Glossary
.LastGKReject
A property list syspolicyd writes when Gatekeeper refuses an item. Only the last rejection is kept: time, bookmark and malware type.
.LastGKReject is a property list written by syspolicyd when Gatekeeper refuses an item (PolicyEngine::recordFailure in Apple's open-source Security code). Older Apple sources place it at /var/db/.LastGKReject; current sources use /var/db/SystemPolicyConfiguration/.LastGKReject. Only the last rejection is kept, and the file may not exist at all.
The keys read by mac_apt's QUARANTINE plugin are TimeStamp, BookmarkData (a bookmark to the rejected item, which yields its path and volume) and XProtectMalwareType. Reported values for the last key, credited by mac_apt to Patrick Wardle, are 2 unsigned app/program, 3 modified bundle, 5 signed app and 7 modified app; Apple does not document them. See .LastGKReject and Gatekeeper evidence.