Skip to content

Re-Opened Apps

Evidence: Re-Opened Apps
Description: Collect Re-Opened Apps
Category: System
Platform: macos
Short Name: reapps
Is Parsed: Yes
Sent to Investigation Hub: Yes
Collect File(s): No

Re-opened apps preference tracks files and apps restored at login. This data is essential for understanding user session restoration and potential persistence via loginwindow.

This collector gathers structured data about re-opened apps.

FieldDescriptionExample
PlistPlistExample value
FilePathFile PathExample value
OriginalFilenameOriginal FilenameExample value
FileTypeFile TypeExample value
SHA1SHA1Example value
SizeInBytesSize In Bytes123
FileCreatedFile Created2023-10-15 14:30:25+03:00
FileLastAccessedFile Last Accessed2023-10-15 14:30:25+03:00
FileLastChangedFile Last Changed2023-10-15 14:30:25+03:00
FileLastModifiedFile Last Modified2023-10-15 14:30:25+03:00

This collector joins plist, hash, and file tables to enumerate ByHost loginwindow plists and referenced items, recording metadata into re_opened_apps.

This evidence is crucial for forensic investigations as it highlights recently accessed items and auto‑restored apps that may indicate user behavior or malicious persistence.