<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Quarantine Parser — Blog</title>
    <link>https://www.quarantineparser.com/de/blog</link>
    <description>Latest from Blog</description>
    <language>de</language>
    <lastBuildDate>Wed, 30 Sep 2026 00:50:49 GMT</lastBuildDate>
    <atom:link href="https://www.quarantineparser.com/de/blog/feed.xml" rel="self" type="application/rss+xml"/>
    <item>
      <title>QuarantineEventsV2 sichern: UAC, Aftermath, Velociraptor</title>
      <link>https://www.quarantineparser.com/de/blog/collect-quarantine-events-uac-aftermath-velociraptor</link>
      <guid isPermaLink="true">https://www.quarantineparser.com/de/blog/collect-quarantine-events-uac-aftermath-velociraptor</guid>
      <description>So sichern Sie macOS QuarantineEventsV2 mit -wal und -journal, Quarantäne-xattrs und .LastGKReject – von Hand oder mit UAC, Aftermath und Velociraptor.</description>
      <author>Florian Amette</author>
      <pubDate>Wed, 30 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>com.apple.quarantine-Flags: das Quarantäne-xattr lesen</title>
      <link>https://www.quarantineparser.com/de/blog/com-apple-quarantine-xattr-flags</link>
      <guid isPermaLink="true">https://www.quarantineparser.com/de/blog/com-apple-quarantine-xattr-flags</guid>
      <description>So dekodieren Sie einen com.apple.quarantine-Wert: Flag-Bits wie 0083 und 00c3, Hex-Zeitstempel, Agent und UUID, mit Quelle und Konfidenz je Flag.</description>
      <author>Florian Amette</author>
      <pubDate>Wed, 30 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>kMDItemWhereFroms vs. Quarantäne-Attribut unter macOS</title>
      <link>https://www.quarantineparser.com/de/blog/kmditemwherefroms-vs-quarantine</link>
      <guid isPermaLink="true">https://www.quarantineparser.com/de/blog/kmditemwherefroms-vs-quarantine</guid>
      <description>Woher stammt diese Datei auf dem Mac? kMDItemWhereFroms lesen, mit Quarantäne-Daten vergleichen und ein fehlendes Quarantäne-Attribut einordnen.</description>
      <author>Florian Amette</author>
      <pubDate>Wed, 30 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>.LastGKReject: Gatekeeper-Ablehnungen als Beweismittel</title>
      <link>https://www.quarantineparser.com/de/blog/lastgkreject-gatekeeper-evidence</link>
      <guid isPermaLink="true">https://www.quarantineparser.com/de/blog/lastgkreject-gatekeeper-evidence</guid>
      <description>Was .LastGKReject festhält, wenn Gatekeeper ein Objekt blockiert, wo die Datei liegt, wie man sie sichert und mit dem Download verknüpft.</description>
      <author>Florian Amette</author>
      <pubDate>Wed, 30 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Download-Forensik unter macOS: ein Fall Schritt für Schritt</title>
      <link>https://www.quarantineparser.com/de/blog/macos-download-investigation-walkthrough</link>
      <guid isPermaLink="true">https://www.quarantineparser.com/de/blog/macos-download-investigation-walkthrough</guid>
      <description>Ein synthetischer macOS-Vorfall mit Quarantine Parser: Zeitleiste, eine gelöschte und wiederhergestellte Zeile, Gatekeeper-Ablehnung und AppleDouble auf USB.</description>
      <author>Florian Amette</author>
      <pubDate>Wed, 30 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>QuarantineEventsV2: den macOS-Downloadverlauf auswerten</title>
      <link>https://www.quarantineparser.com/de/blog/quarantineeventsv2-forensics</link>
      <guid isPermaLink="true">https://www.quarantineparser.com/de/blog/quarantineeventsv2-forensics</guid>
      <description>Was die macOS-Datenbank QuarantineEventsV2 speichert: LSQuarantineEvent-Schema, Mac Absolute Time, Typnummern, Verknüpfung per xattr-UUID und Grenzen.</description>
      <author>Florian Amette</author>
      <pubDate>Wed, 30 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Gelöschte QuarantineEventsV2-Einträge wiederherstellen</title>
      <link>https://www.quarantineparser.com/de/blog/recover-deleted-quarantine-events</link>
      <guid isPermaLink="true">https://www.quarantineparser.com/de/blog/recover-deleted-quarantine-events</guid>
      <description>Wie gelöschte QuarantineEventsV2-Zeilen in SQLite-Freeblocks, Freelist, WAL-Frames und Journalen überleben, wie man sie sichert und was ihr Fund beweist.</description>
      <author>Florian Amette</author>
      <pubDate>Wed, 30 Sep 2026 00:00:00 GMT</pubDate>
    </item>
  </channel>
</rss>