Focus Files

Every Macintosh examination involves looking at the data in a unique manner that likely leads the analyst down a new path each time. Yet, we can usually say that each examination will have a set of data that gathered each time for presentation to go along with the case at hand. This section is meant to present areas of the OS X structure where you can find data for presentation in your cases that many times apply in all circumstances.

This page attempts to note areas that have changed thru OS X updates. With each Apple update come file name and/or location changes as well.

Operating System Installation Date
  • /private/var/log/OSInstall.custom (10.5)
  • /private/var/db/.AppleSetupDone (10.6 and later) a zero byte file, date stamped at the time the Setup Assistant last ran, which is likely the installation date
  • /private/var/log/install.log - contains install date of system (remember current version of system doesn’t always equal initial setup of Mac with an older system)
  • HFS+ Volume Header “dateCreated” - date the volume was created

Operating System Version
  • /System/Library/CoreServices/SystemVersion.plist (OS X Client)
  • /System/Library/CoreServices/ServerVersion.plist (OS X Server) - this is not used with 10.7 and later. The Server OS is a simple application now and not a separate OS.

Software Installation
  • /Library/Receipts/InstallHistory.plist - History of installed applications and updates
  • /Library/Preferences/ - Last Software Update
  • /Applications - system-wide installed applications
  • ~/Applications - applications installed and available to that user only, including VMWare linked apps to a Windows installation

Current Time Zone
  • /etc/localtime (link file pointing to current time zone) OR
  • /Library/Preferences/.GlobalPreferences.plist

Service Settings
  • /private/var/db/launchd.db/ - contains boolean values for system services such as Screen Sharing, File Sharing, etc.

Auto-Login and Last Login User Info
  • /Library/Preferences/
  • /private/etc/kcpassword - auto-login password

Printing System (CUPS)
  • /private/var/spool/cups - completed and and unfinished print jobs (print system uses PDF files so carve for them!)

Deleted Users
  • /Library/Preferences/

Deleted Files
  • /.Trashes - Trash at the root of any media connected to a Mac, used for files deleted from specific volume
  • /Users/username/.Trashes - user specific Trash for items deleted by user on local system

Home Folders
  • /Users/username
  • /private/var/root - Home folder for ‘root’ user

OS X 10.7 and later Sandboxing

  • /Users/username/Library/Containers (look for reverse URL named folders for each sandboxed app)

Attached Media

  • /Users/username/Library/Preferences/ - history of attached media, volumes devices, etc.
  • see our page on USB devices

iCloud Syncing
  • /Users/rkubasiak/Library/Preferences/MobileMeAccounts.plist

  • /Users/username/Library/Mail
  • /Users/username/Library/Mail Downloads

  • see our page on USB devices
  • /Users/username/Library/Application Support/MobileSync/Backup - folder where iPhone, iPod Touch and iPad sync their data to
  • /Users/username/Library/Application Support/MobileSync/Backup/UUID/Info.plist - contains info on the exact device synced (Backup), modified date of this file is the last time it was synced
  • /Users/username/Library/Preferences/ - all iOS and iPod devices connected for this account, includes iOS version , IMEI, etc.

iTunes and iPhoto Information
  • /Users/username/Music/iTunes/ - default location for iTunes Library
  • /Users/username/Pictures/iPhoto Library - default location for “iPhoto Library” bundle

User Auto-Launch Items
  • /Users/username/Library/Preferences/loginwindow.plist

Network Settings
  • /Library/Preferences/ - Firewall Settings
  • /Library/Preferences/SystemConfiguration/ - Airport (Wireless) Settings
  • /Library/Preferences/SystemConfiguration/ - Internet Sharing Settings
  • /Library/Preferences/SystemConfiguration/ - Historical Network TCP/IP Assignments with Timestamps
  • /Library/Preferences/SystemConfiguration/
  • /Library/Preferences/SystemConfiguration/NetworkInterfaces.plist - Available network interfaces including MAC address on 10.8
  • /Library/Preferences/SystemConfiguration/ - Available network interfaces including MAC address
  • /Library/Preferences/SystemConfiguration/ - Network Configuration for each interface (not on 10.8, see below)
  • /Library/Preferences/SystemConfiguration/preferences.plist - network interface configuration and Back To My Mac information

User Configuration
  • /Users/username/Library/Preferences/ - Recent searches, Trash setting, view settings, recent folders
  • /Users/username/Library/Preferences/ - Applications in the Dock
  • /Users/username/Library/Preferences/ - folders and network shares in the Dock
  • /Users/username/Library/Preferences/ - Desktop picture
  • /Users/username/Library/Preferences/ - recent documents, applications, and network connections

Screen Sharing
  • /Users/username/Library/Application Support/Screen Sharing
    • vncloc files for each Screen Sharing connection
    • Screen Sharing is an included application with OS X, and is different than other VNC apps
  • /Users/username/Library/Containers/
    • keys will show managed Macs, Bonjour discovered Macs, IP addresses, MAC addresses, date stamps

Bluetooth History
  • /Library/Preferences/

Instant Messaging
  • /Library/Preferences/
  • /Library/Preferences/
  • /Library/Preferences/
  • /Users/username/Library/Preferences/
  • /Users/username/Library/Preferences/com.adiumX.adiumX.plist
  • /Users/username/Library/Preferences/
  • /Users/username/Library/Preferences/
  • /Users/username/Library/Preferences/
  • /Users/username/Library/Preferences/
  • /Users/username/Library/Preferences/
  • /Users/username/Library/Preferences/
  • /Users/username/Documents/iChat - default save location for iChat and Messages application
  • /Users/username/Library/Messages - database for Messages app

Peer to Peer
  • /Users/username/Library/Preferences/Limewire/*
  • /Users/username/Frostwire
  • /Users/username/Dropbox
  • /Users/username/Google Drive

  • /Users/username/Library/Mobile Documents - sync of “Documents and Data” feature of iCloud
  • /Users/username/Library/SyncedPreferences - syncing of preferences across devices

  • /Users/username/Library/Safari/Bookmarks.plist - User's Bookmarks
  • /Users/username/Library/Safari/Downloads.plist - Contents of the user's Downloads window in Safari
  • /Users/username/Library/Safari/History.plist - Safari browser history
  • /Users/username/Library/Safari/LastSession.plist - defines the last browsing session (window and tabs that were open)

Log Files
  • /private/var/log/
    • system.log
    • kernel.log
    • secure.log
  • /Library/Logs
    • SystemMigration.log
  • /Users/username/Library/Logs/*

Sleep File and Virtual Memory
  • /private/var/vm/sleepimage
  • /private/var/vm/swapfile0

Virtual Machines
  • /Users/username/Documents/Virtual Machines
  • /Users/username/Library/Preferences/VMWare Fusion
  • /Users/username/Library/Preferences/Parallels
  • /Library/Preferences/VMWare Fusion
  • /Library/Preference/Parallels
  • /Library/Parallels