<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>FSEvents Parser — Blog</title>
    <link>https://www.fseventsparser.com/es/blog</link>
    <description>Latest from Blog</description>
    <language>es</language>
    <lastBuildDate>Wed, 30 Sep 2026 00:50:48 GMT</lastBuildDate>
    <atom:link href="https://www.fseventsparser.com/es/blog/feed.xml" rel="self" type="application/rss+xml"/>
    <item>
      <title>Adquirir .fseventsd: tar, UAC, Aftermath, Velociraptor</title>
      <link>https://www.fseventsparser.com/es/blog/collect-fseventsd-tar-uac-velociraptor</link>
      <guid isPermaLink="true">https://www.fseventsparser.com/es/blog/collect-fseventsd-tar-uac-velociraptor</guid>
      <description>Cómo recopilar los registros FSEvents de macOS sin perder sus fechas de modificación: un comando tar, perfiles UAC, Aftermath, Velociraptor e imágenes.</description>
      <author>Florian Amette</author>
      <pubDate>Wed, 30 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Investigación con FSEvents: exfiltración en un Mac</title>
      <link>https://www.fseventsparser.com/es/blog/fsevents-exfiltration-walkthrough</link>
      <guid isPermaLink="true">https://www.fseventsparser.com/es/blog/fsevents-exfiltration-walkthrough</guid>
      <description>Una intrusión ficticia en macOS reconstruida solo con FSEvents: una descarga, un LaunchAgent, Acceso total al disco, una carpeta oculta, un USB y la limpieza.</description>
      <author>Florian Amette</author>
      <pubDate>Wed, 30 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Formato de archivo FSEvents: páginas 1SLD, 2SLD y 3SLD</title>
      <link>https://www.fseventsparser.com/es/blog/fsevents-file-format-1sld-2sld-3sld</link>
      <guid isPermaLink="true">https://www.fseventsparser.com/es/blog/fsevents-file-format-1sld-2sld-3sld</guid>
      <description>Estructura en disco de los logs .fseventsd de macOS: archivos gzip, cabeceras de página DLS, campos por versión y cómo tratar datos truncados o dañados.</description>
      <author>Florian Amette</author>
      <pubDate>Wed, 30 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Flags de FSEvents explicados: cada bit, decodificado</title>
      <link>https://www.fseventsparser.com/es/blog/fsevents-flags-explained</link>
      <guid isPermaLink="true">https://www.fseventsparser.com/es/blog/fsevents-flags-explained</guid>
      <description>Todos los bits de flags de FSEvents en disco con su valor, sus nombres en FSEventsParser y mac_apt, y cómo leer Created, Renamed, ItemCloned o EndOfTransaction.</description>
      <author>Florian Amette</author>
      <pubDate>Wed, 30 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Forense de FSEvents en macOS: qué prueba .fseventsd</title>
      <link>https://www.fseventsparser.com/es/blog/fsevents-forensics-guide</link>
      <guid isPermaLink="true">https://www.fseventsparser.com/es/blog/fsevents-forensics-guide</guid>
      <description>Qué registra FSEvents en macOS, dónde está .fseventsd, qué puede y qué no puede probar, y cómo leerlo sin marcas de tiempo exactas.</description>
      <author>Florian Amette</author>
      <pubDate>Wed, 30 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Cómo datar registros FSEvents sin marcas de tiempo</title>
      <link>https://www.fseventsparser.com/es/blog/fsevents-timestamps-time-windows</link>
      <guid isPermaLink="true">https://www.fseventsparser.com/es/blog/fsevents-timestamps-time-windows</guid>
      <description>FSEvents no guarda horas. Cómo construir ventanas temporales fiables con las mtimes de .fseventsd, fseventsd-uuid y rutas fechadas, y cuándo fallan.</description>
      <author>Florian Amette</author>
      <pubDate>Wed, 30 Sep 2026 00:00:00 GMT</pubDate>
    </item>
  </channel>
</rss>