Skip to content

Dock Items

Evidence: Dock Items
Description: Collect Dock Items
Category: System
Platform: macos
Short Name: dckitms
Is Parsed: Yes
Sent to Investigation Hub: Yes
Collect File(s): No

Dock preferences record persistent apps, folders, and recent items displayed in the macOS Dock. This data is essential for understanding user activity and potential persistence via Dock items.

This collector gathers structured data about dock items.

FieldDescriptionExample
GUIDGUID123
UserUserExample value
FileLabelFile LabelExample value
ParentModifiedParent Modified2023-10-15 14:30:25+03:00
FileModifiedFile Modified2023-10-15 14:30:25+03:00
RecentlyUsedRecently Usedtrue
FileTypeFile Type123
FileTypeNameFile Type NameExample value
FilePathFile PathExample value
SourceSourceExample value

This collector reads users’ com.apple.dock.plist files, decodes entries, and records items into the dock_items table.

This evidence is crucial for forensic investigations as it reveals recently used and pinned applications, supporting timeline and behavior analysis.