Skip to content

Quick Look Cache

Evidence: Quick Look Cache
Description: Collect Quick Look Cache
Category: System
Platform: macos
Short Name: qklc
Is Parsed: Yes
Sent to Investigation Hub: Yes
Collect File(s): No

Quick Look cache stores thumbnails and metadata for recently viewed files. This data is essential for confirming file access and reconstructing user interactions with files.

This collector gathers structured data about quick look cache.

FieldDescriptionExample
PathPathExample value
RowIDRow ID123
FSIDFSIDExample value
VolumeIDVolume ID123
INodeI Node123
ModTimeMod Time123
SizeSize123
LabelLabelExample value
LastHitDateLast Hit Date123
HitCountHit CountExample value
IconModeIcon Mode123
CachePathCache PathExample value

This collector queries the quicklook_cache table via osquery and records cache metadata into quicklook_cache.

This evidence is crucial for forensic investigations as it indicates files previewed or viewed by a user, even if moved or deleted.