Glossary
LaunchAgent / LaunchDaemon
Property lists that tell launchd to start a program automatically, per user or system-wide; a classic macOS persistence place.
A LaunchAgent is a property list (.plist) that tells launchd to start a program automatically on behalf of a user, typically at login (RunAtLoad), on a schedule or to keep it running (KeepAlive). Per-user agents live in ~/Library/LaunchAgents, agents for all users in /Library/LaunchAgents. A LaunchDaemon is the system-wide equivalent in /Library/LaunchDaemons: it runs as root at boot, without anyone logging in. Apple's own agents and daemons sit under /System/Library on the read-only system volume.
Why it matters in investigations
These folders are among the most common persistence locations on macOS. Legitimate updaters and helpers use them every day, and so does malware, because a plist is easy to drop and survives reboots. The plist names the program to run in ProgramArguments, so the file itself is the best evidence, when it still exists.
FSEvents often keeps the story after the file is gone. A record in Users/<name>/Library/LaunchAgents/ or Library/LaunchDaemons/ shows the plist was created, renamed, modified or removed, and the node ID links a temporary name to the final one. The FSEvents Parser raises a finding for writes directly inside these folders. FSEvents cannot tell you what the plist contained or whether launchd loaded it: pair it with the plist content, Unified Logs and the program's own traces.
Example
In the synthetic sample, com.example.updater.plist reaches the user's agents folder through a rename:
Users/dana.whitlock/Library/LaunchAgents/com.example.updater.plist.tmp:Created;Modified;File- the
.tmpname, thencom.example.updater.plist:Renamed;File, same node ID com.example.updater.plist:InodeMetaMod;File
All three sit in the log window 10:09:55 to 10:23:18 UTC, shortly after a TCC.db write, a sequence worth explaining.
Related terms
Filter LaunchAgents in the FSEvents Parser, and see this persistence step in context in the Mac exfiltration walkthrough.