Collect .fseventsd: tar, UAC, Aftermath, Velociraptor
How to collect macOS FSEvents logs without losing their modification times: one tar command, UAC profiles, Aftermath, Velociraptor and disk images.
TL;DR. Archive the whole folder, keep modification times, write nothing to the evidence. On a live Mac, give Terminal Full Disk Access and run sudo tar -czf ~/Desktop/fseventsd.tar.gz -C /System/Volumes/Data .fseventsd. UAC's ir_triage profile does the same as part of a wider collection. Both archives can be dropped into the FSEvents Parser as they are. The quick reference for this artifact is on the FSEvents cheat sheet.
What to collect
| Path | Why |
|---|---|
/System/Volumes/Data/.fseventsd/ | macOS 10.15 and later: user activity, Users/…, private/…, Library/… |
/.fseventsd/ | macOS 10.14 and earlier (boot volume) |
/Volumes/<name>/.fseventsd/ | Each external drive, if you have it |
Take every file in the folder: the hex-named logs, fseventsd-uuid and no_log if present. The parser uses fseventsd-uuid's time as the lower bound of the oldest log, and a missing no_log is itself information (see no_log).
Modification times are the evidence. A record's time window comes from the log files' mtimes (why). tar, ditto and cp -p keep them; AirDrop, e-mail and many cloud uploads do not.
Live Mac: one command
First grant Terminal Full Disk Access (System Settings → Privacy & Security → Full Disk Access). Without it, reading the folder fails with "Operation not permitted", even as root.
sudo tar -czf ~/Desktop/fseventsd-$(hostname -s).tar.gz -C /System/Volumes/Data .fseventsd
For an attached external drive, archive its own folder the same way:
sudo tar -czf ~/Desktop/fseventsd-EXFIL.tar.gz -C /Volumes/EXFIL .fseventsd
Prefer a plain folder? ditto keeps modification times too, and a listing documents them independently:
sudo ditto /System/Volumes/Data/.fseventsd ~/Desktop/fseventsd
sudo ls -laT /System/Volumes/Data/.fseventsd > ~/Desktop/fseventsd-listing.txt
On macOS 10.14 and earlier, replace -C /System/Volumes/Data with -C /.
fseventsd keeps writing while you collect: the newest log may be short or still in memory. That is expected; a good parser keeps every complete record and reports the rest.
UAC
UAC collects /.fseventsd and /System/Volumes/*/.fseventsd through its files/logs/macos.yaml artifact. The ir_triage and full profiles include it:
sudo ./uac -p ir_triage /Volumes/CASE
To collect only the logs artifact:
sudo ./uac -a ./artifacts/files/logs/macos.yaml /Volumes/CASE
Run it from a Terminal with Full Disk Access. The output is a tar.gz that keeps modification times; the FSEvents Parser streams through it and reads only the .fseventsd files.
Aftermath
Jamf's Aftermath does not collect .fseventsd by default. Add the folder explicitly:
sudo ./aftermath --collect-dirs /System/Volumes/Data/.fseventsd -o /Volumes/CASE
Drop the resulting ZIP, then check the Sources tab: if every log shows the same modification time, the times were not preserved and you should recollect with tar.
Velociraptor
Two options:
- Collect the raw files with
Generic.Collectors.File, Root/, and a collection spec listing/System/Volumes/Data/.fseventsd/*and/.fseventsd/*. Drop the collection ZIP, then verify the times in the Sources tab as above. - Parse on the endpoint with
MacOS.Forensics.FSEvents, which reports each record with its source file's times. It is good for hunting across many Macs; its output is a Velociraptor result table, not files this page reads. Its defaultMaxFileSizeis 10 MB and its timeout 600 seconds; raise both for large folders.
Disk images
Attach the image read-only and without Finder, then archive the Data volume's folder:
hdiutil attach -readonly -nobrowse /cases/MBP01.dmg
sudo tar -czf ~/Desktop/fseventsd-image.tar.gz -C "/Volumes/Macintosh HD - Data" .fseventsd
Never attach evidence read-write on your analysis Mac: its own fseventsd will start logging to the evidence volume. The same applies to USB drives: use a write blocker. For E01 images, mac_apt's FSEVENTS plugin reads the folder directly and is a useful second opinion.
Checklist
- Full Disk Access for the collecting app.
- Whole folder, including
fseventsd-uuidandno_log. tar,ditto,cp -por UAC; keep mtimes.- External drives through a write blocker.
- After loading, confirm in the Sources tab that the mtimes look original.
FAQ
Why do file modification times matter for FSEvents?
FSEvents records have no timestamps. The modification time of each log file is the only clock, so a copy that resets those times makes every record undatable.
Does UAC collect .fseventsd?
Yes. The files/logs/macos.yaml artifact collects /.fseventsd and /System/Volumes/*/.fseventsd, and the ir_triage and full profiles include it. The output is a tar.gz that keeps modification times.
Why does tar fail with Operation not permitted?
The Terminal app lacks Full Disk Access. Grant it in System Settings, Privacy & Security, Full Disk Access, then run the command again with sudo.