IT Forensics · macOS
Forensic analysis of macOS plist files – evaluating configurations and states
Property lists, or ‘plists’ for short, are a fundamental data format in macOS and Apple applications. They can contain settings, states and other structured information, and are available in both XML and binary property list formats.
In forensics, plists are often valuable sources of context. However, the meaning of individual keys depends on the specific application, macOS version and implementation. Unknown fields must not be interpreted solely on the basis of their names.
Why LanCologne?
Since its foundation, LanCologne has specialised in professional IT forensics. Our staff have decades of experience in the field of information technology and assist companies, solicitors, private individuals and, on a regular basis, the courts in the technical investigation of complex digital matters.
The examination is, as a matter of principle, carried out exclusively on a forensic copy, a forensic image or a data source captured in a technically equivalent manner that preserves the integrity of the evidence. The original evidence remains unchanged and is stored in a manner that preserves its integrity.
Our services
We identify case-relevant property list files and analyse their structure, keys and values within the relevant application or system context. Binary plists are decoded professionally without altering the original.
Time and status information is cross-referenced with file system metadata, unified logs and other artefacts.
Typical areas of application
This is how the forensic investigation is carried out
Once the data has been backed up, relevant plists are selected on the basis of the query and analysed structurally. Data types, keys and values are documented and – where necessary – compared with version information from the associated application.
Undocumented keys are only assessed in terms of their content if their significance is reliably supported by further technical evidence.
Why is this area of investigation relevant to forensics?
Plists are found in almost all areas of macOS forensics. They can document important configuration states and help to make sense of other artefacts.
At the same time, there is a high risk of misinterpretation if keys are interpreted without knowledge of the relevant software version or implementation.
Frequently Asked Questions
🔗 Related topics
LanCologne – macOS Forensics in Cologne
Do you need a professional analysis of macOS property list files? LanCologne can assist you with the collection of evidence that meets legal standards and a technically sound evaluation.