IT Forensics · macOS
Forensic analysis of gatekeepers and quarantine – assessing the origin and execution of software
Gatekeeper is a key security mechanism in macOS. For software downloaded from the internet, macOS checks, amongst other things, the Developer ID signature, notarisation and integrity, depending on the source and system configuration. Apple also explains that Gatekeeper requests user authorisation before downloaded software is opened for the first time and tracks the origin of files written by downloaded software.
In the field of forensics, gatekeeper and quarantine information can provide important clues as to the origin and handling of downloaded programmes or files. However, they do not constitute a complete download or execution log. The absence of quarantine information does not prove that a file never originated from the internet or was never executed.
Why LanCologne?
Since its foundation, LanCologne has specialised in professional IT forensics. Our staff have decades of experience in the field of information technology and assist companies, solicitors, private individuals and, on a regular basis, the courts in the technical investigation of complex digital matters.
The examination is, as a matter of principle, carried out exclusively on a forensic copy, a forensic image or a data source captured in a technically equivalent manner that preserves the integrity of the evidence. The original evidence remains unchanged and is stored in a manner that preserves its integrity.
Our services
We examine existing quarantine and Gatekeeper-related information in the context of the affected files and applications. In doing so, we take into account, amongst other things, extended file attributes, code-signing and notarisation status, file metadata, application structure and other available system traces.
In the case of suspicious software, a correlation is carried out with Unified Logs, launch and persistence mechanisms, the XProtect context, and browser and download artefacts, where these are present in the specific case. The aim is to carry out a technically verifiable assessment of the software’s origin and execution without over-interpreting individual traces.
Typical areas of application
This is how the forensic investigation is carried out
Once the backup has been completed, relevant files and apps are identified and checked for existing quarantine and security metadata. Code signing, notarisation and integrity are assessed separately from the quarantine status itself. Potential download sources and temporal correlations are then cross-referenced with other artefacts.
Particular caution is required when it comes to negative findings: quarantine information may be missing or altered, and not every route of transmission leaves identical traces. For this reason, only what can actually be verified on the basis of the available data is documented.
Why is this area of investigation relevant to forensics?
Gatekeeper and File Quarantine form an important part of the macOS app security architecture. Apple states that Gatekeeper checks downloaded software and may require user authorisation before it is opened for the first time.
From a forensic perspective, this can help to determine where software came from and how macOS treated it in terms of security. However, the data must be correlated with download, file and runtime traces before any conclusions can be drawn about specific user actions.
Frequently Asked Questions
LanCologne – macOS Forensics in Cologne
Do you require a professional gatekeeper, quarantine or origin analysis of a macOS file? LanCologne can assist you with ensuring your data is admissible in court and providing a technically sound classification.
Related to this topic
- Forensic analysis of XProtect – A technical assessment of Apple’s built-in malware protection
- Forensic analysis of macOS privacy permissions – assessing app access to protected resources
- Forensic analysis of Launch Services – evaluating app and document mappings on macOS
- Forensic analysis of macOS crash reports – investigating process crashes and diagnostic information