Skip to content

macOS Collections

# Evidence
(click for details)
Category Parsed Sent to the
Investigation Hub
Raw Files
Collected
1 .DS_Store Files DiskFilesystem Yes Yes No
2 .Trash DiskFilesystem Yes Yes No
3 AnyDesk Logs Applications No No Yes
4 Apache Logs Applications No No Yes
5 Apple Audit Logs System Yes Yes No
6 Apple System Logs (ASL) System Yes Yes No
7 Application Usage System Yes Yes No
8 Arc Bookmarks Applications Yes Yes No
9 Arc Browsing History Applications Yes Yes No
10 Arc Cookies Applications Yes Yes No
11 Arc Downloads Applications Yes Yes No
12 Arc Favicons Applications Yes Yes No
13 Arc Form History Applications Yes Yes No
14 Arc Local Storage Applications Yes Yes No
15 Arc Login Data Applications Yes Yes No
16 Arc Sessions Applications Yes Yes No
17 Arc Thumbnails Applications Yes Yes No
18 Arc User Profiles Applications Yes Yes No
19 Arc Web Storage Applications Yes Yes No
20 Auto Loaded Processes System Yes Yes No
21 Block Devices DiskFilesystem Yes Yes No
22 Bluetooth Connections System Yes Yes No
23 Brave Bookmarks Applications Yes Yes No
24 Brave Browsing History Applications Yes Yes No
25 Brave Cookies Applications Yes Yes No
26 Brave Downloads Applications Yes Yes No
27 Brave Favicons Applications Yes Yes No
28 Brave Form History Applications Yes Yes No
29 Brave Local Storage Applications Yes Yes No
30 Brave Login Data Applications Yes Yes No
31 Brave Sessions Applications Yes Yes No
32 Brave Thumbnails Applications Yes Yes No
33 Brave User Profiles Applications Yes Yes No
34 Brave Web Storage Applications Yes Yes No
35 Chrome Bookmarks Applications Yes Yes No
36 Chrome Browsing History Applications Yes Yes No
37 Chrome Cookies Applications Yes Yes No
38 Chrome Downloads Applications Yes Yes No
39 Chrome Extensions Applications Yes Yes No
40 Chrome Favicons Applications Yes Yes No
41 Chrome Form History Applications Yes Yes No
42 Chrome Local Storage Applications Yes Yes No
43 Chrome Login Data Applications Yes Yes No
44 Chrome Sessions Applications Yes Yes No
45 Chrome Thumbnails Applications Yes Yes No
46 Chrome User Profiles Applications Yes Yes No
47 Chrome Web Storage Applications Yes Yes No
48 Collect File System (FS) Events DiskFilesystem Yes Yes No
49 Command Line Activity EventLogs Yes Yes No
50 Crashes System Yes Yes No
51 Cron Jobs System Yes Yes No
52 DHCP Settings Network Yes Yes No
53 DMG File Opened DiskFilesystem Yes Yes No
54 DNS Resolvers Network Yes Yes No
55 Default Browser Applications Yes Yes No
56 Discord Desktop Cache Applications No No Yes
57 Disk Encryption DiskFilesystem Yes Yes No
58 Dock Items System Yes Yes No
59 Docker Changes Applications Yes Yes No
60 Docker Container Logs Applications Yes Yes No
61 Docker Containers Applications Yes Yes No
62 Docker Image History Applications Yes Yes No
63 Docker Images Applications Yes Yes No
64 Docker Info Applications Yes Yes No
65 Docker Logs Applications No No Yes
66 Docker Networks Applications Yes Yes No
67 Docker Processes Applications Yes Yes No
68 Docker Volumes Applications Yes Yes No
69 Document Revisions System Yes Yes No
70 Downloaded Files Information System Yes Yes No
71 Dump Arc Indexed DB Applications Yes Yes No
72 Dump Brave Indexed DB Applications Yes Yes No
73 Dump Chrome Indexed DB Applications Yes Yes No
74 Dump Edge Indexed DB Applications Yes Yes No
75 Dump Opera Indexed DB Applications Yes Yes No
76 Dump QQ Indexed DB Applications Yes Yes No
77 Dump Vivaldi Indexed DB Applications Yes Yes No
78 ETC Files System No Yes Yes
79 ETC Hosts Network Yes Yes No
80 ETC Protocols Network Yes Yes No
81 ETC Services Network Yes Yes No
82 Edge Bookmarks Applications Yes Yes No
83 Edge Browsing History Applications Yes Yes No
84 Edge Cookies Applications Yes Yes No
85 Edge Downloads Applications Yes Yes No
86 Edge Extensions Applications Yes Yes No
87 Edge Favicons Applications Yes Yes No
88 Edge Form History Applications Yes Yes No
89 Edge Local Storage Applications Yes Yes No
90 Edge Login Data Applications Yes Yes No
91 Edge Sessions Applications Yes Yes No
92 Edge Thumbnails Applications Yes Yes No
93 Edge User Profiles Applications Yes Yes No
94 Edge Web Storage Applications Yes Yes No
95 Emond Clients System Yes Yes No
96 Event Taps System Yes Yes No
97 Extended Attributes System Yes Yes No
98 Failed Sudo EventLogs Yes Yes No
99 File Last Used DiskFilesystem Yes Yes No
100 File System Enumeration DiskFilesystem Yes No No
101 Finder Mounted Volume DiskFilesystem Yes Yes No
102 Firefox Browsing History Applications Yes Yes No
103 Firefox Cookies Applications Yes Yes No
104 Firefox Downloads Applications Yes Yes No
105 Firefox Extensions Applications Yes Yes No
106 Gatekeeper System Yes Yes No
107 Gatekeeper Approved Apps System Yes Yes No
108 Homebrew Logs Applications No No Yes
109 IP Routes Network Yes Yes No
110 Install Logs System No No Yes
111 Installed Applications System Yes Yes No
112 Kernel Extensions EventLogs Yes Yes No
113 Kernel Extensions Info System Yes Yes No
114 Keyboard Dictionary System Yes Yes No
115 Keychain EventLogs Yes Yes No
116 KnowledgeC System No No Yes
117 Launchd Files System No Yes Yes
118 Launchd Overrides System Yes Yes No
119 Listening Ports Network Yes Yes No
120 Logged Users System Yes Yes No
121 Login Hooks System Yes Yes No
122 Login Items System Yes Yes No
123 Logind EventLogs Yes Yes No
124 Logout Hooks System Yes Yes No
125 Mail Rules System Yes Yes No
126 Manuel Configuration Profile Install EventLogs Yes Yes No
127 MongoDB Logs Applications No No Yes
128 Most Recently Used (MRU) System Yes Yes No
129 Mount DiskFilesystem Yes Yes No
130 MySQL Logs Applications No No Yes
131 NGINX Logs Applications No No Yes
132 Network Interfaces Network Yes Yes No
133 Network Usage Network Yes Yes No
134 NetworkFlow System No Yes No
135 Notification Info System Yes Yes No
136 Opera Bookmarks Applications Yes Yes No
137 Opera Browsing History Applications Yes Yes No
138 Opera Cookies Applications Yes Yes No
139 Opera Downloads Applications Yes Yes No
140 Opera Extensions Applications Yes Yes No
141 Opera Favicons Applications Yes Yes No
142 Opera Form History Applications Yes Yes No
143 Opera Local Storage Applications Yes Yes No
144 Opera Login Data Applications Yes Yes No
145 Opera Sessions Applications Yes Yes No
146 Opera Thumbnails Applications Yes Yes No
147 Opera User Profiles Applications Yes Yes No
148 Opera Web Storage Applications Yes Yes No
149 PCAP System No Yes No
150 Package Install History System Yes Yes No
151 Parallels Logs Applications No No Yes
152 Parse File System (FS) Events DiskFilesystem Yes Yes No
153 PostgreSQL Logs Applications No No Yes
154 Print Jobs System Yes Yes No
155 Printer Info System Yes Yes No
156 Processes System Yes Yes No
157 QQ Bookmarks Applications Yes Yes No
158 QQ Browsing History Applications Yes Yes No
159 QQ Cookies Applications Yes Yes No
160 QQ Downloads Applications Yes Yes No
161 QQ Favicons Applications Yes Yes No
162 QQ Form History Applications Yes Yes No
163 QQ Local Storage Applications Yes Yes No
164 QQ Login Data Applications Yes Yes No
165 QQ Sessions Applications Yes Yes No
166 QQ Thumbnails Applications Yes Yes No
167 QQ User Profiles Applications Yes Yes No
168 QQ Web Storage Applications Yes Yes No
169 Quarantine Events System Yes Yes No
170 Quick Look Cache System Yes Yes No
171 Re-Opened Apps System Yes Yes No
172 SSH Authorized Keys Network Yes Yes No
173 SSH Configs Network Yes Yes No
174 SSH Files System No Yes Yes
175 SSH Known Hosts Network Yes Yes No
176 SSHD Configs Network Yes Yes No
177 Safari Browsing History Applications Yes Yes No
178 Safari Downloads Applications Yes Yes No
179 Screensharing EventLogs Yes Yes No
180 Session Creation and Destruction EventLogs Yes Yes No
181 Shared File List System Yes Yes No
182 Shell History System Yes Yes No
183 Software Update Information System Yes Yes No
184 Sophos Events Database Applications No No Yes
185 Sophos Logs Applications No No Yes
186 Splashtop Mac Logs Applications No No Yes
187 Spotlight System Yes Yes Yes
188 Sshd EventLogs Yes Yes No
189 Sudo Last Run System Yes Yes No
190 System Extension Info System Yes Yes No
191 System Integrity Protection Status System Yes Yes No
192 System Logs System No No Yes
193 Tccd EventLogs Yes Yes No
194 Teamviewer Logs Applications No No Yes
195 Transparency, Consent, and Control (TCC) System Yes Yes No
196 USB Info System Yes Yes No
197 User Groups System Yes Yes No
198 Users System Yes Yes No
199 Vivaldi Bookmarks Applications Yes Yes No
200 Vivaldi Browsing History Applications Yes Yes No
201 Vivaldi Cookies Applications Yes Yes No
202 Vivaldi Downloads Applications Yes Yes No
203 Vivaldi Favicons Applications Yes Yes No
204 Vivaldi Form History Applications Yes Yes No
205 Vivaldi Local Storage Applications Yes Yes No
206 Vivaldi Login Data Applications Yes Yes No
207 Vivaldi Sessions Applications Yes Yes No
208 Vivaldi Thumbnails Applications Yes Yes No
209 Vivaldi User Profiles Applications Yes Yes No
210 Vivaldi Web Storage Applications Yes Yes No
211 Waterfox Browsing History Applications Yes Yes No
212 Waterfox Downloads Applications Yes Yes No
213 Wifi Logs Network No No Yes
214 Wireless Network Connections Network Yes Yes No
215 XProtect Remediation EventLogs Yes Yes No
216 iMessage System Yes Yes Yes