SKIP TO CONTENT
FILE AND FOLDER ACCESS09 / 36

FSEvents

Also called fseventsd, macOS file system events, .fseventsd.

PLATFORM
macOS
CATEGORY
File and Folder Access
INDEX
9 of 36
PROVES
5 findings
CANNOT PROVE
5 limits
QUESTIONS
3 answered
WHAT IT IS

A per-volume macOS log of directory-level change notifications recording that paths were created, renamed, modified or removed — ordered by event identifier rather than by clock time.

Where it lives

/.fseventsd on each mounted volume, one compressed log file per batch

Name the location in the preservation request rather than describing the artifact in general terms. A request that asks for the record by its path is one the responding party can act on and one a court can enforce; a request for “all forensic evidence of fsevents” is neither.

What it records

The file system events daemon writes compressed logs recording a path and a set of change flags for each notification, so an examiner can see that a path was created, renamed, had its content modified, had its inode metadata changed, or was removed. The records are sequenced by a monotonically increasing event identifier. Individual records do not carry their own wall-clock timestamps; timing is inferred from the containing log file's own dates and from anchoring events, which is the single most important limitation of the artifact.

What it proves — and what it cannot

These two panels carry equal weight, deliberately. The right-hand column is not a disclaimer: it is the specific, mechanical reason an inference fails, and it is the column opposing counsel will read back to a witness on cross-examination.

What it proves

FINDINGS THIS ARTIFACT WILL SUPPORT ON ITS OWN TERMS.

  • That a path existed on the volume and was created, renamed, modified or removed, even where the file is long gone
  • The order in which changes occurred, from the event identifier sequence
  • That a volume was mounted and written to, including external volumes that keep their own log
  • Directory structures that no longer exist, reconstructed from the paths in the records
  • Bulk activity patterns — a large number of creations under one directory tree in a short identifier range

What it cannot prove

INFERENCES IT WILL NOT CARRY, HOWEVER STRONGLY IT POINTS.

  • When any individual event happened. Records carry no per-event wall-clock time; timing comes from the log file's own dates and from anchoring against other artifacts, and an examiner who states an FSEvents record to the minute has supplied precision the format does not contain
  • Which user or which process made the change. There is no account or process attribution anywhere in the record
  • What a file contained, or that content was read. Only paths and change flags are stored
  • That a copy occurred. A creation flag on a destination volume is consistent with a copy and equally consistent with a save, a download, or an application writing its own file
  • A complete history. Logs are purged as the volume fills and are removed on some maintenance paths, so an absent record is not an absent event

How the finding is attacked

An opinion built on this artifact meets these arguments. Each of them is answerable, and each of them is answered before the report is served rather than at a deposition.

  • Pressing on the absence of per-event timestamps and the assumptions used to place records on a clock
  • Showing that the flags do not distinguish a user action from an application or system process doing the same thing
  • Establishing how far back the surviving logs on the volume reach and whether that covers the period at issue
  • Questioning whether the parser correctly resolved flag combinations, which are frequently coalesced into a single record for a path

What survives, and for how long

Logs live on the volume itself, so an external drive carries its own FSEvents history and can be examined even when the Mac cannot. They roll as space is reclaimed, and coverage on a busy volume can be short; a reformat removes them entirely.

More matters are decided by what an artifact never kept than by what it says, which makes preservation timing the most consequential decision in the matter — and it is usually made months before anyone examines anything. The evidence preservation deadline calculator works from the date you first anticipated litigation.

Questions counsel ask

What does FSEvents prove on a Mac?

FSEvents proves that a path on that volume was created, renamed, modified or removed, and the order in which those changes happened relative to one another. It is the standard way to show that files and folders existed on a macOS volume after they have been deleted. It attributes nothing to a user or a process and records no file content.

Do FSEvents records have timestamps?

Not per record, and this is the most misunderstood point about the artifact. Individual entries are sequenced by an increasing event identifier, not stamped with a clock time. Timing is inferred from the dates of the log file containing them and by anchoring the sequence against events dated in other artifacts. Testimony placing an FSEvents record at a precise minute is asserting more than the format holds.

Can FSEvents show that files were copied to an external drive?

It can show that files with those paths were created on the external volume, if that volume's own FSEvents log survives and is examined. What it cannot do is establish that the creation was a copy rather than a save, a download, or an application writing its own data — and it identifies no user or process. The copy inference needs corroboration from the source machine.

Terms used on this page

Every term below is defined in the forensic glossary — what it is, why a case turns on it, and what happens when it is mishandled.

No artifact carries a matter on its own. These are the records that corroborate, contradict, or supply the timeline this one cannot.

A FINDING ON THIS ARTIFACT

Whether the fseventsevidence in your matter supports the opinion built on it is a question with a testable answer. Law & Forensics retains court-tested digital forensic expert witnesses and forensic neutrals.

A conflicts check and scoping call follow, normally within one business day. Please do not send privileged or case-sensitive material until conflicts have cleared.

WEEKLY BRIEFING

Digital evidence, explained for litigators.

One email a week on forensic method, digital evidence, and expert testimony — written for counsel, not for technicians. No pitches.

DOUBLE OPT-IN · UNSUBSCRIBE ANY TIME · PRIVACY POLICY

  • Can This Artifact Prove That?

    Start from the claim rather than the artifact: which records bear on it, and what no combination of them establishes.

  • Computer forensics

    The examination this artifact is collected and analysed in, scoped to a matter and reported so it can be tested.

  • The artifact index

    All 36 entries, grouped by what they bear on and filterable by platform.

  • Daubert and digital evidence

    Why an opinion stated one level too strongly is an admissibility problem rather than a point for cross-examination.

← BACK TO THE ARTIFACT INDEX

Attorney advertising / expert services. This page describes forensic artifacts and the procedural rules that govern expert evidence in general terms. Artifact behaviour varies by operating-system version, build, and configuration, and every observation has to be verified against the system actually in front of you. Nothing here is legal advice, and it is not a substitute for checking the rules, standing orders, and case law of your own forum.