Aide-mémoire des artefacts macOS
Tous les artefacts sur un seul tableau, regroupés par catégorie. Imprimez en paysage ou enregistrez en PDF depuis votre navigateur.
www.macforensics.app/fr/artifacts
Les artefacts les plus utilisés sont traduits. Les entrées marquées « Anglais » ouvrent la page en anglais.
| Artefact | Emplacement | Prouve | Horodatages | Accès | Rétention | Analyse |
|---|---|---|---|---|---|---|
| Exécution | ||||||
| Crash ReportsAnglaismacOS 10.15+ | /Library/Logs/DiagnosticReports/ | That a given executable ran on the Mac, from which path, launched by which parent, and when it crashed or hung | Local time with UTC offset in JSON strings and file names | root, or membership of _analyticsusers (admins are members) | Moved to Retired and cleaned up by SubmitDiagInfo; days to weeks | jq, mac_apt, Console |
| Historique du shell sous macOSmacOS 10.15+ | ~/.zsh_history | Quelles commandes un utilisateur a tapées dans un shell interactif, dans quel ordre, et dans quelle fenêtre du Terminal | Aucun par défaut ; secondes d'époque Unix uniquement si EXTENDED_HISTORY (zsh) ou HISTTIMEFORMAT (bash) est défini | Propriétaire du fichier ou root ; fichiers texte dans le dossier personnel | zsh : SAVEHIST=1000 lignes par défaut ; fichiers de session du Terminal supprimés après environ deux semaines | mac_apt, grep, sed |
| InstallHistory.plistAnglaismacOS 10.15+ | /Library/Receipts/InstallHistory.plist | Which software packages and updates were installed, when, and through which installer process | Plist date values (UTC); receipt install-time in Unix epoch seconds | Readable by all users; InstallHistory.plist is writable by the admin group | Until deleted; receipts until pkgutil --forget or removal | mac_apt, Plaso, pkgutil, plutil |
| Mounted Disk Images on macOSAnglaismacOS 10.15+ | /Volumes/<name>/ (mount point), plus logs and per-user caches | That a disk image was mounted, under which volume name, which apps were run from it and where it came from | Unified Log entries in UTC; FSEvents event IDs; file system times of the image and translocation folders | root for logs and /private/var/folders; owning user for Downloads | Log events follow rotation; the image file, quarantine and FSEvents records persist longer | hdiutil, log, FSEventsParser, mac_apt, xattr |
| sudo LogsAnglaismacOS 10.15+ | /private/var/db/diagnostics/ | Which account ran which command as root (or another user), from which directory and terminal, and failed attempts | Unified Logs: timestamp with UTC offset; ts files: file mtime plus monotonic counters | root to read the log store, /etc/sudoers and /var/db/sudo | Unified Log rotation (days to weeks); ts records until reboot or overwrite | log, macos-UnifiedLogs, mac_apt, Plaso |
| TCC.dbmacOS 10.15+ | /Library/Application Support/com.apple.TCC/TCC.db | Quels programmes ont demandé ou obtenu des autorisations de confidentialité sensibles, par qui, et quand la décision a changé pour la dernière fois | Secondes d'époque Unix (UTC) dans last_modified | Accès complet au disque pour la lecture ; base système également protégée par SIP | Jusqu'à la modification de la ligne, sa réinitialisation (tccutil) ou la suppression de l'application | mac_apt, Plaso, Velociraptor, sqlite3 |
| Traces de Gatekeeper et XProtect sous macOSmacOS 10.15+ | /var/db/SystemPolicyConfiguration/ExecPolicy | Si macOS a évalué, autorisé, bloqué ou neutralisé un programme donné, et quels comportements il a signalés | Unified log : affiché dans le fuseau enregistré avec chaque entrée sauf si --timezone est passé ; dt de XPdb : date-heure textuelle ; ExecPolicy : secondes Unix | root ; accès complet au disque ; XPdb est un Data Vault à partir de 26.2 | Unified log : quelques jours à quelques semaines ; bases : jusqu'à leur reconstruction (variable) | log, mac_apt, sqlite3 |
| Persistance | ||||||
| Configuration Profiles and MDMAnglaismacOS 10.15+ | /private/var/db/ConfigurationProfiles/ | Which profiles and payloads (certificates, proxies, VPN, TCC/PPPC, system extensions, login items) were installed, by MDM or manually, and when | Install dates in the profile store (plist dates); Unified Log entries in UTC | root; the profile store is SIP-protected on current releases, read it from an image or with profiles(1) live | Profiles persist until removed; install events follow Unified Log rotation | profiles, log, plutil, macos-UnifiedLogs |
| cron, at and periodicAnglaismacOS 10.15+ | /usr/lib/cron/tabs/ | Whether a command was scheduled to run repeatedly or once through a Unix-style scheduler, by which account | File system times of tab and job files (APFS, UTC); cron schedules are in local time | root (tabs directory is mode 700) | Until the crontab, job or script is removed | crontab, mac_apt, Aftermath |
| Éléments de connexion et base BTM sous macOSmacOS 10.15+ | /private/var/db/com.apple.backgroundtaskmanagement/BackgroundItems-v*.btm | Quels éléments de connexion, agents et démons ont été enregistrés, par quel développeur, et s'ils ont été autorisés | Dates NSKeyedArchiver (temps absolu Mac, UTC) plus dates du système de fichiers | root et accès complet au disque (magasin BTM) ; utilisateur propriétaire (ancien backgrounditems.btm) | Jusqu'au retrait de l'élément ou à la reconstruction du magasin par sfltool resetbtm | DumpBTM, bgiparser, Plaso, sfltool |
| Kernel and System ExtensionsAnglaismacOS 10.15+ | /Library/SystemExtensions/db.plist and /private/var/db/SystemPolicyConfiguration/KextPolicy | Which third-party kernel extensions and system extensions were installed, approved, activated or loaded, by which team ID, and when | KextPolicy created_at / last_seen as date-time values (check the storage type per image); Unified Log entries in UTC | root; KextPolicy is SIP-protected, read it from an image or with Full Disk Access | Records persist until the extension is removed and often after; Unified Log events follow rotation | kmutil, systemextensionsctl, sqlite3, plutil, KnockKnock, APOLLO |
| LaunchAgents et LaunchDaemonsmacOS 10.15+ | ~/Library/LaunchAgents, /Library/LaunchAgents, /Library/LaunchDaemons | Quel code est configuré pour démarrer automatiquement, sous quel utilisateur, sur quel déclencheur, et depuis quand | Aucun horodatage interne ; dates de fichier APFS (nanosecondes, UTC) | Agents utilisateur : utilisateur propriétaire ; /Library : root ; accès complet au disque recommandé pour l'outil de collecte | Jusqu'à la suppression du plist ; les overrides et les enregistrements BTM peuvent lui survivre | mac_apt, Plaso, KnockKnock, plutil |
| Accès aux fichiers | ||||||
| Cloud Storage Clients on MacAnglaismacOS 10.15+ | ~/Library/CloudStorage/ plus each client's Application Support, Group Container and log folders | Which cloud accounts were linked, which files existed in or passed through the synced folders, and when they were uploaded, downloaded or deleted | Mixed: Unix epoch (seconds or milliseconds) in most client databases, Mac absolute time in File Provider data, local time in some logs | Owning user; some client databases are encrypted or obfuscated and need the user's keychain | Databases track the current sync state; logs rotate by size and age; deleted files may remain in the cloud service's own trash | sqlite3, FSEventsParser, plutil, grep |
| CUPS Print Jobs and LogsAnglaismacOS 10.15+ | /private/var/spool/cups/ and /private/var/log/cups/ | Which user printed which job (document name and application), to which printer, when, and how many pages or copies | IPP attributes time-at-creation / processing / completed in Unix epoch seconds; log lines in local time with UTC offset | root for the spool and logs; printers.conf readable by root | Control files for up to the configured job history (default 500 jobs); data files usually removed after the job; logs rotate by size | mac_apt, lpstat, grep |
| FSEvents (.fseventsd)macOS 10.15+ | /System/Volumes/Data/.fseventsd/ | Quels chemins ont été créés, modifiés, renommés ou supprimés sur un volume, dans l'ordre des événements | Aucun par enregistrement ; estimation à partir du mtime des fichiers journaux et des chemins datés | root ; accès complet au disque sur un système live | Glissante, purgée par fseventsd (plusieurs mois observés, variable) | FSEventsParser, mac_apt |
| Horodatages APFS et snapshots locaux sous macOSmacOS 10.15+ | /System/Volumes/Data | Quand des fichiers ont été créés, modifiés et ajoutés à un dossier, et à quoi ressemblait le volume quelques heures plus tôt | Nanosecondes depuis le 1970-01-01 UTC (époque Unix) | Tout utilisateur pour stat sur ses propres fichiers ; root plus accès complet au disque pour monter des snapshots | Horodatages jusqu'à écrasement ; snapshots locaux horaires conservés environ 24 heures | libfsapfs, stat, mac_apt |
| iCloud Drive (CloudDocs)AnglaismacOS 10.15+ | ~/Library/Application Support/CloudDocs/session/db/client.db | Which files were in the user's iCloud Drive, when, and from which of their devices | Unix epoch seconds (UTC) in CloudDocs databases | User or root; Full Disk Access for the collector on a live system | Current sync state; items leave when deleted and purged from iCloud | mac_apt, sqlite3 |
| Microsoft Office and Outlook for MacAnglaismacOS 10.15+ | ~/Library/Containers/com.microsoft.<App>/ and ~/Library/Group Containers/UBF8T346G9.Office/ | Which documents were opened in Word, Excel and PowerPoint, from which paths and when, the Office user identity, and the local copy of Outlook mail | Plist dates (kLastUsedDateKey); Windows FILETIME in MicrosoftRegistrationDB.reg; Outlook database dates per schema | Owning user; Group Containers and Containers need Full Disk Access to collect on current releases | MRU lists hold a limited number of entries; Outlook caches follow account sync settings | mac_apt, plutil, sqlite3 |
| Photos.sqliteAnglaismacOS 10.15+ | ~/Pictures/Photos Library.photoslibrary/database/Photos.sqlite | When media was captured, added, edited, hidden or trashed, where it was taken and which app or device imported it | Mac absolute time (seconds since 2001-01-01 UTC); time zone offset per asset | TCC-protected library: Full Disk Access (or Photos access) for the collector | Until deleted; Recently Deleted items are purged after 30 days | osxphotos, exiftool, sqlite3 |
| QuarantineEventsV2 et xattr de quarantaine sous macOSmacOS 10.15+ | ~/Library/Preferences/com.apple.LaunchServices.QuarantineEventsV2 | Quels fichiers un utilisateur a téléchargés, depuis quelle URL et quelle page d'origine, avec quelle application, et quand | Base : temps absolu Mac (UTC) ; xattr : secondes Unix en hexadécimal (UTC) | Utilisateur propriétaire ou root ; accès complet au disque recommandé pour l'outil de collecte | Jusqu'à suppression ou effacement (aucune purge automatique documentée) | mac_apt, Plaso, Velociraptor, sqlite3 |
| QuickLook Thumbnail CacheAnglaismacOS 10.15+ | $(getconf DARWIN_USER_CACHE_DIR)/com.apple.quicklook.ThumbnailsAgent/com.apple.QuickLook.thumbnailcache/ | That a file existed at a path and was displayed as a thumbnail or preview, with a cached image that can outlive the original | last_hit_date in Mac absolute time; file modification time stored in the version blob | Owning user or root; the cache sits under /private/var/folders, collect as root | Cache is pruned by size and age and rebuilt with qlmanage -r cache; not a long-term record | mac_apt, sqlite3, plutil |
| Recent Items (.sfl2/.sfl3)AnglaismacOS 10.15+ | ~/Library/Application Support/com.apple.sharedfilelist/ | Which documents, apps and servers a user recently opened, with full paths and source volumes | Mostly none per item; bookmark dates in Mac absolute time (2001 epoch) | User-owned; Full Disk Access for the collector on a live system | Rolling lists capped by the Recent Items count (default 10) | mac_apt, plutil |
| Spotlight Store (.Spotlight-V100)AnglaismacOS 10.15+ | /System/Volumes/Data/.Spotlight-V100/Store-V2/<UUID>/store.db | Where a file came from, when it was added and opened, and that it existed even after deletion | Mac absolute time (seconds since 2001-01-01 UTC); mdls shows UTC | root; Full Disk Access on a live system | Until the indexer updates or purges the entry, or the index is rebuilt | spotlight_parser, mac_apt |
| Time Machine BackupsAnglaismacOS 10.15+ | /Library/Preferences/com.apple.TimeMachine.plist | Which backup destinations were used, when backups ran, and what files looked like at each backup | Backup names YYYY-MM-DD-HHMMSS; plist dates as plist date objects | root plus Full Disk Access for tmutil listbackups and backup contents | Hourly 24 h, daily for a month, weekly after; oldest deleted when full | tmutil, Plaso, plutil |
| Activité utilisateur | ||||||
| Apple MailAnglaismacOS 10.15+ | ~/Library/Mail/V10/MailData/Envelope Index | Which emails were sent or received, from and to whom, when, in which mailbox, and which attachments were opened | Envelope Index dates in Unix epoch seconds (UTC); message headers in RFC 5322 local time | TCC-protected (Mail data): Full Disk Access for the collector | Until deleted or removed from the server; local copies follow account sync settings | sqlite3, emlx (Python) |
| Apple Notes NoteStore.sqliteAnglaismacOS 10.15+ | ~/Library/Group Containers/group.com.apple.notes/NoteStore.sqlite | What a user wrote in Notes, when each note was created and last modified, attachments, folders, iCloud or local account, and deleted notes still in the database | Mac absolute time (seconds since 2001-01-01 UTC) | Owning user; the group container is TCC-protected, so the collector needs Full Disk Access | Until deleted; Recently Deleted keeps notes for about 30 days, and freed pages may survive in the WAL or free list | apple_cloud_notes_parser, mac_apt, sqlite3 |
| Calendar, Contacts and Reminders Databases on macOSAnglaismacOS 10.15+ | ~/Library/Application Support/AddressBook/, ~/Library/Group Containers/group.com.apple.reminders/, ~/Library/Calendars/ or group.com.apple.calendar | Who the user knew and how to reach them, which meetings and appointments existed, where and with whom, and which tasks were created or completed | Mac absolute time (seconds since 2001-01-01 UTC) in all three Core Data stores | Owning user; each store is TCC-protected (Contacts, Calendars, Reminders), so the collector needs Full Disk Access | Until deleted locally or through sync; deleted items may persist briefly for sync and in WAL files | sqlite3, APOLLO, plutil |
| Chrome and Firefox History on macOSAnglaismacOS 10.15+ | ~/Library/Application Support/Google/Chrome/Default/History | Which sites a user opened in Chrome, Chromium browsers or Firefox, when, and what they downloaded | Chrome: microseconds since 1601-01-01 UTC; Firefox PRTime: microseconds since 1970-01-01 UTC | File owner or root; give the collector Full Disk Access as well | Chrome: about 90 days of visits; Firefox: size-based expiration of old pages | Hindsight, mac_apt, sqlite3 |
| Dock and Finder PlistsAnglaismacOS 10.15+ | ~/Library/Preferences/com.apple.finder.plist | Which apps a user kept or recently ran in the Dock, and which folders, paths and servers they visited in Finder | Few per key; Dock tile dates in HFS+ seconds (1904 epoch) | User-owned; Full Disk Access for the collector on a live system | Until the preference changes or the user resets it | mac_apt, plutil |
| dslocal User AccountsAnglaismacOS 10.15+ | /private/var/db/dslocal/nodes/Default/users/<name>.plist | Which local accounts exist, when they were created, who is admin, and recent password and failed-login activity | accountPolicyData: Unix epoch seconds (UTC) | root; Full Disk Access recommended for the collector | Until the account is deleted; home may survive in /Users/Deleted Users | mac_apt, Velociraptor, plutil, dscl |
| Flux Biome SEGBmacOS 12+ | ~/Library/Biome/streams/restricted/<Stream>/local/ | Quelles applications étaient au premier plan, quels sites ont été visités, quels appareils et réseaux ont été connectés, avec une heure par enregistrement | Temps absolu Mac (Cocoa) en doubles dans les enregistrements SEGB ; noms de fichiers en temps Cocoa exprimé en microsecondes | Accès complet au disque (flux utilisateur) ; flux système restreints par SIP | Quelques semaines pour la plupart des flux (environ 28 jours, chiffre issu de recherches sur iOS) ; les fichiers expirés passent dans tombstone | mac_apt, ccl-segb |
| knowledgeC.dbmacOS 10.15+ | /private/var/db/CoreDuet/Knowledge/knowledgeC.db | Quelles applications étaient utilisées, quand et combien de temps, et si l'écran était allumé à ce moment-là | Temps absolu Mac (secondes depuis le 2001-01-01 UTC), plus le décalage ZSECONDSFROMGMT | root plus restrictions SIP (base système) ; accès complet au disque (base utilisateur) | Environ quatre semaines d'événements sur un système typique (variable selon le flux) | APOLLO, Plaso, sqlite3 |
| macOS Keychain FilesAnglaismacOS 10.15+ | ~/Library/Keychains/ | Which accounts, services, networks and certificates a user had saved, and when items were created or modified | File keychain: UTC strings YYYYMMDDhhmmssZ; keychain-2.db: Mac absolute time | Owning user or root; secrets need user credentials and, for data protection items, the original device | Until the item or keychain is deleted | security, sqlite3 |
| Messages chat.dbAnglaismacOS 10.15+ | ~/Library/Messages/chat.db | Who communicated with whom, what was said, when it was sent, delivered and read, and which files were exchanged | Nanoseconds since 2001-01-01 UTC (High Sierra+); older rows in seconds | TCC-protected (Messages data): Full Disk Access for the collector | Until deleted; Recently Deleted keeps items up to 30 days (Ventura+) | imessage-exporter, mac_apt, Plaso, sqlite3 |
| Notification Center DatabaseAnglaismacOS 10.15+ | ~/Library/Group Containers/group.com.apple.usernoted/db2/db | Which app showed which notification text to the user, and when it was delivered | Mac absolute time (seconds since 2001-01-01 UTC) | Sequoia+: TCC-protected group container (Full Disk Access); older: owning user | Not documented by Apple; varies, measure from oldest delivered_date | mac_apt, Plaso, sqlite3 |
| Safari History.dbmacOS 10.15+ | ~/Library/Safari/History.db | Quelles URL un utilisateur macOS a ouvertes dans Safari, quand, par quelles redirections, et si l'historique a été effacé | Temps absolu Mac (Cocoa, secondes depuis le 2001-01-01 UTC), stocké en REAL | Accès complet au disque pour le processus lecteur (TCC) ; root seul ne suffit pas | Réglage utilisateur, un an par défaut ou conservé jusqu'à effacement manuel ; liste des téléchargements : un jour par défaut | mac_apt, APOLLO, sqlite3, plutil |
| Saved Application StateAnglaismacOS 10.15+ | ~/Library/Saved Application State/<bundle-id>.savedState/ | Which apps were open with which windows, document titles and dock menu entries, and for Terminal, the text visible in each window | File system times of windows.plist and data.data (last state save) | Owning user; readable from an image or with Full Disk Access | Rewritten while the app runs; kept after quit when Close windows when quitting an app is off; deleted on clean quit otherwise | mac_apt, plutil |
| Screen Time DatabasesAnglaismacOS 10.15+ | /private/var/folders/<xx>/<id>/0/com.apple.ScreenTimeAgent/Store/ | How much time each app or web domain was used per period, on which device and by which Apple Account | Mac absolute time (seconds since 2001-01-01 UTC); durations in seconds | Owning user or root; extra protection on current macOS, image collection is most reliable | Not documented by Apple; measure from the oldest usage block | mac_apt, APOLLO, sqlite3 |
| Réseau | ||||||
| netusage.sqliteAnglaismacOS 10.15+ | /private/var/networkd/db/netusage.sqlite | That a process used the network, when it was first and last seen, how much data it moved per interface type, and which networks the Mac attached to | Mac absolute time (seconds since 2001-01-01 UTC) | root; the networkd folder is protected, collect with Full Disk Access or from an image | Rows persist for long periods; counters are cumulative and records are pruned by networkd on its own schedule | mac_apt, APOLLO, sqlite3 |
| Screen Sharing and Apple Remote Desktop ArtifactsAnglaismacOS 10.15+ | /private/var/db/RemoteManagement/ and ~/Library/Containers/com.apple.ScreenSharing/ | Who connected to this Mac over VNC / Screen Sharing or ARD, from which address and when, and which hosts this Mac's user controlled | Unified Log entries in UTC; plist dates and ARD caches in Mac absolute time | root for /private/var/db/RemoteManagement and the log store; owning user for the Screen Sharing container | Log events follow Unified Log rotation; connection history and ARD caches persist until cleared | log, mac_apt, plutil, macos-UnifiedLogs |
| SSH and Remote Login on macOSAnglaismacOS 10.15+ | ~/.ssh/ and /private/etc/ssh/ | Inbound SSH logons (who, from which IP, with which key or password), outbound SSH targets, and key-based persistence | Unified Log entries in UTC; file system times of authorized_keys, known_hosts and host keys | Owning user for ~/.ssh; root for /private/etc/ssh and the log store | Key files until edited; sshd events follow Unified Log rotation (days to weeks) | log, macos-UnifiedLogs, ssh-keygen, stat, grep |
| Wi-Fi Known Networks on macOSAnglaismacOS 10.15+ | /Library/Preferences/com.apple.wifi.known-networks.plist | Which Wi-Fi networks and access points a Mac joined, when first added, and when last joined by the user or system | Plist date objects (stored as Mac absolute time, shown in UTC); wifi.log in local time | root (known-networks plist is 0600 root:wheel on current macOS) | Known networks until the user forgets them; wifi.log rotated daily, about 10 archives | mac_apt, plutil |
| USB et périphériques | ||||||
| Bluetooth Devices on macOSAnglaismacOS 10.15+ | /Library/Bluetooth/Library/Preferences/com.apple.MobileBluetooth.devices.plist | Which Bluetooth devices were paired with or seen by a Mac, their names and vendors, and when they were last seen | LastSeenTime: Unix epoch seconds; legacy plist dates: plist date objects (UTC) | root (files under /Library/Bluetooth are root-only on current macOS) | Paired devices until removed; LE 'other' cache and logs roll over | mac_apt, APOLLO, plutil, sqlite3 |
| iPhone Backups and Pairing Records on a MacAnglaismacOS 10.15+ | ~/Library/Application Support/MobileSync/Backup/<UDID>/ | Which iPhone or iPad was paired with and backed up to this Mac, when, whether the backup is encrypted, and the full content of the device at backup time | Plist dates in Info.plist and Status.plist; file system times of the backup folder | Owning user for MobileSync (TCC-protected, Full Disk Access needed); root for /private/var/db/lockdown | Backups persist until deleted in Finder; pairing records until the device is untrusted or the OS is reinstalled | iLEAPP, MVT, mac_apt, plutil, sqlite3 |
| USB DevicesAnglaismacOS 10.15+ | /private/var/db/diagnostics/ | Which USB storage devices were attached, when volumes were mounted, and which files were touched on them | Unified Logs UTC instants; FSEvents has no per-record time | root for the log store and .fseventsd; live commands need no special rights | Unified Log rotation (days to weeks); FSEvents until pages are purged | log, macos-UnifiedLogs, mac_apt, FSEventsParser |
| Anti-forensique | ||||||
| macOS Trash and .DS_StoreAnglaismacOS 10.15+ | ~/.Trash/ and /Volumes/<volume>/.Trashes/<uid>/ | Which files a user moved to the Trash, their original folder and name, and roughly when they were trashed | File system times of the trashed item (ctime changes on the move); .DS_Store modD/moDD in Mac absolute time | Owning user; ~/.Trash is TCC-protected for other apps, so the collector needs Full Disk Access | Until the Trash is emptied, or 30 days if Remove items from the Trash after 30 days is enabled | mac_apt, DSStoreParser, stat |
| Journaux | ||||||
| System LogsAnglaismacOS 10.15+ | /private/var/log/ | Install, update, Wi-Fi and legacy syslog activity, often beyond Unified Log retention | Local time; install.log uses ISO-style time with UTC offset, BSD syslog lines have no year | admin group or root (system.log and wifi.log are mode 640, group admin) | Size or daily rotation set in /etc/asl.conf, /etc/asl/ and /etc/newsyslog.d/ | Plaso, mac_apt, syslog, grep |
| Unified LogsmacOS 10.15+ | /private/var/db/diagnostics/ | Ce que les processus et sous-systèmes ont signalé, et quand : connexions, élévations de privilèges, contrôles de sécurité, périphériques | Temps Mach converti via les enregistrements timesync ; log show affiche de l'ISO 8601 avec décalage UTC | root (le groupe admin peut lire le magasin) ; log collect nécessite sudo | Rotation par taille, en général de quelques jours à quelques semaines | log, macos-UnifiedLogs, Plaso, mac_apt |
L'acquisition de la mémoire sous macOS sort du cadre de ces pages ; voir mac-dump : github.com/Cyber-Experts/mac-dump