Chuleta de artefactos de macOS
Todos los artefactos en una sola tabla, agrupados por categoría. Imprime en horizontal o guarda como PDF desde el navegador.
www.macforensics.app/es/artifacts
Los artefactos más usados están traducidos. Las entradas marcadas «Inglés» abren la página en inglés.
| Artefacto | Ubicación | Prueba | Marcas de tiempo | Acceso | Retención | Análisis |
|---|---|---|---|---|---|---|
| Ejecución | ||||||
| Crash ReportsInglésmacOS 10.15+ | /Library/Logs/DiagnosticReports/ | That a given executable ran on the Mac, from which path, launched by which parent, and when it crashed or hung | Local time with UTC offset in JSON strings and file names | root, or membership of _analyticsusers (admins are members) | Moved to Retired and cleaned up by SubmitDiagInfo; days to weeks | jq, mac_apt, Console |
| Evidencias de Gatekeeper y XProtect en macOSmacOS 10.15+ | /var/db/SystemPolicyConfiguration/ExecPolicy | Si macOS evaluó, permitió, bloqueó o corrigió un programa concreto, y qué comportamientos marcó | Unified log: se muestra en la zona horaria registrada con cada entrada salvo que se use --timezone; dt de XPdb: fecha y hora en texto; ExecPolicy: segundos Unix | root; Full Disk Access; XPdb es un Data Vault en 26.2+ | Unified log: de días a semanas; bases de datos: hasta que se reconstruyen (varía) | log, mac_apt, sqlite3 |
| Historial de shell en macOSmacOS 10.15+ | ~/.zsh_history | Qué comandos escribió un usuario en una shell interactiva, en qué orden y en qué ventana de Terminal | Ninguna por defecto; segundos de época Unix solo si EXTENDED_HISTORY (zsh) o HISTTIMEFORMAT (bash) está activo | Propietario del archivo o root; archivos normales en la carpeta personal | zsh por defecto SAVEHIST=1000 líneas; los archivos de sesión de Terminal se borran tras unas dos semanas | mac_apt, grep, sed |
| InstallHistory.plistInglésmacOS 10.15+ | /Library/Receipts/InstallHistory.plist | Which software packages and updates were installed, when, and through which installer process | Plist date values (UTC); receipt install-time in Unix epoch seconds | Readable by all users; InstallHistory.plist is writable by the admin group | Until deleted; receipts until pkgutil --forget or removal | mac_apt, Plaso, pkgutil, plutil |
| Mounted Disk Images on macOSInglésmacOS 10.15+ | /Volumes/<name>/ (mount point), plus logs and per-user caches | That a disk image was mounted, under which volume name, which apps were run from it and where it came from | Unified Log entries in UTC; FSEvents event IDs; file system times of the image and translocation folders | root for logs and /private/var/folders; owning user for Downloads | Log events follow rotation; the image file, quarantine and FSEvents records persist longer | hdiutil, log, FSEventsParser, mac_apt, xattr |
| sudo LogsInglésmacOS 10.15+ | /private/var/db/diagnostics/ | Which account ran which command as root (or another user), from which directory and terminal, and failed attempts | Unified Logs: timestamp with UTC offset; ts files: file mtime plus monotonic counters | root to read the log store, /etc/sudoers and /var/db/sudo | Unified Log rotation (days to weeks); ts records until reboot or overwrite | log, macos-UnifiedLogs, mac_apt, Plaso |
| TCC.dbmacOS 10.15+ | /Library/Application Support/com.apple.TCC/TCC.db | Qué programas solicitaron u obtuvieron permisos de privacidad sensibles, quién los concedió y cuándo cambió la decisión por última vez | Segundos de época Unix (UTC) en last_modified | Full Disk Access para leer; la base de datos del sistema está además protegida por SIP | Hasta que la fila se modifica, se restablece (tccutil) o se elimina la app | mac_apt, Plaso, Velociraptor, sqlite3 |
| Persistencia | ||||||
| Configuration Profiles and MDMInglésmacOS 10.15+ | /private/var/db/ConfigurationProfiles/ | Which profiles and payloads (certificates, proxies, VPN, TCC/PPPC, system extensions, login items) were installed, by MDM or manually, and when | Install dates in the profile store (plist dates); Unified Log entries in UTC | root; the profile store is SIP-protected on current releases, read it from an image or with profiles(1) live | Profiles persist until removed; install events follow Unified Log rotation | profiles, log, plutil, macos-UnifiedLogs |
| cron, at and periodicInglésmacOS 10.15+ | /usr/lib/cron/tabs/ | Whether a command was scheduled to run repeatedly or once through a Unix-style scheduler, by which account | File system times of tab and job files (APFS, UTC); cron schedules are in local time | root (tabs directory is mode 700) | Until the crontab, job or script is removed | crontab, mac_apt, Aftermath |
| Ítems de inicio y base de datos BTM en macOSmacOS 10.15+ | /private/var/db/com.apple.backgroundtaskmanagement/BackgroundItems-v*.btm | Qué ítems de inicio, agentes y daemons se registraron, de qué desarrollador, y si se permitieron | Fechas NSKeyedArchiver (Mac absolute time, UTC) más las horas del sistema de archivos | root y Full Disk Access (almacén BTM); usuario propietario (backgrounditems.btm heredado) | Hasta que se elimina el ítem o sfltool resetbtm reconstruye el almacén | DumpBTM, bgiparser, Plaso, sfltool |
| Kernel and System ExtensionsInglésmacOS 10.15+ | /Library/SystemExtensions/db.plist and /private/var/db/SystemPolicyConfiguration/KextPolicy | Which third-party kernel extensions and system extensions were installed, approved, activated or loaded, by which team ID, and when | KextPolicy created_at / last_seen as date-time values (check the storage type per image); Unified Log entries in UTC | root; KextPolicy is SIP-protected, read it from an image or with Full Disk Access | Records persist until the extension is removed and often after; Unified Log events follow rotation | kmutil, systemextensionsctl, sqlite3, plutil, KnockKnock, APOLLO |
| LaunchAgents y LaunchDaemonsmacOS 10.15+ | ~/Library/LaunchAgents, /Library/LaunchAgents, /Library/LaunchDaemons | Qué código está configurado para iniciarse automáticamente, con qué usuario, con qué disparador y desde cuándo | Sin marcas de tiempo internas; horas de archivo APFS (nanosegundos, UTC) | Agentes de usuario: usuario propietario; /Library: root; se recomienda FDA para la herramienta de adquisición | Hasta que se borra el plist; las anulaciones y los registros BTM pueden sobrevivirle | mac_apt, Plaso, KnockKnock, plutil |
| Acceso a archivos | ||||||
| Cloud Storage Clients on MacInglésmacOS 10.15+ | ~/Library/CloudStorage/ plus each client's Application Support, Group Container and log folders | Which cloud accounts were linked, which files existed in or passed through the synced folders, and when they were uploaded, downloaded or deleted | Mixed: Unix epoch (seconds or milliseconds) in most client databases, Mac absolute time in File Provider data, local time in some logs | Owning user; some client databases are encrypted or obfuscated and need the user's keychain | Databases track the current sync state; logs rotate by size and age; deleted files may remain in the cloud service's own trash | sqlite3, FSEventsParser, plutil, grep |
| CUPS Print Jobs and LogsInglésmacOS 10.15+ | /private/var/spool/cups/ and /private/var/log/cups/ | Which user printed which job (document name and application), to which printer, when, and how many pages or copies | IPP attributes time-at-creation / processing / completed in Unix epoch seconds; log lines in local time with UTC offset | root for the spool and logs; printers.conf readable by root | Control files for up to the configured job history (default 500 jobs); data files usually removed after the job; logs rotate by size | mac_apt, lpstat, grep |
| FSEvents (.fseventsd)macOS 10.15+ | /System/Volumes/Data/.fseventsd/ | Qué rutas se crearon, cambiaron, renombraron o borraron en un volumen, en el orden de los eventos | Ninguna por registro; se estiman a partir del mtime del archivo de log y de rutas con fecha | root; Full Disk Access en un sistema en vivo | Continua, depurada por fseventsd (se han observado meses, varía) | FSEventsParser, mac_apt |
| iCloud Drive (CloudDocs)InglésmacOS 10.15+ | ~/Library/Application Support/CloudDocs/session/db/client.db | Which files were in the user's iCloud Drive, when, and from which of their devices | Unix epoch seconds (UTC) in CloudDocs databases | User or root; Full Disk Access for the collector on a live system | Current sync state; items leave when deleted and purged from iCloud | mac_apt, sqlite3 |
| Marcas de tiempo APFS y snapshots locales en macOSmacOS 10.15+ | /System/Volumes/Data | Cuándo se crearon, modificaron y añadieron archivos a una carpeta, y cómo era el volumen unas horas antes | Nanosegundos desde 1970-01-01 UTC (época Unix) | Cualquier usuario para stat sobre sus propios archivos; root más Full Disk Access para montar snapshots | Marcas de tiempo hasta que se sobrescriben; snapshots locales horarios conservados unas 24 horas | libfsapfs, stat, mac_apt |
| Microsoft Office and Outlook for MacInglésmacOS 10.15+ | ~/Library/Containers/com.microsoft.<App>/ and ~/Library/Group Containers/UBF8T346G9.Office/ | Which documents were opened in Word, Excel and PowerPoint, from which paths and when, the Office user identity, and the local copy of Outlook mail | Plist dates (kLastUsedDateKey); Windows FILETIME in MicrosoftRegistrationDB.reg; Outlook database dates per schema | Owning user; Group Containers and Containers need Full Disk Access to collect on current releases | MRU lists hold a limited number of entries; Outlook caches follow account sync settings | mac_apt, plutil, sqlite3 |
| Photos.sqliteInglésmacOS 10.15+ | ~/Pictures/Photos Library.photoslibrary/database/Photos.sqlite | When media was captured, added, edited, hidden or trashed, where it was taken and which app or device imported it | Mac absolute time (seconds since 2001-01-01 UTC); time zone offset per asset | TCC-protected library: Full Disk Access (or Photos access) for the collector | Until deleted; Recently Deleted items are purged after 30 days | osxphotos, exiftool, sqlite3 |
| QuarantineEventsV2 y xattr de cuarentena en macOSmacOS 10.15+ | ~/Library/Preferences/com.apple.LaunchServices.QuarantineEventsV2 | Qué archivos descargó un usuario, desde qué URL y página de origen, con qué app y cuándo | Base de datos: Mac absolute time (UTC); xattr: segundos Unix en hexadecimal (UTC) | Usuario propietario o root; se recomienda Full Disk Access para la herramienta de adquisición | Hasta que se borra o se limpia (no hay depuración automática documentada) | mac_apt, Plaso, Velociraptor, sqlite3 |
| QuickLook Thumbnail CacheInglésmacOS 10.15+ | $(getconf DARWIN_USER_CACHE_DIR)/com.apple.quicklook.ThumbnailsAgent/com.apple.QuickLook.thumbnailcache/ | That a file existed at a path and was displayed as a thumbnail or preview, with a cached image that can outlive the original | last_hit_date in Mac absolute time; file modification time stored in the version blob | Owning user or root; the cache sits under /private/var/folders, collect as root | Cache is pruned by size and age and rebuilt with qlmanage -r cache; not a long-term record | mac_apt, sqlite3, plutil |
| Recent Items (.sfl2/.sfl3)InglésmacOS 10.15+ | ~/Library/Application Support/com.apple.sharedfilelist/ | Which documents, apps and servers a user recently opened, with full paths and source volumes | Mostly none per item; bookmark dates in Mac absolute time (2001 epoch) | User-owned; Full Disk Access for the collector on a live system | Rolling lists capped by the Recent Items count (default 10) | mac_apt, plutil |
| Spotlight Store (.Spotlight-V100)InglésmacOS 10.15+ | /System/Volumes/Data/.Spotlight-V100/Store-V2/<UUID>/store.db | Where a file came from, when it was added and opened, and that it existed even after deletion | Mac absolute time (seconds since 2001-01-01 UTC); mdls shows UTC | root; Full Disk Access on a live system | Until the indexer updates or purges the entry, or the index is rebuilt | spotlight_parser, mac_apt |
| Time Machine BackupsInglésmacOS 10.15+ | /Library/Preferences/com.apple.TimeMachine.plist | Which backup destinations were used, when backups ran, and what files looked like at each backup | Backup names YYYY-MM-DD-HHMMSS; plist dates as plist date objects | root plus Full Disk Access for tmutil listbackups and backup contents | Hourly 24 h, daily for a month, weekly after; oldest deleted when full | tmutil, Plaso, plutil |
| Actividad del usuario | ||||||
| Apple MailInglésmacOS 10.15+ | ~/Library/Mail/V10/MailData/Envelope Index | Which emails were sent or received, from and to whom, when, in which mailbox, and which attachments were opened | Envelope Index dates in Unix epoch seconds (UTC); message headers in RFC 5322 local time | TCC-protected (Mail data): Full Disk Access for the collector | Until deleted or removed from the server; local copies follow account sync settings | sqlite3, emlx (Python) |
| Apple Notes NoteStore.sqliteInglésmacOS 10.15+ | ~/Library/Group Containers/group.com.apple.notes/NoteStore.sqlite | What a user wrote in Notes, when each note was created and last modified, attachments, folders, iCloud or local account, and deleted notes still in the database | Mac absolute time (seconds since 2001-01-01 UTC) | Owning user; the group container is TCC-protected, so the collector needs Full Disk Access | Until deleted; Recently Deleted keeps notes for about 30 days, and freed pages may survive in the WAL or free list | apple_cloud_notes_parser, mac_apt, sqlite3 |
| Calendar, Contacts and Reminders Databases on macOSInglésmacOS 10.15+ | ~/Library/Application Support/AddressBook/, ~/Library/Group Containers/group.com.apple.reminders/, ~/Library/Calendars/ or group.com.apple.calendar | Who the user knew and how to reach them, which meetings and appointments existed, where and with whom, and which tasks were created or completed | Mac absolute time (seconds since 2001-01-01 UTC) in all three Core Data stores | Owning user; each store is TCC-protected (Contacts, Calendars, Reminders), so the collector needs Full Disk Access | Until deleted locally or through sync; deleted items may persist briefly for sync and in WAL files | sqlite3, APOLLO, plutil |
| Chrome and Firefox History on macOSInglésmacOS 10.15+ | ~/Library/Application Support/Google/Chrome/Default/History | Which sites a user opened in Chrome, Chromium browsers or Firefox, when, and what they downloaded | Chrome: microseconds since 1601-01-01 UTC; Firefox PRTime: microseconds since 1970-01-01 UTC | File owner or root; give the collector Full Disk Access as well | Chrome: about 90 days of visits; Firefox: size-based expiration of old pages | Hindsight, mac_apt, sqlite3 |
| Dock and Finder PlistsInglésmacOS 10.15+ | ~/Library/Preferences/com.apple.finder.plist | Which apps a user kept or recently ran in the Dock, and which folders, paths and servers they visited in Finder | Few per key; Dock tile dates in HFS+ seconds (1904 epoch) | User-owned; Full Disk Access for the collector on a live system | Until the preference changes or the user resets it | mac_apt, plutil |
| dslocal User AccountsInglésmacOS 10.15+ | /private/var/db/dslocal/nodes/Default/users/<name>.plist | Which local accounts exist, when they were created, who is admin, and recent password and failed-login activity | accountPolicyData: Unix epoch seconds (UTC) | root; Full Disk Access recommended for the collector | Until the account is deleted; home may survive in /Users/Deleted Users | mac_apt, Velociraptor, plutil, dscl |
| Flujos Biome SEGBmacOS 12+ | ~/Library/Biome/streams/restricted/<Stream>/local/ | Qué apps estaban en primer plano, qué sitios se visitaron, qué dispositivos y redes se conectaron, con horas por registro | Mac absolute time (Cocoa) como doubles en los registros SEGB; los nombres de archivo son tiempo Cocoa en microsegundos | Full Disk Access (flujos de usuario); los flujos del sistema están restringidos por SIP | Semanas para la mayoría de los flujos (unos 28 días, cifra de estudios sobre iOS); los archivos caducados pasan a tombstone | mac_apt, ccl-segb |
| knowledgeC.dbmacOS 10.15+ | /private/var/db/CoreDuet/Knowledge/knowledgeC.db | Qué apps estaban en uso, cuándo y durante cuánto tiempo, y si la pantalla estaba encendida en ese momento | Mac absolute time (segundos desde 2001-01-01 UTC), más el desfase ZSECONDSFROMGMT | root más las restricciones de SIP (BD del sistema); Full Disk Access (BD del usuario) | Unas cuatro semanas de eventos en sistemas típicos (varía según el flujo) | APOLLO, Plaso, sqlite3 |
| macOS Keychain FilesInglésmacOS 10.15+ | ~/Library/Keychains/ | Which accounts, services, networks and certificates a user had saved, and when items were created or modified | File keychain: UTC strings YYYYMMDDhhmmssZ; keychain-2.db: Mac absolute time | Owning user or root; secrets need user credentials and, for data protection items, the original device | Until the item or keychain is deleted | security, sqlite3 |
| Messages chat.dbInglésmacOS 10.15+ | ~/Library/Messages/chat.db | Who communicated with whom, what was said, when it was sent, delivered and read, and which files were exchanged | Nanoseconds since 2001-01-01 UTC (High Sierra+); older rows in seconds | TCC-protected (Messages data): Full Disk Access for the collector | Until deleted; Recently Deleted keeps items up to 30 days (Ventura+) | imessage-exporter, mac_apt, Plaso, sqlite3 |
| Notification Center DatabaseInglésmacOS 10.15+ | ~/Library/Group Containers/group.com.apple.usernoted/db2/db | Which app showed which notification text to the user, and when it was delivered | Mac absolute time (seconds since 2001-01-01 UTC) | Sequoia+: TCC-protected group container (Full Disk Access); older: owning user | Not documented by Apple; varies, measure from oldest delivered_date | mac_apt, Plaso, sqlite3 |
| Safari History.dbmacOS 10.15+ | ~/Library/Safari/History.db | Qué URL abrió un usuario de macOS en Safari, cuándo, a través de qué redirecciones y si se borró el historial | Mac absolute time (Cocoa, segundos desde 2001-01-01 UTC), almacenado como REAL | Full Disk Access para el proceso que lee (TCC); root por sí solo no basta | Ajuste del usuario, un año por defecto o hasta que se borre manualmente; la lista de descargas, un día por defecto | mac_apt, APOLLO, sqlite3, plutil |
| Saved Application StateInglésmacOS 10.15+ | ~/Library/Saved Application State/<bundle-id>.savedState/ | Which apps were open with which windows, document titles and dock menu entries, and for Terminal, the text visible in each window | File system times of windows.plist and data.data (last state save) | Owning user; readable from an image or with Full Disk Access | Rewritten while the app runs; kept after quit when Close windows when quitting an app is off; deleted on clean quit otherwise | mac_apt, plutil |
| Screen Time DatabasesInglésmacOS 10.15+ | /private/var/folders/<xx>/<id>/0/com.apple.ScreenTimeAgent/Store/ | How much time each app or web domain was used per period, on which device and by which Apple Account | Mac absolute time (seconds since 2001-01-01 UTC); durations in seconds | Owning user or root; extra protection on current macOS, image collection is most reliable | Not documented by Apple; measure from the oldest usage block | mac_apt, APOLLO, sqlite3 |
| Red | ||||||
| netusage.sqliteInglésmacOS 10.15+ | /private/var/networkd/db/netusage.sqlite | That a process used the network, when it was first and last seen, how much data it moved per interface type, and which networks the Mac attached to | Mac absolute time (seconds since 2001-01-01 UTC) | root; the networkd folder is protected, collect with Full Disk Access or from an image | Rows persist for long periods; counters are cumulative and records are pruned by networkd on its own schedule | mac_apt, APOLLO, sqlite3 |
| Screen Sharing and Apple Remote Desktop ArtifactsInglésmacOS 10.15+ | /private/var/db/RemoteManagement/ and ~/Library/Containers/com.apple.ScreenSharing/ | Who connected to this Mac over VNC / Screen Sharing or ARD, from which address and when, and which hosts this Mac's user controlled | Unified Log entries in UTC; plist dates and ARD caches in Mac absolute time | root for /private/var/db/RemoteManagement and the log store; owning user for the Screen Sharing container | Log events follow Unified Log rotation; connection history and ARD caches persist until cleared | log, mac_apt, plutil, macos-UnifiedLogs |
| SSH and Remote Login on macOSInglésmacOS 10.15+ | ~/.ssh/ and /private/etc/ssh/ | Inbound SSH logons (who, from which IP, with which key or password), outbound SSH targets, and key-based persistence | Unified Log entries in UTC; file system times of authorized_keys, known_hosts and host keys | Owning user for ~/.ssh; root for /private/etc/ssh and the log store | Key files until edited; sshd events follow Unified Log rotation (days to weeks) | log, macos-UnifiedLogs, ssh-keygen, stat, grep |
| Wi-Fi Known Networks on macOSInglésmacOS 10.15+ | /Library/Preferences/com.apple.wifi.known-networks.plist | Which Wi-Fi networks and access points a Mac joined, when first added, and when last joined by the user or system | Plist date objects (stored as Mac absolute time, shown in UTC); wifi.log in local time | root (known-networks plist is 0600 root:wheel on current macOS) | Known networks until the user forgets them; wifi.log rotated daily, about 10 archives | mac_apt, plutil |
| USB y dispositivos | ||||||
| Bluetooth Devices on macOSInglésmacOS 10.15+ | /Library/Bluetooth/Library/Preferences/com.apple.MobileBluetooth.devices.plist | Which Bluetooth devices were paired with or seen by a Mac, their names and vendors, and when they were last seen | LastSeenTime: Unix epoch seconds; legacy plist dates: plist date objects (UTC) | root (files under /Library/Bluetooth are root-only on current macOS) | Paired devices until removed; LE 'other' cache and logs roll over | mac_apt, APOLLO, plutil, sqlite3 |
| iPhone Backups and Pairing Records on a MacInglésmacOS 10.15+ | ~/Library/Application Support/MobileSync/Backup/<UDID>/ | Which iPhone or iPad was paired with and backed up to this Mac, when, whether the backup is encrypted, and the full content of the device at backup time | Plist dates in Info.plist and Status.plist; file system times of the backup folder | Owning user for MobileSync (TCC-protected, Full Disk Access needed); root for /private/var/db/lockdown | Backups persist until deleted in Finder; pairing records until the device is untrusted or the OS is reinstalled | iLEAPP, MVT, mac_apt, plutil, sqlite3 |
| USB DevicesInglésmacOS 10.15+ | /private/var/db/diagnostics/ | Which USB storage devices were attached, when volumes were mounted, and which files were touched on them | Unified Logs UTC instants; FSEvents has no per-record time | root for the log store and .fseventsd; live commands need no special rights | Unified Log rotation (days to weeks); FSEvents until pages are purged | log, macos-UnifiedLogs, mac_apt, FSEventsParser |
| Antiforense | ||||||
| macOS Trash and .DS_StoreInglésmacOS 10.15+ | ~/.Trash/ and /Volumes/<volume>/.Trashes/<uid>/ | Which files a user moved to the Trash, their original folder and name, and roughly when they were trashed | File system times of the trashed item (ctime changes on the move); .DS_Store modD/moDD in Mac absolute time | Owning user; ~/.Trash is TCC-protected for other apps, so the collector needs Full Disk Access | Until the Trash is emptied, or 30 days if Remove items from the Trash after 30 days is enabled | mac_apt, DSStoreParser, stat |
| Registros | ||||||
| System LogsInglésmacOS 10.15+ | /private/var/log/ | Install, update, Wi-Fi and legacy syslog activity, often beyond Unified Log retention | Local time; install.log uses ISO-style time with UTC offset, BSD syslog lines have no year | admin group or root (system.log and wifi.log are mode 640, group admin) | Size or daily rotation set in /etc/asl.conf, /etc/asl/ and /etc/newsyslog.d/ | Plaso, mac_apt, syslog, grep |
| Unified LogsmacOS 10.15+ | /private/var/db/diagnostics/ | Qué procesos y subsistemas informaron de algo y cuándo: inicios de sesión, uso de privilegios, controles de seguridad, dispositivos | Mach time convertido mediante los registros timesync; log show imprime ISO 8601 con desfase respecto a UTC | root (el grupo admin puede leer el almacén); log collect requiere sudo | Rotación por tamaño, normalmente de días a unas pocas semanas | log, macos-UnifiedLogs, Plaso, mac_apt |
La adquisición de memoria en macOS queda fuera de estas páginas; consulta mac-dump: github.com/Cyber-Experts/mac-dump