<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>FSEvents Parser — Blog</title>
    <link>https://www.fseventsparser.com/en/blog</link>
    <description>Latest from Blog</description>
    <language>en</language>
    <lastBuildDate>Wed, 30 Sep 2026 00:50:48 GMT</lastBuildDate>
    <atom:link href="https://www.fseventsparser.com/en/blog/feed.xml" rel="self" type="application/rss+xml"/>
    <item>
      <title>Collect .fseventsd: tar, UAC, Aftermath, Velociraptor</title>
      <link>https://www.fseventsparser.com/en/blog/collect-fseventsd-tar-uac-velociraptor</link>
      <guid isPermaLink="true">https://www.fseventsparser.com/en/blog/collect-fseventsd-tar-uac-velociraptor</guid>
      <description>How to collect macOS FSEvents logs without losing their modification times: one tar command, UAC profiles, Aftermath, Velociraptor and disk images.</description>
      <author>Florian Amette</author>
      <pubDate>Wed, 30 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>FSEvents Investigation: A Mac Exfiltration Walkthrough</title>
      <link>https://www.fseventsparser.com/en/blog/fsevents-exfiltration-walkthrough</link>
      <guid isPermaLink="true">https://www.fseventsparser.com/en/blog/fsevents-exfiltration-walkthrough</guid>
      <description>A fictional macOS intrusion traced with FSEvents alone: a download, a LaunchAgent, Full Disk Access, a hidden staging folder, a USB stick and the cleanup.</description>
      <author>Florian Amette</author>
      <pubDate>Wed, 30 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>FSEvents File Format: 1SLD, 2SLD and 3SLD Pages</title>
      <link>https://www.fseventsparser.com/en/blog/fsevents-file-format-1sld-2sld-3sld</link>
      <guid isPermaLink="true">https://www.fseventsparser.com/en/blog/fsevents-file-format-1sld-2sld-3sld</guid>
      <description>The on-disk layout of macOS .fseventsd logs: gzip files, DLS page headers, record fields per version, and how to handle truncated or corrupt data.</description>
      <author>Florian Amette</author>
      <pubDate>Wed, 30 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>FSEvents Flags Explained: Every Bit, Decoded</title>
      <link>https://www.fseventsparser.com/en/blog/fsevents-flags-explained</link>
      <guid isPermaLink="true">https://www.fseventsparser.com/en/blog/fsevents-flags-explained</guid>
      <description>Every on-disk FSEvents flag bit with its value, the names FSEventsParser and mac_apt use, and how to read Created, Renamed, ItemCloned or EndOfTransaction.</description>
      <author>Florian Amette</author>
      <pubDate>Wed, 30 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>macOS FSEvents Forensics: What .fseventsd Proves</title>
      <link>https://www.fseventsparser.com/en/blog/fsevents-forensics-guide</link>
      <guid isPermaLink="true">https://www.fseventsparser.com/en/blog/fsevents-forensics-guide</guid>
      <description>What the macOS FSEvents log records, where .fseventsd lives, what it can and cannot prove, and how to read it without exact timestamps.</description>
      <author>Florian Amette</author>
      <pubDate>Wed, 30 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Dating FSEvents Records Without Timestamps</title>
      <link>https://www.fseventsparser.com/en/blog/fsevents-timestamps-time-windows</link>
      <guid isPermaLink="true">https://www.fseventsparser.com/en/blog/fsevents-timestamps-time-windows</guid>
      <description>FSEvents records have no time. How to build honest time windows from .fseventsd log file modification times, uuid files and dated paths, and when they fail.</description>
      <author>Florian Amette</author>
      <pubDate>Wed, 30 Sep 2026 00:00:00 GMT</pubDate>
    </item>
  </channel>
</rss>