Skip to content

Document Revisions

Evidence: Document Revisions
Description: Collect Document Revisions
Category: System
Platform: macos
Short Name: drvs
Is Parsed: Yes
Sent to Investigation Hub: Yes
Collect File(s): No

macOS DocumentRevisions-V100 stores prior versions of documents for autosave. This data is essential for recovering prior content and tracking edits over time.

This collector gathers structured data about document revisions.

FieldDescriptionExample
FileINodeFile I Node123
StorageIDStorage ID123
FilePathFile PathExample value
ExistsOnDiskExists On Disktrue
FileLastSeenFile Last Seen2023-10-15 14:30:25+03:00
GenerationAddedGeneration Added2023-10-15 14:30:25+03:00
GenerationPathGeneration PathExample value
SourceSourceExample value

This collector copies the DocumentRevisions database and queries for files and generations, recording into document_revisions.

This evidence is crucial for forensic investigations as it can reveal previous versions of altered or deleted documents.