IT Forensics · macOS
Forensic analysis of screen time – analysing app and website usage on macOS
Screen Time has been a feature of macOS since macOS 10.15 and can provide usage information on apps, websites and other device activities. Apple describes, amongst other things, reports on app and website usage, notifications and device activity. Depending on the configuration, Screen Time data can also be synchronised across devices linked to the same Apple ID.
For forensic analysis, existing Screen Time data can provide clues as to the use of specific apps or websites over a given period. However, it should not be regarded as a complete activity log. Screen Time must be enabled or configured accordingly; data can be consolidated across devices, and Apple points out that deleting your Safari history or an app may result in the removal of associated usage data.
Why LanCologne?
Since its foundation, LanCologne has specialised in professional IT forensics. Our staff have decades of experience in the field of information technology and assist companies, solicitors, private individuals and, on a regular basis, the courts in the technical investigation of complex digital matters.
The examination is, as a matter of principle, carried out exclusively on a forensic copy, a forensic image or a data source captured in a technically equivalent manner that preserves the integrity of the evidence. The original evidence remains unchanged and is stored in a manner that preserves its integrity.
Our services
We check whether screen time data is available in the forensic data source and can be analysed for the relevant user or time period. Available usage information is categorised by application, website, time period and device.
The results are cross-referenced with browser artefacts, unified logs, application data and other time-stamped traces. A displayed usage duration is not attributed to a specific user behaviour without verification, particularly if Screen Time has been synchronised across devices.
Typical areas of application
This is how the forensic investigation is carried out
Once the data has been securely backed up, the first step is to check whether Screen Time was enabled and what data is available. Relevant usage information is then extracted and assigned to the relevant app, website, time period and – where technically possible – the device.
Particular attention is paid to the possibility of synchronisation across multiple Apple devices. Apple allows both individual device data and combined usage statistics to be displayed. Therefore, before drawing any conclusions relating to time or specific individuals, a check is carried out to ensure that the findings can indeed be attributed to the Mac under investigation.
Why is this area of investigation relevant to forensics?
Screen Time can supplement a standard macOS artefact analysis with usage information. Existing data can provide additional insight, particularly when determining whether an application or website was used within a specific time frame.
Its reliability has clear limitations: Screen Time is not a forensic audit log; it may be disabled, and data may be synchronised or deleted. Reliable conclusions can therefore only be drawn by correlating the data with independent evidence.
Frequently Asked Questions
🔗 Related topics
LanCologne – macOS Forensics in Cologne
Do you need a professional analysis of screen time or usage data on a Mac? LanCologne can assist you with the collection of evidence that will stand up in court and a transparent technical analysis.
Related to this topic
- Forensic analysis of recent items – reconstructing evidence of recently used objects
- Forensic analysis of macOS user accounts – understanding user and account structures
- Forensic analysis of macOS login artefacts – reconstructing login and session processes
- Forensic analysis of Safari history – reconstructing web activity on macOS