IT Forensics · macOS

Forensic analysis of FSEvents – reconstructing file system changes on macOS

FSEvents is a macOS mechanism for detecting changes within monitored directory hierarchies. Apple has provided this interface since Mac OS X 10.5. The FSEvents service processes file system events and can maintain persistent event data, which applications can use to determine whether content has changed since a previous event state.

Enquire without obligation

In the context of forensic analysis, FSEvents can provide valuable insights into file and directory activity. However, the data must not be interpreted as a complete log of every single user action. In particular, the granularity of the events, any gaps in the data, rotation and the specific state of macOS must be taken into account in every assessment.

Why LanCologne?

Since its foundation, LanCologne has specialised in professional IT forensics. Our staff have decades of experience in the field of information technology and assist companies, solicitors, private individuals and, on a regular basis, the courts in the technical investigation of complex digital matters.

The examination is, as a matter of principle, carried out exclusively on a forensic copy, a forensic image or a data source captured in a technically equivalent manner that preserves the integrity of the evidence. The original evidence remains unchanged and is stored in a manner that preserves its integrity.

Our services

We back up and analyse existing FSEvents data within the forensic working copy and technically categorise event identifiers, time references, paths and event flags. The results are cross-referenced with APFS structures, file metadata, Unified Logs, Spotlight metadata and other case-specific artefacts.

An FSEvents entry is not automatically attributed to a specific person or application. Statements regarding the cause are only made if additional evidence supports such an attribution.

Typical areas of application

Reconstruction of file and directory changes
Investigation of deleted or moved data
Time-based restriction of file system activities
Incident Response and Malware Investigations
Investigation into allegations of manipulation
Correlation with APFS and system artefacts
Judicial and non-judicial expert reports

This is how the forensic investigation is carried out

Once the data has been securely backed up, existing FSEvents structures are identified and checked for technical usability. Event data is decoded, relevant paths and flags are recorded, and the data is organised into a clear chronological or event-based sequence.

This is followed by correlation with other data sources. In doing so, a specific check is carried out to determine whether sequences of events appear to be complete or whether there are indications of gaps or event data that no longer exists. Only technically sound correlations are included in the assessment.

Why is this artefact relevant from a forensic point of view?

FSEvents can efficiently document changes to large directory hierarchies, thereby providing traces that are no longer immediately visible in the current file system alone. This makes the mechanism particularly useful for reconstructing changes.

At the same time, FSEvents is not a complete substitute for a file system timeline. Apple describes the technology as a notification and change-tracking mechanism; the level of detail can be at directory level. Forensic conclusions must therefore always be corroborated by other artefacts.

Frequently Asked Questions

What makes FSEvents stand out?+
FSEvents is used to provide notifications of changes to directory hierarchies and can provide persistent change events.
Can FSEvents provide evidence of every single file operation?+
No. The event data should not be regarded as a complete log of user actions and must be assessed in the context of other artefacts.
Can FSEvents help with deleted files?+
Yes, existing events can provide clues about previous paths or changes, even if the file in question no longer exists.
Can the user be identified from an FSEvents entry?+
Not based on the event alone. User attribution requires additional reliable evidence.

LanCologne – macOS Forensics in Cologne

Do you need a professional FSEvents analysis of a macOS system? LanCologne can assist you with the forensically sound preservation and traceable reconstruction of file system changes.

Get in touch now