macOS FSEvents Forensics: What .fseventsd Proves
What the macOS FSEvents log records, where .fseventsd lives, what it can and cannot prove, and how to read it without exact timestamps.
Series
4 posts in this series. Read them in order or jump to any one.
What the macOS FSEvents log records, where .fseventsd lives, what it can and cannot prove, and how to read it without exact timestamps.
How to collect macOS FSEvents logs without losing their modification times: one tar command, UAC profiles, Aftermath, Velociraptor and disk images.
The on-disk layout of macOS .fseventsd logs: gzip files, DLS page headers, record fields per version, and how to handle truncated or corrupt data.
Every on-disk FSEvents flag bit with its value, the names FSEventsParser and mac_apt use, and how to read Created, Renamed, ItemCloned or EndOfTransaction.
What the macOS FSEvents log records, where .fseventsd lives, what it can and cannot prove, and how to read it without exact timestamps.
How to collect macOS FSEvents logs without losing their modification times: one tar command, UAC profiles, Aftermath, Velociraptor and disk images.
The on-disk layout of macOS .fseventsd logs: gzip files, DLS page headers, record fields per version, and how to handle truncated or corrupt data.
Every on-disk FSEvents flag bit with its value, the names FSEventsParser and mac_apt use, and how to read Created, Renamed, ItemCloned or EndOfTransaction.