06 · TCC & Keychain
TCC Database Forensics: macOS Privacy Permissions
Analyze macOS TCC.db privacy permissions: access table columns, service names, auth_value meanings, MDM grants, SIP protection and unified log evidence.
Read guide
06 · Evidence area
Transparency, Consent and Control (TCC) records every privacy permission a Mac has granted, which makes it a map of what an attacker needed. The keychain, handled lawfully, adds metadata about accounts, networks and services. Both are protected, so acquisition context matters.
2 guides in this area
06 · TCC & Keychain
Analyze macOS TCC.db privacy permissions: access table columns, service names, auth_value meanings, MDM grants, SIP protection and unified log evidence.
06 · TCC & Keychain
Understand macOS keychains for DFIR: login and System keychains, the data protection keychain, iCloud Keychain, metadata value and legal limits.
Where each artifact lives, what it proves, its timestamps and the tools to parse it.