Skip to content

Glossary

LaunchAgent / LaunchDaemon

Property lists that tell launchd to start a program automatically, per user or system-wide; a classic macOS persistence place.

A LaunchAgent is a property list (.plist) that tells launchd to start a program automatically on behalf of a user, typically at login (RunAtLoad), on a schedule or to keep it running (KeepAlive). Per-user agents live in ~/Library/LaunchAgents, agents for all users in /Library/LaunchAgents. A LaunchDaemon is the system-wide equivalent in /Library/LaunchDaemons: it runs as root at boot, without anyone logging in. Apple's own agents and daemons sit under /System/Library on the read-only system volume.

Why it matters in investigations

These folders are among the most common persistence locations on macOS. Legitimate updaters and helpers use them every day, and so does malware, because a plist is easy to drop and survives reboots. The plist names the program to run in ProgramArguments, so the file itself is the best evidence, when it still exists.

FSEvents often keeps the story after the file is gone. A record in Users/<name>/Library/LaunchAgents/ or Library/LaunchDaemons/ shows the plist was created, renamed, modified or removed, and the node ID links a temporary name to the final one. The FSEvents Parser raises a finding for writes directly inside these folders. FSEvents cannot tell you what the plist contained or whether launchd loaded it: pair it with the plist content, Unified Logs and the program's own traces.

Example

In the synthetic sample, com.example.updater.plist reaches the user's agents folder through a rename:

  • Users/dana.whitlock/Library/LaunchAgents/com.example.updater.plist.tmp: Created;Modified;File
  • the .tmp name, then com.example.updater.plist: Renamed;File, same node ID
  • com.example.updater.plist: InodeMetaMod;File

All three sit in the log window 10:09:55 to 10:23:18 UTC, shortly after a TCC.db write, a sequence worth explaining.

Filter LaunchAgents in the FSEvents Parser, and see this persistence step in context in the Mac exfiltration walkthrough.