Skip to content

Glossary

Quarantine attribute (com.apple.quarantine)

The extended attribute macOS adds to downloaded files so Gatekeeper checks them on first open; removing it skips that check.

com.apple.quarantine is the extended attribute that browsers, mail clients and other quarantine-aware apps add to files they download. It records who quarantined the file and when; xattr -p com.apple.quarantine <file> typically prints a value of the form flags;hex time;agent;UUID, for example with Safari as the agent. On first launch of a quarantined app, Gatekeeper checks it and asks the user to confirm. Archive Utility passes the attribute on to the items it extracts.

Why it matters in investigations

Removing the attribute, for example with xattr -d com.apple.quarantine <file>, skips that first-launch check. Attackers and some installers do it so that an unsigned tool runs without a prompt, which makes its removal a lead worth following.

FSEvents sees attribute changes, not their names:

  • adding or changing any extended attribute sets ExtendedAttrModified;
  • removing one sets ExtendedAttrRemoved.

So a new download often shows ExtendedAttrModified (quarantine and where-from attributes being set), and a later ExtendedAttrRemoved on the same path means an attribute was removed. It could be the quarantine attribute, or something routine. Confirm with the file itself if it still exists, with the quarantine events database (com.apple.LaunchServices.QuarantineEventsV2 in the user's Library/Preferences), and with the surrounding records. The FSEvents Parser raises a finding when attributes are removed in download, desktop, documents, application and temporary folders.

Example

In the synthetic sample, Downloads/tools/sync-helper is extracted with Created;Modified;ExtendedAttrModified;File, then shows ExtendedAttrRemoved;File followed by InodeMetaMod;File (made executable), between 09:58:40 and 10:09:55 UTC, while Terminal is running.

Find removed attributes in the FSEvents Parser, and see how to read the flags in FSEvents flags explained.