Skip to content

Glossary

Data volume (/System/Volumes/Data)

The writable APFS volume holding user data since macOS 10.15; its .fseventsd folder carries most FSEvents evidence.

The Data volume is the writable APFS volume that has held user data since macOS 10.15 Catalina. The operating system itself lives on a separate read-only system volume, and the two are presented as one tree through firmlinks: /Users, /Applications or /Library look like normal folders on the startup disk, but their contents are stored on the Data volume, mounted at /System/Volumes/Data. In Finder or on a disk image it usually appears as "Macintosh HD - Data".

Why it matters in investigations

fseventsd only keeps a journal on volumes it can write to, so on macOS 10.15 and later the FSEvents history of user activity is in /System/Volumes/Data/.fseventsd. Collecting /.fseventsd alone on a modern Mac misses it. On macOS 10.14 and earlier there is a single boot volume and the folder is /.fseventsd.

Paths in the Data volume's journal are relative to the Data volume root, not to /. A record reads Users/dana/Downloads/tools.zip, Library/LaunchAgents/… or private/var/…, without a leading slash and without the System/Volumes/Data prefix. When correlating with other artifacts that use full paths, strip or add that prefix consistently.

The Data volume journal also logs mount and unmount events of other volumes under Volumes/<name>, which is how a USB stick shows up even when its own history was never collected.

Example

A live collection that keeps modification times:

sudo tar -czf ~/Desktop/fseventsd.tar.gz -C /System/Volumes/Data .fseventsd

From a mounted image, the same folder is under /Volumes/Macintosh HD - Data/.fseventsd. When loaded, the FSEvents Parser labels it as the Data volume and lists it separately from any external drive.

Drop the archive into the FSEvents Parser; the collection options are covered in how to collect .fseventsd.