IT Forensics · macOS

Forensic analysis of gatekeepers and quarantine – assessing the origin and execution of software

Gatekeeper is a key security mechanism in macOS. For software downloaded from the internet, macOS checks, amongst other things, the Developer ID signature, notarisation and integrity, depending on the source and system configuration. Apple also explains that Gatekeeper requests user authorisation before downloaded software is opened for the first time and tracks the origin of files written by downloaded software.

Enquire without obligation

In the field of forensics, gatekeeper and quarantine information can provide important clues as to the origin and handling of downloaded programmes or files. However, they do not constitute a complete download or execution log. The absence of quarantine information does not prove that a file never originated from the internet or was never executed.

Why LanCologne?

Since its foundation, LanCologne has specialised in professional IT forensics. Our staff have decades of experience in the field of information technology and assist companies, solicitors, private individuals and, on a regular basis, the courts in the technical investigation of complex digital matters.

The examination is, as a matter of principle, carried out exclusively on a forensic copy, a forensic image or a data source captured in a technically equivalent manner that preserves the integrity of the evidence. The original evidence remains unchanged and is stored in a manner that preserves its integrity.

Our services

We examine existing quarantine and Gatekeeper-related information in the context of the affected files and applications. In doing so, we take into account, amongst other things, extended file attributes, code-signing and notarisation status, file metadata, application structure and other available system traces.

In the case of suspicious software, a correlation is carried out with Unified Logs, launch and persistence mechanisms, the XProtect context, and browser and download artefacts, where these are present in the specific case. The aim is to carry out a technically verifiable assessment of the software’s origin and execution without over-interpreting individual traces.

Typical areas of application

Scanning downloaded programmes and files
Malware and incident response analyses
Verification of origin and first flight context
Assessment of security warnings that have been disregarded
Analysis of code-signing and notarisation status
Correlation with browser and download history
Judicial and non-judicial expert reports

This is how the forensic investigation is carried out

Once the backup has been completed, relevant files and apps are identified and checked for existing quarantine and security metadata. Code signing, notarisation and integrity are assessed separately from the quarantine status itself. Potential download sources and temporal correlations are then cross-referenced with other artefacts.

Particular caution is required when it comes to negative findings: quarantine information may be missing or altered, and not every route of transmission leaves identical traces. For this reason, only what can actually be verified on the basis of the available data is documented.

Why is this area of investigation relevant to forensics?

Gatekeeper and File Quarantine form an important part of the macOS app security architecture. Apple states that Gatekeeper checks downloaded software and may require user authorisation before it is opened for the first time.

From a forensic perspective, this can help to determine where software came from and how macOS treated it in terms of security. However, the data must be correlated with download, file and runtime traces before any conclusions can be drawn about specific user actions.

Frequently Asked Questions

What does Gatekeeper check?+
When software is downloaded, macOS checks, amongst other things, the developer’s identity, notarisation and integrity, depending on the circumstances.
Does notarisation guarantee that there are no issues whatsoever?+
No. It is a security feature and part of Apple’s chain of evidence, but it does not replace case-specific forensic malware analysis.
Does a quarantine entry prove that a file was executed?+
No. It can verify a file’s origin and security context, but on its own it does not constitute proof of secure execution.
Does the absence of quarantine data prove that the file was created locally?+
No. The lack of information on quarantine does not allow for such a definitive conclusion to be drawn without further evidence.

LanCologne – macOS Forensics in Cologne

Do you require a professional gatekeeper, quarantine or origin analysis of a macOS file? LanCologne can assist you with ensuring your data is admissible in court and providing a technically sound classification.

Get in touch now