<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Quarantine Parser — Blog</title>
    <link>https://www.quarantineparser.com/en/blog</link>
    <description>Latest from Blog</description>
    <language>en</language>
    <lastBuildDate>Wed, 30 Sep 2026 00:50:48 GMT</lastBuildDate>
    <atom:link href="https://www.quarantineparser.com/en/blog/feed.xml" rel="self" type="application/rss+xml"/>
    <item>
      <title>Collect QuarantineEventsV2: UAC, Aftermath, Velociraptor</title>
      <link>https://www.quarantineparser.com/en/blog/collect-quarantine-events-uac-aftermath-velociraptor</link>
      <guid isPermaLink="true">https://www.quarantineparser.com/en/blog/collect-quarantine-events-uac-aftermath-velociraptor</guid>
      <description>How to collect macOS QuarantineEventsV2, its -wal and -journal files, quarantine xattrs and .LastGKReject by hand or with UAC, Aftermath and Velociraptor.</description>
      <author>Florian Amette</author>
      <pubDate>Wed, 30 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>com.apple.quarantine Flags: Reading the Quarantine xattr</title>
      <link>https://www.quarantineparser.com/en/blog/com-apple-quarantine-xattr-flags</link>
      <guid isPermaLink="true">https://www.quarantineparser.com/en/blog/com-apple-quarantine-xattr-flags</guid>
      <description>How to decode a com.apple.quarantine value: flag bits such as 0083 and 00c3, the hex timestamp, agent and UUID, with a source and confidence for each flag.</description>
      <author>Florian Amette</author>
      <pubDate>Wed, 30 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>kMDItemWhereFroms vs the macOS Quarantine Attribute</title>
      <link>https://www.quarantineparser.com/en/blog/kmditemwherefroms-vs-quarantine</link>
      <guid isPermaLink="true">https://www.quarantineparser.com/en/blog/kmditemwherefroms-vs-quarantine</guid>
      <description>Where did this file come from on a Mac? Read kMDItemWhereFroms, compare it with quarantine data, and interpret a missing quarantine attribute.</description>
      <author>Florian Amette</author>
      <pubDate>Wed, 30 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>.LastGKReject: Gatekeeper Rejection Evidence on macOS</title>
      <link>https://www.quarantineparser.com/en/blog/lastgkreject-gatekeeper-evidence</link>
      <guid isPermaLink="true">https://www.quarantineparser.com/en/blog/lastgkreject-gatekeeper-evidence</guid>
      <description>What .LastGKReject records when Gatekeeper blocks an item, where it lives, how to collect it and how to tie the rejection back to a download.</description>
      <author>Florian Amette</author>
      <pubDate>Wed, 30 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>macOS Download Forensics: An Investigation Walkthrough</title>
      <link>https://www.quarantineparser.com/en/blog/macos-download-investigation-walkthrough</link>
      <guid isPermaLink="true">https://www.quarantineparser.com/en/blog/macos-download-investigation-walkthrough</guid>
      <description>A synthetic macOS intrusion worked through with Quarantine Parser: timeline, a recovered deleted row, a Gatekeeper rejection and an AppleDouble on USB.</description>
      <author>Florian Amette</author>
      <pubDate>Wed, 30 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>QuarantineEventsV2: macOS Download History Forensics</title>
      <link>https://www.quarantineparser.com/en/blog/quarantineeventsv2-forensics</link>
      <guid isPermaLink="true">https://www.quarantineparser.com/en/blog/quarantineeventsv2-forensics</guid>
      <description>What the macOS QuarantineEventsV2 database records: LSQuarantineEvent schema, Mac absolute time, type numbers, the xattr UUID join and its limits.</description>
      <author>Florian Amette</author>
      <pubDate>Wed, 30 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Recover Deleted QuarantineEventsV2 Records</title>
      <link>https://www.quarantineparser.com/en/blog/recover-deleted-quarantine-events</link>
      <guid isPermaLink="true">https://www.quarantineparser.com/en/blog/recover-deleted-quarantine-events</guid>
      <description>How deleted QuarantineEventsV2 rows survive in SQLite freeblocks, freelist pages, WAL frames and journals, how to preserve them and what recovery proves.</description>
      <author>Florian Amette</author>
      <pubDate>Wed, 30 Sep 2026 00:00:00 GMT</pubDate>
    </item>
  </channel>
</rss>