cpus.me

macOS Forensic Artifact Browser

A searchable index of 313 macOS forensic artifacts collectable from a live system, covering macOS 13 Ventura through macOS 26. Each entry records where the artifact lives, how to collect it, what privilege the collection requires, and what investigative question it answers.

Root alone is not sufficient on macOS 13 and later. TCC applies regardless of uid, so a root process without Full Disk Access gets EPERM on Mail, Messages, Safari data, the user’s Desktop, Documents and Downloads, and on TCC.db itself. Every entry declares its access tier, so you can filter for exactly what a given privilege level can reach.

Read this before relying on it.

An independent audit pass completed for only one of the ten research domains. The remaining entries are schema-valid and path-checked but were not reviewed for access-tier or timestamp-epoch correctness. Treat a high confidence rating on those as an assessment, not a verified fact.

Live verification ran on a single machine: macOS 26.5.2 on Apple Silicon. Availability on macOS 13 through 25 comes from documentation, not observation. Thirty paths are marked absent simply because the relevant software was not installed on that host.

Full RAM acquisition is out of scope — there is no supported path with SIP enabled on Apple Silicon — so memory entries are live-state snapshots, not memory dumps.

Loading artifacts…