LSQuarantine
Also called QuarantineEventsV2, macOS quarantine database, com.apple.quarantine, Gatekeeper quarantine.
- PLATFORM
- macOS
- CATEGORY
- File and Folder Access
- INDEX
- 11 of 36
- PROVES
- 4 findings
- CANNOT PROVE
- 5 limits
- QUESTIONS
- 3 answered
A per-user macOS database recording files downloaded by quarantine-aware applications, with the source URL, the downloading application, and a timestamp for each event.
Where it lives
~/Library/Preferences/com.apple.LaunchServices.QuarantineEventsV2 (SQLite), plus the com.apple.quarantine extended attribute on the file itself
Name the location in the preservation request rather than describing the artifact in general terms. A request that asks for the record by its path is one the responding party can act on and one a court can enforce; a request for “all forensic evidence of lsquarantine” is neither.
What it records
When a quarantine-aware application writes a downloaded file, macOS records an event holding a unique identifier, the timestamp, the name of the agent that performed the download, and the origin and data URLs. The same identifier is written to the file as an extended attribute, so a file on disk can be matched to its download event. Applications that do not participate — many command-line tools among them — create no record at all.
What it proves — and what it cannot
These two panels carry equal weight, deliberately. The right-hand column is not a disclaimer: it is the specific, mechanical reason an inference fails, and it is the column opposing counsel will read back to a witness on cross-examination.
What it proves
FINDINGS THIS ARTIFACT WILL SUPPORT ON ITS OWN TERMS.
- That a named application downloaded a file at a recorded time, and the URL it came from
- A link between a specific file still on disk and the download event that produced it, through the shared identifier in the extended attribute
- Per-user attribution, since the database sits in an individual account's library
- That content arrived from outside the machine rather than being created on it
What it cannot prove
INFERENCES IT WILL NOT CARRY, HOWEVER STRONGLY IT POINTS.
- That the file was opened, executed, or used in any way. Quarantine records arrival, not use
- That a file without a quarantine record was not downloaded. Command-line transfers, many synchronisation clients, and any application that does not set the attribute leave nothing
- That the recorded URL is where the content actually originated. The value is what the downloading application reported, and redirection chains are collapsed
- That the person at the keyboard chose the download. Automatic and background downloads by a participating application produce the same kind of record
- That the absence of an entry means nothing was downloaded on a date. The extended attribute can be stripped in one command and the database rows deleted, both without administrative rights
How the finding is attacked
An opinion built on this artifact meets these arguments. Each of them is answerable, and each of them is answered before the report is served rather than at a deposition.
- Pointing out how trivially the extended attribute is removed and the database edited by an ordinary user
- Arguing that the source URL is self-reported by the downloading application rather than independently observed
- Showing that the artifact records arrival only, and that any claim about what happened to the file afterwards rests on other evidence
- Establishing that the tool the party actually used does not set quarantine attributes, which makes the absence of records uninformative
What survives, and for how long
The database persists in the user's library across reboots, and older rows are pruned over time — the retention behaviour has changed between macOS releases, so the window should be established on the system examined rather than assumed. The extended attribute survives on the file until it is stripped, which happens routinely when files are copied through filesystems that do not carry extended attributes.
More matters are decided by what an artifact never kept than by what it says, which makes preservation timing the most consequential decision in the matter — and it is usually made months before anyone examines anything. The evidence preservation deadline calculator works from the date you first anticipated litigation.
Questions counsel ask
What does the macOS quarantine database prove?
It proves that a quarantine-aware application downloaded a particular file at a particular time from a particular URL, under a particular user account. Because the same identifier is written to the file as an extended attribute, a file still on disk can be tied back to its download event. It says nothing about whether the file was ever opened or run.
Can the com.apple.quarantine attribute be removed?
Yes, by any ordinary user with a single command, and it is also stripped automatically when a file is copied through filesystems that do not carry extended attributes — many USB drives among them. So a file without the attribute is not evidence that it was not downloaded, and the database rows themselves can be deleted just as easily.
Does LSQuarantine show that a downloaded file was opened?
No. Quarantine records the arrival of a file and the approval prompt mechanism around it, not its use. Evidence that a downloaded application or document was actually opened comes from elsewhere — the Spotlight last-used attributes, the KnowledgeC application usage database, or the unified logs — and those have shorter retention than the quarantine record itself.
Terms used on this page
Every term below is defined in the forensic glossary — what it is, why a case turns on it, and what happens when it is mishandled.
Related artifacts
No artifact carries a matter on its own. These are the records that corroborate, contradict, or supply the timeline this one cannot.
Spotlight Metadata Store
The macOS metadata index, holding per-file attributes including last-used dates, use counts, and the URL a downloaded file came from — often for files that no longer exist.
Browser History, Cache and Downloads
Per-profile databases recording pages visited with timestamps and transition types, files downloaded with their source URLs and target paths, and cached copies of retrieved content.
KnowledgeC
A macOS database of user-activity streams recording which applications were in focus and for how long, when the display was lit, and when the device was locked.
macOS Unified Logs
The macOS system-wide log stream, recording process launches, device attachment, authentication and application behaviour in extraordinary detail for a short period.
Whether the lsquarantineevidence in your matter supports the opinion built on it is a question with a testable answer. Law & Forensics retains court-tested digital forensic expert witnesses and forensic neutrals.
A conflicts check and scoping call follow, normally within one business day. Please do not send privileged or case-sensitive material until conflicts have cleared.
- Can This Artifact Prove That?
Start from the claim rather than the artifact: which records bear on it, and what no combination of them establishes.
- Computer forensics
The examination this artifact is collected and analysed in, scoped to a matter and reported so it can be tested.
- The artifact index
All 36 entries, grouped by what they bear on and filterable by platform.
- Daubert and digital evidence
Why an opinion stated one level too strongly is an admissibility problem rather than a point for cross-examination.
Attorney advertising / expert services. This page describes forensic artifacts and the procedural rules that govern expert evidence in general terms. Artifact behaviour varies by operating-system version, build, and configuration, and every observation has to be verified against the system actually in front of you. Nothing here is legal advice, and it is not a substitute for checking the rules, standing orders, and case law of your own forum.