known-networks.plist, airport preferences, wifi.log and Unified Logs: where a Mac has connected, and when.

Location
/Library/Preferences/com.apple.wifi.known-networks.plist
Proves
Which Wi-Fi networks and access points a Mac joined, when first added, and when last joined by the user or system
Timestamps
Plist date objects (stored as Mac absolute time, shown in UTC); wifi.log in local time
Access
root (known-networks plist is 0600 root:wheel on current macOS)
Retention
Known networks until the user forgets them; wifi.log rotated daily, about 10 archives
Collection
UAC, Aftermath, mac_apt

What it is

macOS remembers every Wi-Fi network it has joined so it can rejoin automatically. On current releases that list lives in a dedicated property list, /Library/Preferences/com.apple.wifi.known-networks.plist, with one entry per network holding the SSID, security type, several "joined at" dates and a list of access point BSSIDs. Older releases kept the same information in the KnownNetworks dictionary of com.apple.airport.preferences.plist. Sources disagree on whether the split came with macOS 11 Big Sur or macOS 12 Monterey, so check which file holds the data on your evidence.

The configuration plists answer "which networks, first and last when". Connection-by-connection detail comes from logs: the Wi-Fi daemon airportd logs to the Unified Logs, and current macOS also keeps a text wifi.log. The network passphrases themselves are not in these plists; they are keychain items (see Keychain).

Where it lives

FilePathVersions / protection
Known networks/Library/Preferences/com.apple.wifi.known-networks.plistmacOS 11/12 and later; mode 0600 root:wheel (observed on macOS 26)
Airport preferences/Library/Preferences/SystemConfiguration/com.apple.airport.preferences.plistAll versions; holds KnownNetworks on older releases, only global Wi-Fi settings and PreferredOrder on current ones
Airport preferences backup/Library/Preferences/SystemConfiguration/com.apple.airport.preferences.plist.backupWhen present
Network services/Library/Preferences/SystemConfiguration/preferences.plistNetwork sets, services, locations
Network interfaces/Library/Preferences/SystemConfiguration/NetworkInterfaces.plistInterface list with BSD names and MAC addresses
Wi-Fi text log/var/log/wifi.log and wifi.log.N.bz2Present on current macOS (verified on macOS 26); 0640 root:admin
Unified Logs/private/var/db/diagnosticsProcess airportd, subsystem com.apple.WiFiManager

All of these are on the Data volume. They are not TCC-protected, but the known-networks plist needs root and wifi.log is readable only by root and the admin group. A macOS upgrade can leave *-pre-upgrade-* copies of preferences.plist and NetworkInterfaces.plist in the same folder, which preserve the configuration before the upgrade.

What it proves

  • That the Mac saved (and therefore joined or was configured for) a named network: SSID, security type, hidden-network flag.
  • When the network was first added (AddedAt) and when it was last joined by the user (JoinedByUserAt) or automatically by the system (JoinedBySystemAt).
  • Which access points (BSSIDs) were used, with per-BSS association dates; these can support a physical location when matched to a known access point.
  • Personal Hotspot and captive-portal networks, which point to phones and public venues.
  • With logs: individual association, disconnection and roaming events around an incident time.

It does not prove:

  • Who was at the keyboard, or that traffic crossed the network.
  • A complete connection history: the plist keeps the latest dates per network, not every join.
  • That the network was joined on this Mac: networks can arrive through configuration profiles, and iCloud Keychain can sync known networks between a user's devices. Check AddReason and corroborate with logs.

Key fields

com.apple.wifi.known-networks.plist (one dictionary per network, keyed by a network identifier string):

KeyMeaning
SSIDNetwork name (data)
SupportedSecurityTypesSecurity mode(s)
AddedAtWhen the network was added to the list
AddReasonWhy it was added
JoinedByUserAtLast manual join
JoinedBySystemAtLast automatic join
UpdatedAtLast change to the entry
LastDiscoveredAtLast time seen in a scan (seen on macOS 13+)
SystemMode, PossiblyHiddenNetworkJoin mode, hidden SSID flag
BSSListPer-access-point entries: BSSID, LastAssociatedAt, optional Location (LocationLatitude, LocationLongitude, LocationTimestamp, LocationAccuracy)
__OSSpecific__Extra data such as ChannelHistory, CollocatedGroup, RoamingProfileType, CaptiveProfile, TemporarilyDisabled

Older com.apple.airport.preferences.plist KnownNetworks entries use SSIDString, SecurityType, LastConnected, AutoLogin, Captive, Closed, Disabled, PersonalHotspot, PossiblyHiddenNetwork, ChannelHistory and, in some versions, BSSIDHistory. Very old releases used a RememberedNetworks array, and UpdateHistory can preserve a previous copy of the list.

Timestamps

  • Plist dates are native date objects. In binary plists they are stored as Mac absolute time (seconds since 2001-01-01 UTC); plutil -p prints them as UTC with +0000.
  • wifi.log lines are written in the system's local time. Record the Mac's time zone before merging them into a UTC timeline.
  • Unified Log entries carry full-precision timestamps; log show prints them in local time unless you pass --timezone.
sudo plutil -p /Library/Preferences/com.apple.wifi.known-networks.plist | \
  grep -E '"(SSID|AddedAt|JoinedByUserAt|JoinedBySystemAt|LastAssociatedAt)"'

Retention

  • Known networks stay until the user removes them ("Forget This Network") or the file is reset. AddedAt can therefore be years old.
  • wifi.log is rotated by newsyslog (/etc/newsyslog.d/wifi.conf): daily ($D0, midnight), bzip2-compressed, a count of 10 archives, so roughly ten days of text history.
  • Unified Log retention depends on volume and log level; expect days to a few weeks for airportd messages.

Collection

sudo ditto /Library/Preferences/com.apple.wifi.known-networks.plist /cases/host01/wifi/
sudo ditto /Library/Preferences/SystemConfiguration /cases/host01/wifi/SystemConfiguration
sudo ditto /var/log /cases/host01/var_log     # includes wifi.log*
sudo log collect --output /cases/host01/system_logs.logarchive
  • UAC: library_preferences.yaml collects /Library/Preferences plists; its macOS network preferences live-response artifact dumps preferences.plist.
  • Aftermath: collects airport preferences and log files (root plus Full Disk Access).
  • mac_apt: the WIFI plugin parses com.apple.airport.preferences.plist, its .backup, and com.apple.wifi.known-networks.plist into one table.

Parsing

  • plutil -p or plutil -convert xml1 -o - <file> for quick reading.
  • mac_apt WIFI plugin: SSIDs, security, all join dates, BSSIDs with association dates and any stored coordinates.
  • Unified Logs for connection events:
log show system_logs.logarchive --style syslog \
  --predicate 'process == "airportd" AND subsystem == "com.apple.WiFiManager"' \
  --start '2026-09-01 00:00:00' --end '2026-09-02 00:00:00'

Unified Log Parser opens a .logarchive, the diagnostics and uuidtext folders or a log show export in the browser, applies DFIR triage rules and exports CSV or Timesketch; nothing is uploaded.

Investigator tips

  • Put AddedAt next to the user account creation and OS install dates: networks added before the Mac was issued to the user may come from migration or sync.
  • Coffee-shop, hotel and airport SSIDs with JoinedByUserAt inside the incident window are strong location leads; confirm them with BSSIDs and wifi.log.
  • Personal Hotspot entries identify a phone, useful when exfiltration may have bypassed the corporate network.
  • A known-networks list that is nearly empty on an old, heavily used laptop suggests a reset or deliberate forgetting; check *.backup and *-pre-upgrade-* files and local snapshots.
  • Correlate with Bluetooth connections and system logs to place the device in time and space.
  • Private Wi-Fi address settings (PrivateMACAddress* keys in the airport preferences on recent releases) mean the MAC seen by an access point may not match the hardware address in NetworkInterfaces.plist.

See also