Skip to content

Series

FSEvents fundamentals

4 posts in this series. Read them in order or jump to any one.

  1. macOS FSEvents Forensics: What .fseventsd Proves

    What the macOS FSEvents log records, where .fseventsd lives, what it can and cannot prove, and how to read it without exact timestamps.

  2. Collect .fseventsd: tar, UAC, Aftermath, Velociraptor

    How to collect macOS FSEvents logs without losing their modification times: one tar command, UAC profiles, Aftermath, Velociraptor and disk images.

  3. FSEvents File Format: 1SLD, 2SLD and 3SLD Pages

    The on-disk layout of macOS .fseventsd logs: gzip files, DLS page headers, record fields per version, and how to handle truncated or corrupt data.

  4. FSEvents Flags Explained: Every Bit, Decoded

    Every on-disk FSEvents flag bit with its value, the names FSEventsParser and mac_apt use, and how to read Created, Renamed, ItemCloned or EndOfTransaction.

All posts in this series