Glossary
QuarantineEventsV2
The per-user LaunchServices SQLite database that logs downloads made by quarantine-aware apps: time, agent, URLs and an event UUID.
~/Library/Preferences/com.apple.LaunchServices.QuarantineEventsV2 is a per-user SQLite database with a single table, LSQuarantineEvent. Each row describes one download event: LSQuarantineEventIdentifier (a UUID), LSQuarantineTimeStamp in Mac absolute time, the downloading agent's name and bundle identifier, the data and origin URLs, sender name and address for attachments, and a type number.
The database does not store the local file name or path. The link to a file on disk is the UUID at the end of its quarantine attribute. Rows typically persist after the file is deleted, and no automatic purge is documented. Downloads by tools that do not opt in to quarantine, such as curl, wget, scp, rsync or git, never appear, so absence is weak evidence. See QuarantineEventsV2 forensics.