IT Forensics · macOS

Forensic analysis of LaunchAgents and LaunchDaemons – Investigating persistence on macOS

launchd is a central service for launching and managing background processes on macOS. Apple distinguishes, amongst other things, between LaunchAgents, which can be run within the context of a logged-in user, and LaunchDaemons, which are managed system-wide and can run even when no user is logged in. Depending on the mechanism and the version of macOS, configurations are provided via property list files or modern service management structures.

Enquire without obligation

These mechanisms are particularly relevant to forensic analysis because legitimate software, as well as unwanted or malicious programmes, can use them for automatic launch and persistence. However, the presence of a LaunchAgent or LaunchDaemon does not in itself constitute evidence of malware. The decisive factors are the origin, signature, programme path, configuration, time reference and correlation with other traces.

Why LanCologne?

Since its foundation, LanCologne has specialised in professional IT forensics. Our staff have decades of experience in the field of information technology and assist companies, solicitors, private individuals and, on a regular basis, the courts in the technical investigation of complex digital matters.

The examination is, as a matter of principle, carried out exclusively on a forensic copy, a forensic image or a data source captured in a technically equivalent manner that preserves the integrity of the evidence. The original evidence remains unchanged and is stored in a manner that preserves its integrity.

Our services

We identify existing LaunchAgent and LaunchDaemon configurations and examine, amongst other things, the label, programme or programme arguments, start conditions, referenced executable files and associated paths. User-specific and system-wide entries are considered separately.

Suspicious entries are correlated with code-signing information, file metadata, quarantine and Gatekeeper context, unified logs, and other persistence and malware artefacts. For macOS 13 and later, we also take into account the service management structures introduced by Apple for helpers, LaunchAgents and LaunchDaemons embedded in app bundles.

Typical areas of application

Investigation of suspected persistence mechanisms
Malware and incident response analyses
Checking automatically started background processes
Mapping helper components to applications
Analysis of manipulated or unknown property lists
Reconstruction of system-wide and user-specific autostarts
Judicial and non-judicial expert reports

This is how the forensic investigation is carried out

Once the data has been securely backed up, the relevant Launch Service structures are catalogued. Traditional paths such as user and local LaunchAgents, as well as local LaunchDaemons, are taken into account, as are newer service management components integrated into app bundles. Programmes referenced are then checked for existence, hash values, signatures, owners, permissions and other metadata.

A persistence assessment is never based solely on the file name or a single plist key. Only the combination of configuration, executable file, origin, runtime traces and other artefacts allows for a reliable classification.

Why is this area of investigation relevant to forensics?

LaunchAgents and LaunchDaemons are among the most important legitimate auto-start mechanisms in macOS and are therefore also a key area to investigate when persistence is suspected. Apple documents LaunchAgents as processes running in the user context and LaunchDaemons as system-wide background processes managed by launchd.

From a forensic perspective, a distinction must be made between normal software behaviour, a service intentionally set up by an administrator, and malicious persistence. An unusual entry is merely a starting point for an investigation; a robust assessment requires additional technical evidence.

Frequently Asked Questions

What is the difference between LaunchAgent and LaunchDaemon?+
LaunchAgents generally operate within the context of a user session. LaunchDaemons are system-wide background processes and can run independently of a user being logged in.
Where might standard LaunchAgent configurations be located?+
Among other things, Apple documents /Library/LaunchAgents and the LaunchAgents directory within the user library; Apple’s own components may also be located in the system directory.
Is every unknown LaunchDaemon suspicious?+
No. Many legitimate applications install background services. The source, digital signature, programme path and other indicators must be assessed collectively.
Has the mechanism changed in more recent versions of macOS?+
Yes. Since macOS 13, Apple has supported a modernised service management structure in which helpers, LaunchAgents and LaunchDaemons can be provided within an app bundle.

LanCologne – macOS Forensics in Cologne

Do you need a professional analysis of LaunchAgents, LaunchDaemons or other persistence mechanisms on a Mac? LanCologne can assist you with evidence-secure backups and a transparent technical assessment.

Get in touch now