Skip to content

Software Update Information

Evidence: Software Update Information
Description: Collects software update information
Category: System
Platform: macos
Short Name: swinfo
Is Parsed: Yes
Sent to Investigation Hub: Yes
Collect File(s): No

Software update preferences record last successful updates and recommended updates. This data is essential for verifying patch status and detecting outdated or vulnerable systems.

This collector gathers structured data about software update information.

This collector copies and parses /Library/Preferences/com.apple.SoftwareUpdate.plist and records fields into software_update_information.

This evidence is crucial for forensic investigations as it reveals update timelines and failures, helping assess exposure windows and compliance.