Skip to content

Series

Quarantine fundamentals

6 posts in this series. Read them in order or jump to any one.

  1. QuarantineEventsV2: macOS Download History Forensics

    What the macOS QuarantineEventsV2 database records: LSQuarantineEvent schema, Mac absolute time, type numbers, the xattr UUID join and its limits.

  2. com.apple.quarantine Flags: Reading the Quarantine xattr

    How to decode a com.apple.quarantine value: flag bits such as 0083 and 00c3, the hex timestamp, agent and UUID, with a source and confidence for each flag.

  3. Collect QuarantineEventsV2: UAC, Aftermath, Velociraptor

    How to collect macOS QuarantineEventsV2, its -wal and -journal files, quarantine xattrs and .LastGKReject by hand or with UAC, Aftermath and Velociraptor.

  4. Recover Deleted QuarantineEventsV2 Records

    How deleted QuarantineEventsV2 rows survive in SQLite freeblocks, freelist pages, WAL frames and journals, how to preserve them and what recovery proves.

  5. .LastGKReject: Gatekeeper Rejection Evidence on macOS

    What .LastGKReject records when Gatekeeper blocks an item, where it lives, how to collect it and how to tie the rejection back to a download.

  6. kMDItemWhereFroms vs the macOS Quarantine Attribute

    Where did this file come from on a Mac? Read kMDItemWhereFroms, compare it with quarantine data, and interpret a missing quarantine attribute.

All posts in this series