Skip to content

Logged Users

Evidence: Logged Users
Description: Collect Logged Users
Category: System
Platform: macos
Short Name: lusrs
Is Parsed: Yes
Sent to Investigation Hub: Yes
Collect File(s): No

This collector gathers logged users information from the macOS system. This data is essential for understanding system activity, detecting security incidents, and investigating system-related events.

This collector gathers structured data about logged users.

FieldDescriptionExample
TypeTypeExample value
UsernameUsernameExample value
TtyTtyExample value
HostHostExample value
TimeTime2023-10-15 14:30:25+03:00
ProcessIdProcess Id123

This collector queries the logged_in_users table via osquery and records results into the logged_users table.

This evidence is crucial for forensic investigations as it reveals active and recent user sessions, helping identify unauthorized access, lateral movement, and account misuse.