Skip to content

Glossary

AppleDouble (._ files)

Companion ._name files macOS writes on FAT, exFAT and network volumes to store extended attributes and resource forks.

AppleDouble is the format macOS falls back on when a volume cannot store Mac metadata natively. On FAT32, exFAT and some network shares there is no place for extended attributes or a resource fork, so macOS writes them into a hidden companion file whose name is the original name prefixed with ._: ._report.pdf next to report.pdf. On APFS and HFS+ volumes the metadata stays attached to the file and no companion is created.

Why it matters in investigations

USB sticks and external drives sold for both Windows and Mac are usually formatted exFAT or FAT32, so AppleDouble files are a fingerprint of a Mac having written to them. When such a drive is imaged and its own .fseventsd folder is read, every file copied from the Mac that carried an extended attribute (a quarantine attribute, a where-from attribute, Finder tags) typically appears twice: once under its own name and once as ._name, created at almost the same event ID.

That pairing helps in three ways. It indicates the copy came from a Mac rather than from a Windows or Linux machine. It shows the files carried metadata, which can hint at their origin (a download, a mail attachment). And the ._ names survive on the drive after the originals are deleted, unless someone runs dot_clean or deletes them explicitly. The FSEvents Parser treats ._ paths as expected noise and leaves them out of its short-lived file finding.

Example

In the synthetic sample, the EXFIL stick's history contains, for each of 48 finance documents:

  • exfil/Q3-forecast-2026.xlsx with Created;Modified;File
  • exfil/._Q3-forecast-2026.xlsx with Created;Modified;File

Together with the Volumes/EXFIL mount record on the Mac's Data volume, this shows which files were written to the stick and that a Mac wrote them.

Load a drive's .fseventsd in the FSEvents Parser, and follow the full case in the Mac exfiltration walkthrough.