Collect .fseventsd: tar, UAC, Aftermath, Velociraptor
How to collect macOS FSEvents logs without losing their modification times: one tar command, UAC profiles, Aftermath, Velociraptor and disk images.
How to collect macOS FSEvents logs without losing their modification times: one tar command, UAC profiles, Aftermath, Velociraptor and disk images.
A fictional macOS intrusion traced with FSEvents alone: a download, a LaunchAgent, Full Disk Access, a hidden staging folder, a USB stick and the cleanup.
The on-disk layout of macOS .fseventsd logs: gzip files, DLS page headers, record fields per version, and how to handle truncated or corrupt data.
Every on-disk FSEvents flag bit with its value, the names FSEventsParser and mac_apt use, and how to read Created, Renamed, ItemCloned or EndOfTransaction.
What the macOS FSEvents log records, where .fseventsd lives, what it can and cannot prove, and how to read it without exact timestamps.
FSEvents records have no time. How to build honest time windows from .fseventsd log file modification times, uuid files and dated paths, and when they fail.