<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Quarantine Parser — Blog</title>
    <link>https://www.quarantineparser.com/es/blog</link>
    <description>Latest from Blog</description>
    <language>es</language>
    <lastBuildDate>Wed, 30 Sep 2026 00:50:49 GMT</lastBuildDate>
    <atom:link href="https://www.quarantineparser.com/es/blog/feed.xml" rel="self" type="application/rss+xml"/>
    <item>
      <title>Recopilar QuarantineEventsV2: UAC, Aftermath, Velociraptor</title>
      <link>https://www.quarantineparser.com/es/blog/collect-quarantine-events-uac-aftermath-velociraptor</link>
      <guid isPermaLink="true">https://www.quarantineparser.com/es/blog/collect-quarantine-events-uac-aftermath-velociraptor</guid>
      <description>Cómo recopilar QuarantineEventsV2 de macOS, sus archivos -wal y -journal, los xattr de cuarentena y .LastGKReject a mano o con UAC, Aftermath y Velociraptor.</description>
      <author>Florian Amette</author>
      <pubDate>Wed, 30 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Flags de com.apple.quarantine: leer el xattr de cuarentena</title>
      <link>https://www.quarantineparser.com/es/blog/com-apple-quarantine-xattr-flags</link>
      <guid isPermaLink="true">https://www.quarantineparser.com/es/blog/com-apple-quarantine-xattr-flags</guid>
      <description>Cómo decodificar un valor com.apple.quarantine: bits como 0083 y 00c3, marca de tiempo hexadecimal, agente y UUID, con fuente y confianza para cada flag.</description>
      <author>Florian Amette</author>
      <pubDate>Wed, 30 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>kMDItemWhereFroms frente al atributo de cuarentena</title>
      <link>https://www.quarantineparser.com/es/blog/kmditemwherefroms-vs-quarantine</link>
      <guid isPermaLink="true">https://www.quarantineparser.com/es/blog/kmditemwherefroms-vs-quarantine</guid>
      <description>¿De dónde vino este archivo en un Mac? Lea kMDItemWhereFroms, compárelo con los datos de cuarentena e interprete un atributo de cuarentena ausente.</description>
      <author>Florian Amette</author>
      <pubDate>Wed, 30 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>.LastGKReject: rechazos de Gatekeeper como evidencia</title>
      <link>https://www.quarantineparser.com/es/blog/lastgkreject-gatekeeper-evidence</link>
      <guid isPermaLink="true">https://www.quarantineparser.com/es/blog/lastgkreject-gatekeeper-evidence</guid>
      <description>Qué registra .LastGKReject cuando Gatekeeper bloquea un elemento, dónde está, cómo recopilarlo y cómo vincular el rechazo con una descarga.</description>
      <author>Florian Amette</author>
      <pubDate>Wed, 30 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Forense de descargas en macOS: un caso paso a paso</title>
      <link>https://www.quarantineparser.com/es/blog/macos-download-investigation-walkthrough</link>
      <guid isPermaLink="true">https://www.quarantineparser.com/es/blog/macos-download-investigation-walkthrough</guid>
      <description>Una intrusión sintética en macOS analizada con Quarantine Parser: cronología, fila borrada recuperada, rechazo de Gatekeeper y AppleDouble en USB.</description>
      <author>Florian Amette</author>
      <pubDate>Wed, 30 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>QuarantineEventsV2: historial de descargas en macOS</title>
      <link>https://www.quarantineparser.com/es/blog/quarantineeventsv2-forensics</link>
      <guid isPermaLink="true">https://www.quarantineparser.com/es/blog/quarantineeventsv2-forensics</guid>
      <description>Qué registra la base QuarantineEventsV2 de macOS: esquema de LSQuarantineEvent, tiempo absoluto de Mac, números de tipo, unión por UUID del xattr y límites.</description>
      <author>Florian Amette</author>
      <pubDate>Wed, 30 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Recuperar registros borrados de QuarantineEventsV2</title>
      <link>https://www.quarantineparser.com/es/blog/recover-deleted-quarantine-events</link>
      <guid isPermaLink="true">https://www.quarantineparser.com/es/blog/recover-deleted-quarantine-events</guid>
      <description>Cómo sobreviven las filas borradas de QuarantineEventsV2 en freeblocks, freelist, frames WAL y diarios de SQLite, cómo preservarlas y qué prueba recuperarlas.</description>
      <author>Florian Amette</author>
      <pubDate>Wed, 30 Sep 2026 00:00:00 GMT</pubDate>
    </item>
  </channel>
</rss>