<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Quarantine Parser — Blog</title>
    <link>https://www.quarantineparser.com/fr/blog</link>
    <description>Latest from Blog</description>
    <language>fr</language>
    <lastBuildDate>Wed, 30 Sep 2026 00:50:48 GMT</lastBuildDate>
    <atom:link href="https://www.quarantineparser.com/fr/blog/feed.xml" rel="self" type="application/rss+xml"/>
    <item>
      <title>Collecter QuarantineEventsV2 : UAC, Aftermath, Velociraptor</title>
      <link>https://www.quarantineparser.com/fr/blog/collect-quarantine-events-uac-aftermath-velociraptor</link>
      <guid isPermaLink="true">https://www.quarantineparser.com/fr/blog/collect-quarantine-events-uac-aftermath-velociraptor</guid>
      <description>Collecter QuarantineEventsV2 (macOS), ses fichiers -wal et -journal, les xattr de quarantaine et .LastGKReject, à la main, avec UAC, Aftermath ou Velociraptor.</description>
      <author>Florian Amette</author>
      <pubDate>Wed, 30 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Flags com.apple.quarantine : lire l’attribut de quarantaine</title>
      <link>https://www.quarantineparser.com/fr/blog/com-apple-quarantine-xattr-flags</link>
      <guid isPermaLink="true">https://www.quarantineparser.com/fr/blog/com-apple-quarantine-xattr-flags</guid>
      <description>Décoder une valeur com.apple.quarantine : bits de flags comme 0083 et 00c3, horodatage hexadécimal, agent et UUID, avec source et niveau de confiance par flag.</description>
      <author>Florian Amette</author>
      <pubDate>Wed, 30 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>kMDItemWhereFroms face à l’attribut de quarantaine</title>
      <link>https://www.quarantineparser.com/fr/blog/kmditemwherefroms-vs-quarantine</link>
      <guid isPermaLink="true">https://www.quarantineparser.com/fr/blog/kmditemwherefroms-vs-quarantine</guid>
      <description>D’où vient ce fichier sur Mac ? Lire kMDItemWhereFroms, le comparer aux données de quarantaine et interpréter un attribut de quarantaine absent.</description>
      <author>Florian Amette</author>
      <pubDate>Wed, 30 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>.LastGKReject : les rejets Gatekeeper comme preuve</title>
      <link>https://www.quarantineparser.com/fr/blog/lastgkreject-gatekeeper-evidence</link>
      <guid isPermaLink="true">https://www.quarantineparser.com/fr/blog/lastgkreject-gatekeeper-evidence</guid>
      <description>Ce que .LastGKReject enregistre quand Gatekeeper bloque un élément, où le trouver, comment le collecter et le relier au téléchargement d’origine.</description>
      <author>Florian Amette</author>
      <pubDate>Wed, 30 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Forensique des téléchargements macOS : un cas pas à pas</title>
      <link>https://www.quarantineparser.com/fr/blog/macos-download-investigation-walkthrough</link>
      <guid isPermaLink="true">https://www.quarantineparser.com/fr/blog/macos-download-investigation-walkthrough</guid>
      <description>Une intrusion macOS synthétique analysée avec Quarantine Parser : chronologie, ligne supprimée récupérée, rejet Gatekeeper et AppleDouble sur USB.</description>
      <author>Florian Amette</author>
      <pubDate>Wed, 30 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>QuarantineEventsV2 : l’historique des téléchargements macOS</title>
      <link>https://www.quarantineparser.com/fr/blog/quarantineeventsv2-forensics</link>
      <guid isPermaLink="true">https://www.quarantineparser.com/fr/blog/quarantineeventsv2-forensics</guid>
      <description>Ce qu’enregistre la base macOS QuarantineEventsV2 : schéma LSQuarantineEvent, temps absolu Mac, numéros de type, jointure par UUID de l’xattr et limites.</description>
      <author>Florian Amette</author>
      <pubDate>Wed, 30 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Récupérer les enregistrements QuarantineEventsV2 supprimés</title>
      <link>https://www.quarantineparser.com/fr/blog/recover-deleted-quarantine-events</link>
      <guid isPermaLink="true">https://www.quarantineparser.com/fr/blog/recover-deleted-quarantine-events</guid>
      <description>Comment des lignes QuarantineEventsV2 supprimées survivent dans les freeblocks, la freelist, le WAL et les journaux SQLite, et ce que prouve leur récupération.</description>
      <author>Florian Amette</author>
      <pubDate>Wed, 30 Sep 2026 00:00:00 GMT</pubDate>
    </item>
  </channel>
</rss>