IT Forensics · macOS

Forensic analysis of macOS plist files – evaluating configurations and states

Property lists, or ‘plists’ for short, are a fundamental data format in macOS and Apple applications. They can contain settings, states and other structured information, and are available in both XML and binary property list formats.

Enquire without obligation

In forensics, plists are often valuable sources of context. However, the meaning of individual keys depends on the specific application, macOS version and implementation. Unknown fields must not be interpreted solely on the basis of their names.

Why LanCologne?

Since its foundation, LanCologne has specialised in professional IT forensics. Our staff have decades of experience in the field of information technology and assist companies, solicitors, private individuals and, on a regular basis, the courts in the technical investigation of complex digital matters.

The examination is, as a matter of principle, carried out exclusively on a forensic copy, a forensic image or a data source captured in a technically equivalent manner that preserves the integrity of the evidence. The original evidence remains unchanged and is stored in a manner that preserves its integrity.

Our services

We identify case-relevant property list files and analyse their structure, keys and values within the relevant application or system context. Binary plists are decoded professionally without altering the original.

Time and status information is cross-referenced with file system metadata, unified logs and other artefacts.

Typical areas of application

Analysis of user and system settings
Survey of application preferences
Malware and persistence investigations
Reconstruction of configuration changes
Validation of binary and XML-based plists
Correlation with file system and log data
Judicial and non-judicial expert reports

This is how the forensic investigation is carried out

Once the data has been backed up, relevant plists are selected on the basis of the query and analysed structurally. Data types, keys and values are documented and – where necessary – compared with version information from the associated application.

Undocumented keys are only assessed in terms of their content if their significance is reliably supported by further technical evidence.

Why is this area of investigation relevant to forensics?

Plists are found in almost all areas of macOS forensics. They can document important configuration states and help to make sense of other artefacts.

At the same time, there is a high risk of misinterpretation if keys are interpreted without knowledge of the relevant software version or implementation.

Frequently Asked Questions

What is a plist file?+
A property list is a structured data format used by macOS and many applications for settings and other data.
Are there binary plists?+
Yes. Property lists can be in XML and binary formats, amongst others.
Can every plist key be interpreted unambiguously?+
No. The meaning and usage depend on the application and version.
Are plists in themselves evidence of user actions?+
Not necessarily. Many metrics describe configuration or state and need to be correlated with activity artefacts.

LanCologne – macOS Forensics in Cologne

Do you need a professional analysis of macOS property list files? LanCologne can assist you with the collection of evidence that meets legal standards and a technically sound evaluation.

Get in touch now