Device Plugged In State
Overview
Section titled “Overview”Evidence: Device Plugged In State
Description: Collect Device Plugged In State
Category: System
Platform: macos
Short Name: devplug
Is Parsed: Yes
Sent to Investigation Hub: Yes
Collect File(s): No
Background
Section titled “Background”The KnowledgeC plugged-in stream records when the device was connected to or disconnected from power, building a charging timeline that reflects physical location and usage habits.
Data Collected
Section titled “Data Collected”This collector gathers structured data about whether the device was plugged into power and the associated timing. Results are recorded in device_plugged_in.
Collection Method
Section titled “Collection Method”This collector reads KnowledgeC databases under user profiles and records device power-state events into device_plugged_in.
Forensic Value
Section titled “Forensic Value”Power state transitions correlate with the user being at a desk or travelling, helping place the device and user on a timeline.