Saltar al contenido

Chuleta de artefactos de macOS

Todos los artefactos en una sola tabla, agrupados por categoría. Imprime en horizontal o guarda como PDF desde el navegador.

Los artefactos más usados están traducidos. Las entradas marcadas «Inglés» abren la página en inglés.

ArtefactoUbicaciónPruebaMarcas de tiempoAccesoRetenciónAnálisis
Ejecución
Crash ReportsInglésmacOS 10.15+/Library/Logs/DiagnosticReports/That a given executable ran on the Mac, from which path, launched by which parent, and when it crashed or hungLocal time with UTC offset in JSON strings and file namesroot, or membership of _analyticsusers (admins are members)Moved to Retired and cleaned up by SubmitDiagInfo; days to weeksjq, mac_apt, Console
Evidencias de Gatekeeper y XProtect en macOSmacOS 10.15+/var/db/SystemPolicyConfiguration/ExecPolicySi macOS evaluó, permitió, bloqueó o corrigió un programa concreto, y qué comportamientos marcóUnified log: se muestra en la zona horaria registrada con cada entrada salvo que se use --timezone; dt de XPdb: fecha y hora en texto; ExecPolicy: segundos Unixroot; Full Disk Access; XPdb es un Data Vault en 26.2+Unified log: de días a semanas; bases de datos: hasta que se reconstruyen (varía)log, mac_apt, sqlite3
Historial de shell en macOSmacOS 10.15+~/.zsh_historyQué comandos escribió un usuario en una shell interactiva, en qué orden y en qué ventana de TerminalNinguna por defecto; segundos de época Unix solo si EXTENDED_HISTORY (zsh) o HISTTIMEFORMAT (bash) está activoPropietario del archivo o root; archivos normales en la carpeta personalzsh por defecto SAVEHIST=1000 líneas; los archivos de sesión de Terminal se borran tras unas dos semanasmac_apt, grep, sed
InstallHistory.plistInglésmacOS 10.15+/Library/Receipts/InstallHistory.plistWhich software packages and updates were installed, when, and through which installer processPlist date values (UTC); receipt install-time in Unix epoch secondsReadable by all users; InstallHistory.plist is writable by the admin groupUntil deleted; receipts until pkgutil --forget or removalmac_apt, Plaso, pkgutil, plutil
Mounted Disk Images on macOSInglésmacOS 10.15+/Volumes/<name>/ (mount point), plus logs and per-user cachesThat a disk image was mounted, under which volume name, which apps were run from it and where it came fromUnified Log entries in UTC; FSEvents event IDs; file system times of the image and translocation foldersroot for logs and /private/var/folders; owning user for DownloadsLog events follow rotation; the image file, quarantine and FSEvents records persist longerhdiutil, log, FSEventsParser, mac_apt, xattr
sudo LogsInglésmacOS 10.15+/private/var/db/diagnostics/Which account ran which command as root (or another user), from which directory and terminal, and failed attemptsUnified Logs: timestamp with UTC offset; ts files: file mtime plus monotonic countersroot to read the log store, /etc/sudoers and /var/db/sudoUnified Log rotation (days to weeks); ts records until reboot or overwritelog, macos-UnifiedLogs, mac_apt, Plaso
TCC.dbmacOS 10.15+/Library/Application Support/com.apple.TCC/TCC.dbQué programas solicitaron u obtuvieron permisos de privacidad sensibles, quién los concedió y cuándo cambió la decisión por última vezSegundos de época Unix (UTC) en last_modifiedFull Disk Access para leer; la base de datos del sistema está además protegida por SIPHasta que la fila se modifica, se restablece (tccutil) o se elimina la appmac_apt, Plaso, Velociraptor, sqlite3
Persistencia
Configuration Profiles and MDMInglésmacOS 10.15+/private/var/db/ConfigurationProfiles/Which profiles and payloads (certificates, proxies, VPN, TCC/PPPC, system extensions, login items) were installed, by MDM or manually, and whenInstall dates in the profile store (plist dates); Unified Log entries in UTCroot; the profile store is SIP-protected on current releases, read it from an image or with profiles(1) liveProfiles persist until removed; install events follow Unified Log rotationprofiles, log, plutil, macos-UnifiedLogs
cron, at and periodicInglésmacOS 10.15+/usr/lib/cron/tabs/Whether a command was scheduled to run repeatedly or once through a Unix-style scheduler, by which accountFile system times of tab and job files (APFS, UTC); cron schedules are in local timeroot (tabs directory is mode 700)Until the crontab, job or script is removedcrontab, mac_apt, Aftermath
Ítems de inicio y base de datos BTM en macOSmacOS 10.15+/private/var/db/com.apple.backgroundtaskmanagement/BackgroundItems-v*.btmQué ítems de inicio, agentes y daemons se registraron, de qué desarrollador, y si se permitieronFechas NSKeyedArchiver (Mac absolute time, UTC) más las horas del sistema de archivosroot y Full Disk Access (almacén BTM); usuario propietario (backgrounditems.btm heredado)Hasta que se elimina el ítem o sfltool resetbtm reconstruye el almacénDumpBTM, bgiparser, Plaso, sfltool
Kernel and System ExtensionsInglésmacOS 10.15+/Library/SystemExtensions/db.plist and /private/var/db/SystemPolicyConfiguration/KextPolicyWhich third-party kernel extensions and system extensions were installed, approved, activated or loaded, by which team ID, and whenKextPolicy created_at / last_seen as date-time values (check the storage type per image); Unified Log entries in UTCroot; KextPolicy is SIP-protected, read it from an image or with Full Disk AccessRecords persist until the extension is removed and often after; Unified Log events follow rotationkmutil, systemextensionsctl, sqlite3, plutil, KnockKnock, APOLLO
LaunchAgents y LaunchDaemonsmacOS 10.15+~/Library/LaunchAgents, /Library/LaunchAgents, /Library/LaunchDaemonsQué código está configurado para iniciarse automáticamente, con qué usuario, con qué disparador y desde cuándoSin marcas de tiempo internas; horas de archivo APFS (nanosegundos, UTC)Agentes de usuario: usuario propietario; /Library: root; se recomienda FDA para la herramienta de adquisiciónHasta que se borra el plist; las anulaciones y los registros BTM pueden sobrevivirlemac_apt, Plaso, KnockKnock, plutil
Acceso a archivos
Cloud Storage Clients on MacInglésmacOS 10.15+~/Library/CloudStorage/ plus each client's Application Support, Group Container and log foldersWhich cloud accounts were linked, which files existed in or passed through the synced folders, and when they were uploaded, downloaded or deletedMixed: Unix epoch (seconds or milliseconds) in most client databases, Mac absolute time in File Provider data, local time in some logsOwning user; some client databases are encrypted or obfuscated and need the user's keychainDatabases track the current sync state; logs rotate by size and age; deleted files may remain in the cloud service's own trashsqlite3, FSEventsParser, plutil, grep
CUPS Print Jobs and LogsInglésmacOS 10.15+/private/var/spool/cups/ and /private/var/log/cups/Which user printed which job (document name and application), to which printer, when, and how many pages or copiesIPP attributes time-at-creation / processing / completed in Unix epoch seconds; log lines in local time with UTC offsetroot for the spool and logs; printers.conf readable by rootControl files for up to the configured job history (default 500 jobs); data files usually removed after the job; logs rotate by sizemac_apt, lpstat, grep
FSEvents (.fseventsd)macOS 10.15+/System/Volumes/Data/.fseventsd/Qué rutas se crearon, cambiaron, renombraron o borraron en un volumen, en el orden de los eventosNinguna por registro; se estiman a partir del mtime del archivo de log y de rutas con fecharoot; Full Disk Access en un sistema en vivoContinua, depurada por fseventsd (se han observado meses, varía)FSEventsParser, mac_apt
iCloud Drive (CloudDocs)InglésmacOS 10.15+~/Library/Application Support/CloudDocs/session/db/client.dbWhich files were in the user's iCloud Drive, when, and from which of their devicesUnix epoch seconds (UTC) in CloudDocs databasesUser or root; Full Disk Access for the collector on a live systemCurrent sync state; items leave when deleted and purged from iCloudmac_apt, sqlite3
Marcas de tiempo APFS y snapshots locales en macOSmacOS 10.15+/System/Volumes/DataCuándo se crearon, modificaron y añadieron archivos a una carpeta, y cómo era el volumen unas horas antesNanosegundos desde 1970-01-01 UTC (época Unix)Cualquier usuario para stat sobre sus propios archivos; root más Full Disk Access para montar snapshotsMarcas de tiempo hasta que se sobrescriben; snapshots locales horarios conservados unas 24 horaslibfsapfs, stat, mac_apt
Microsoft Office and Outlook for MacInglésmacOS 10.15+~/Library/Containers/com.microsoft.<App>/ and ~/Library/Group Containers/UBF8T346G9.Office/Which documents were opened in Word, Excel and PowerPoint, from which paths and when, the Office user identity, and the local copy of Outlook mailPlist dates (kLastUsedDateKey); Windows FILETIME in MicrosoftRegistrationDB.reg; Outlook database dates per schemaOwning user; Group Containers and Containers need Full Disk Access to collect on current releasesMRU lists hold a limited number of entries; Outlook caches follow account sync settingsmac_apt, plutil, sqlite3
Photos.sqliteInglésmacOS 10.15+~/Pictures/Photos Library.photoslibrary/database/Photos.sqliteWhen media was captured, added, edited, hidden or trashed, where it was taken and which app or device imported itMac absolute time (seconds since 2001-01-01 UTC); time zone offset per assetTCC-protected library: Full Disk Access (or Photos access) for the collectorUntil deleted; Recently Deleted items are purged after 30 daysosxphotos, exiftool, sqlite3
QuarantineEventsV2 y xattr de cuarentena en macOSmacOS 10.15+~/Library/Preferences/com.apple.LaunchServices.QuarantineEventsV2Qué archivos descargó un usuario, desde qué URL y página de origen, con qué app y cuándoBase de datos: Mac absolute time (UTC); xattr: segundos Unix en hexadecimal (UTC)Usuario propietario o root; se recomienda Full Disk Access para la herramienta de adquisiciónHasta que se borra o se limpia (no hay depuración automática documentada)mac_apt, Plaso, Velociraptor, sqlite3
QuickLook Thumbnail CacheInglésmacOS 10.15+$(getconf DARWIN_USER_CACHE_DIR)/com.apple.quicklook.ThumbnailsAgent/com.apple.QuickLook.thumbnailcache/That a file existed at a path and was displayed as a thumbnail or preview, with a cached image that can outlive the originallast_hit_date in Mac absolute time; file modification time stored in the version blobOwning user or root; the cache sits under /private/var/folders, collect as rootCache is pruned by size and age and rebuilt with qlmanage -r cache; not a long-term recordmac_apt, sqlite3, plutil
Recent Items (.sfl2/.sfl3)InglésmacOS 10.15+~/Library/Application Support/com.apple.sharedfilelist/Which documents, apps and servers a user recently opened, with full paths and source volumesMostly none per item; bookmark dates in Mac absolute time (2001 epoch)User-owned; Full Disk Access for the collector on a live systemRolling lists capped by the Recent Items count (default 10)mac_apt, plutil
Spotlight Store (.Spotlight-V100)InglésmacOS 10.15+/System/Volumes/Data/.Spotlight-V100/Store-V2/<UUID>/store.dbWhere a file came from, when it was added and opened, and that it existed even after deletionMac absolute time (seconds since 2001-01-01 UTC); mdls shows UTCroot; Full Disk Access on a live systemUntil the indexer updates or purges the entry, or the index is rebuiltspotlight_parser, mac_apt
Time Machine BackupsInglésmacOS 10.15+/Library/Preferences/com.apple.TimeMachine.plistWhich backup destinations were used, when backups ran, and what files looked like at each backupBackup names YYYY-MM-DD-HHMMSS; plist dates as plist date objectsroot plus Full Disk Access for tmutil listbackups and backup contentsHourly 24 h, daily for a month, weekly after; oldest deleted when fulltmutil, Plaso, plutil
Actividad del usuario
Apple MailInglésmacOS 10.15+~/Library/Mail/V10/MailData/Envelope IndexWhich emails were sent or received, from and to whom, when, in which mailbox, and which attachments were openedEnvelope Index dates in Unix epoch seconds (UTC); message headers in RFC 5322 local timeTCC-protected (Mail data): Full Disk Access for the collectorUntil deleted or removed from the server; local copies follow account sync settingssqlite3, emlx (Python)
Apple Notes NoteStore.sqliteInglésmacOS 10.15+~/Library/Group Containers/group.com.apple.notes/NoteStore.sqliteWhat a user wrote in Notes, when each note was created and last modified, attachments, folders, iCloud or local account, and deleted notes still in the databaseMac absolute time (seconds since 2001-01-01 UTC)Owning user; the group container is TCC-protected, so the collector needs Full Disk AccessUntil deleted; Recently Deleted keeps notes for about 30 days, and freed pages may survive in the WAL or free listapple_cloud_notes_parser, mac_apt, sqlite3
Calendar, Contacts and Reminders Databases on macOSInglésmacOS 10.15+~/Library/Application Support/AddressBook/, ~/Library/Group Containers/group.com.apple.reminders/, ~/Library/Calendars/ or group.com.apple.calendarWho the user knew and how to reach them, which meetings and appointments existed, where and with whom, and which tasks were created or completedMac absolute time (seconds since 2001-01-01 UTC) in all three Core Data storesOwning user; each store is TCC-protected (Contacts, Calendars, Reminders), so the collector needs Full Disk AccessUntil deleted locally or through sync; deleted items may persist briefly for sync and in WAL filessqlite3, APOLLO, plutil
Chrome and Firefox History on macOSInglésmacOS 10.15+~/Library/Application Support/Google/Chrome/Default/HistoryWhich sites a user opened in Chrome, Chromium browsers or Firefox, when, and what they downloadedChrome: microseconds since 1601-01-01 UTC; Firefox PRTime: microseconds since 1970-01-01 UTCFile owner or root; give the collector Full Disk Access as wellChrome: about 90 days of visits; Firefox: size-based expiration of old pagesHindsight, mac_apt, sqlite3
Dock and Finder PlistsInglésmacOS 10.15+~/Library/Preferences/com.apple.finder.plistWhich apps a user kept or recently ran in the Dock, and which folders, paths and servers they visited in FinderFew per key; Dock tile dates in HFS+ seconds (1904 epoch)User-owned; Full Disk Access for the collector on a live systemUntil the preference changes or the user resets itmac_apt, plutil
dslocal User AccountsInglésmacOS 10.15+/private/var/db/dslocal/nodes/Default/users/<name>.plistWhich local accounts exist, when they were created, who is admin, and recent password and failed-login activityaccountPolicyData: Unix epoch seconds (UTC)root; Full Disk Access recommended for the collectorUntil the account is deleted; home may survive in /Users/Deleted Usersmac_apt, Velociraptor, plutil, dscl
Flujos Biome SEGBmacOS 12+~/Library/Biome/streams/restricted/<Stream>/local/Qué apps estaban en primer plano, qué sitios se visitaron, qué dispositivos y redes se conectaron, con horas por registroMac absolute time (Cocoa) como doubles en los registros SEGB; los nombres de archivo son tiempo Cocoa en microsegundosFull Disk Access (flujos de usuario); los flujos del sistema están restringidos por SIPSemanas para la mayoría de los flujos (unos 28 días, cifra de estudios sobre iOS); los archivos caducados pasan a tombstonemac_apt, ccl-segb
knowledgeC.dbmacOS 10.15+/private/var/db/CoreDuet/Knowledge/knowledgeC.dbQué apps estaban en uso, cuándo y durante cuánto tiempo, y si la pantalla estaba encendida en ese momentoMac absolute time (segundos desde 2001-01-01 UTC), más el desfase ZSECONDSFROMGMTroot más las restricciones de SIP (BD del sistema); Full Disk Access (BD del usuario)Unas cuatro semanas de eventos en sistemas típicos (varía según el flujo)APOLLO, Plaso, sqlite3
macOS Keychain FilesInglésmacOS 10.15+~/Library/Keychains/Which accounts, services, networks and certificates a user had saved, and when items were created or modifiedFile keychain: UTC strings YYYYMMDDhhmmssZ; keychain-2.db: Mac absolute timeOwning user or root; secrets need user credentials and, for data protection items, the original deviceUntil the item or keychain is deletedsecurity, sqlite3
Messages chat.dbInglésmacOS 10.15+~/Library/Messages/chat.dbWho communicated with whom, what was said, when it was sent, delivered and read, and which files were exchangedNanoseconds since 2001-01-01 UTC (High Sierra+); older rows in secondsTCC-protected (Messages data): Full Disk Access for the collectorUntil deleted; Recently Deleted keeps items up to 30 days (Ventura+)imessage-exporter, mac_apt, Plaso, sqlite3
Notification Center DatabaseInglésmacOS 10.15+~/Library/Group Containers/group.com.apple.usernoted/db2/dbWhich app showed which notification text to the user, and when it was deliveredMac absolute time (seconds since 2001-01-01 UTC)Sequoia+: TCC-protected group container (Full Disk Access); older: owning userNot documented by Apple; varies, measure from oldest delivered_datemac_apt, Plaso, sqlite3
Safari History.dbmacOS 10.15+~/Library/Safari/History.dbQué URL abrió un usuario de macOS en Safari, cuándo, a través de qué redirecciones y si se borró el historialMac absolute time (Cocoa, segundos desde 2001-01-01 UTC), almacenado como REALFull Disk Access para el proceso que lee (TCC); root por sí solo no bastaAjuste del usuario, un año por defecto o hasta que se borre manualmente; la lista de descargas, un día por defectomac_apt, APOLLO, sqlite3, plutil
Saved Application StateInglésmacOS 10.15+~/Library/Saved Application State/<bundle-id>.savedState/Which apps were open with which windows, document titles and dock menu entries, and for Terminal, the text visible in each windowFile system times of windows.plist and data.data (last state save)Owning user; readable from an image or with Full Disk AccessRewritten while the app runs; kept after quit when Close windows when quitting an app is off; deleted on clean quit otherwisemac_apt, plutil
Screen Time DatabasesInglésmacOS 10.15+/private/var/folders/<xx>/<id>/0/com.apple.ScreenTimeAgent/Store/How much time each app or web domain was used per period, on which device and by which Apple AccountMac absolute time (seconds since 2001-01-01 UTC); durations in secondsOwning user or root; extra protection on current macOS, image collection is most reliableNot documented by Apple; measure from the oldest usage blockmac_apt, APOLLO, sqlite3
Red
netusage.sqliteInglésmacOS 10.15+/private/var/networkd/db/netusage.sqliteThat a process used the network, when it was first and last seen, how much data it moved per interface type, and which networks the Mac attached toMac absolute time (seconds since 2001-01-01 UTC)root; the networkd folder is protected, collect with Full Disk Access or from an imageRows persist for long periods; counters are cumulative and records are pruned by networkd on its own schedulemac_apt, APOLLO, sqlite3
Screen Sharing and Apple Remote Desktop ArtifactsInglésmacOS 10.15+/private/var/db/RemoteManagement/ and ~/Library/Containers/com.apple.ScreenSharing/Who connected to this Mac over VNC / Screen Sharing or ARD, from which address and when, and which hosts this Mac's user controlledUnified Log entries in UTC; plist dates and ARD caches in Mac absolute timeroot for /private/var/db/RemoteManagement and the log store; owning user for the Screen Sharing containerLog events follow Unified Log rotation; connection history and ARD caches persist until clearedlog, mac_apt, plutil, macos-UnifiedLogs
SSH and Remote Login on macOSInglésmacOS 10.15+~/.ssh/ and /private/etc/ssh/Inbound SSH logons (who, from which IP, with which key or password), outbound SSH targets, and key-based persistenceUnified Log entries in UTC; file system times of authorized_keys, known_hosts and host keysOwning user for ~/.ssh; root for /private/etc/ssh and the log storeKey files until edited; sshd events follow Unified Log rotation (days to weeks)log, macos-UnifiedLogs, ssh-keygen, stat, grep
Wi-Fi Known Networks on macOSInglésmacOS 10.15+/Library/Preferences/com.apple.wifi.known-networks.plistWhich Wi-Fi networks and access points a Mac joined, when first added, and when last joined by the user or systemPlist date objects (stored as Mac absolute time, shown in UTC); wifi.log in local timeroot (known-networks plist is 0600 root:wheel on current macOS)Known networks until the user forgets them; wifi.log rotated daily, about 10 archivesmac_apt, plutil
USB y dispositivos
Bluetooth Devices on macOSInglésmacOS 10.15+/Library/Bluetooth/Library/Preferences/com.apple.MobileBluetooth.devices.plistWhich Bluetooth devices were paired with or seen by a Mac, their names and vendors, and when they were last seenLastSeenTime: Unix epoch seconds; legacy plist dates: plist date objects (UTC)root (files under /Library/Bluetooth are root-only on current macOS)Paired devices until removed; LE 'other' cache and logs roll overmac_apt, APOLLO, plutil, sqlite3
iPhone Backups and Pairing Records on a MacInglésmacOS 10.15+~/Library/Application Support/MobileSync/Backup/<UDID>/Which iPhone or iPad was paired with and backed up to this Mac, when, whether the backup is encrypted, and the full content of the device at backup timePlist dates in Info.plist and Status.plist; file system times of the backup folderOwning user for MobileSync (TCC-protected, Full Disk Access needed); root for /private/var/db/lockdownBackups persist until deleted in Finder; pairing records until the device is untrusted or the OS is reinstallediLEAPP, MVT, mac_apt, plutil, sqlite3
USB DevicesInglésmacOS 10.15+/private/var/db/diagnostics/Which USB storage devices were attached, when volumes were mounted, and which files were touched on themUnified Logs UTC instants; FSEvents has no per-record timeroot for the log store and .fseventsd; live commands need no special rightsUnified Log rotation (days to weeks); FSEvents until pages are purgedlog, macos-UnifiedLogs, mac_apt, FSEventsParser
Antiforense
macOS Trash and .DS_StoreInglésmacOS 10.15+~/.Trash/ and /Volumes/<volume>/.Trashes/<uid>/Which files a user moved to the Trash, their original folder and name, and roughly when they were trashedFile system times of the trashed item (ctime changes on the move); .DS_Store modD/moDD in Mac absolute timeOwning user; ~/.Trash is TCC-protected for other apps, so the collector needs Full Disk AccessUntil the Trash is emptied, or 30 days if Remove items from the Trash after 30 days is enabledmac_apt, DSStoreParser, stat
Registros
System LogsInglésmacOS 10.15+/private/var/log/Install, update, Wi-Fi and legacy syslog activity, often beyond Unified Log retentionLocal time; install.log uses ISO-style time with UTC offset, BSD syslog lines have no yearadmin group or root (system.log and wifi.log are mode 640, group admin)Size or daily rotation set in /etc/asl.conf, /etc/asl/ and /etc/newsyslog.d/Plaso, mac_apt, syslog, grep
Unified LogsmacOS 10.15+/private/var/db/diagnostics/Qué procesos y subsistemas informaron de algo y cuándo: inicios de sesión, uso de privilegios, controles de seguridad, dispositivosMach time convertido mediante los registros timesync; log show imprime ISO 8601 con desfase respecto a UTCroot (el grupo admin puede leer el almacén); log collect requiere sudoRotación por tamaño, normalmente de días a unas pocas semanaslog, macos-UnifiedLogs, Plaso, mac_apt

La adquisición de memoria en macOS queda fuera de estas páginas; consulta mac-dump: github.com/Cyber-Experts/mac-dump