IT Forensics · macOS
Forensic analysis of FSEvents – reconstructing file system changes on macOS
FSEvents is a macOS mechanism for detecting changes within monitored directory hierarchies. Apple has provided this interface since Mac OS X 10.5. The FSEvents service processes file system events and can maintain persistent event data, which applications can use to determine whether content has changed since a previous event state.
In the context of forensic analysis, FSEvents can provide valuable insights into file and directory activity. However, the data must not be interpreted as a complete log of every single user action. In particular, the granularity of the events, any gaps in the data, rotation and the specific state of macOS must be taken into account in every assessment.
Why LanCologne?
Since its foundation, LanCologne has specialised in professional IT forensics. Our staff have decades of experience in the field of information technology and assist companies, solicitors, private individuals and, on a regular basis, the courts in the technical investigation of complex digital matters.
The examination is, as a matter of principle, carried out exclusively on a forensic copy, a forensic image or a data source captured in a technically equivalent manner that preserves the integrity of the evidence. The original evidence remains unchanged and is stored in a manner that preserves its integrity.
Our services
We back up and analyse existing FSEvents data within the forensic working copy and technically categorise event identifiers, time references, paths and event flags. The results are cross-referenced with APFS structures, file metadata, Unified Logs, Spotlight metadata and other case-specific artefacts.
An FSEvents entry is not automatically attributed to a specific person or application. Statements regarding the cause are only made if additional evidence supports such an attribution.
Typical areas of application
This is how the forensic investigation is carried out
Once the data has been securely backed up, existing FSEvents structures are identified and checked for technical usability. Event data is decoded, relevant paths and flags are recorded, and the data is organised into a clear chronological or event-based sequence.
This is followed by correlation with other data sources. In doing so, a specific check is carried out to determine whether sequences of events appear to be complete or whether there are indications of gaps or event data that no longer exists. Only technically sound correlations are included in the assessment.
Why is this artefact relevant from a forensic point of view?
FSEvents can efficiently document changes to large directory hierarchies, thereby providing traces that are no longer immediately visible in the current file system alone. This makes the mechanism particularly useful for reconstructing changes.
At the same time, FSEvents is not a complete substitute for a file system timeline. Apple describes the technology as a notification and change-tracking mechanism; the level of detail can be at directory level. Forensic conclusions must therefore always be corroborated by other artefacts.
Frequently Asked Questions
🔗 Related topics
LanCologne – macOS Forensics in Cologne
Do you need a professional FSEvents analysis of a macOS system? LanCologne can assist you with the forensically sound preservation and traceable reconstruction of file system changes.