Skip to content

Users

Evidence: Users
Description: Collect Users
Category: System
Platform: macos
Short Name: users
Is Parsed: Yes
Sent to Investigation Hub: Yes
Collect File(s): No

User account information provides details about local accounts on macOS, including group memberships and account properties. This data is essential for understanding system access and detecting unauthorized accounts.

This collector gathers structured data about users.

FieldDescriptionExample
UserIdUser Id123
NameNameExample value
GroupIdGroup Id123
GroupNameGroup NameExample value
DescriptionDescriptionExample value
DirectoryDirectoryExample value
ShellShellExample value

This collector queries osquery’s users joined with groups and records results into the users table.

This evidence is crucial for forensic investigations as it helps identify suspicious or unauthorized accounts, detect privilege escalation, and audit user management for policy compliance.