Spotlight Metadata Store
Also called Spotlight-V100, store.db, kMDItem attributes, mdls.
- PLATFORM
- macOS
- CATEGORY
- File and Folder Access
- INDEX
- 10 of 36
- PROVES
- 4 findings
- CANNOT PROVE
- 5 limits
- QUESTIONS
- 3 answered
The macOS metadata index, holding per-file attributes including last-used dates, use counts, and the URL a downloaded file came from — often for files that no longer exist.
Where it lives
/.Spotlight-V100/Store-V2/ on each indexed volume, plus per-user stores
Name the location in the preservation request rather than describing the artifact in general terms. A request that asks for the record by its path is one the responding party can act on and one a court can enforce; a request for “all forensic evidence of spotlight metadata store” is neither.
What it records
Spotlight stores a rich attribute set for indexed items: name, path, size, content type, kind, and dates including when the item was added, alongside application-supplied attributes. Two attribute families matter most in litigation: last-used date and use count, written when an item is opened through a participating application, and the where-from and downloaded-date attributes recording the source URL of a downloaded file. Attributes are written by applications and by the launch services layer, so coverage varies by application.
What it proves — and what it cannot
These two panels carry equal weight, deliberately. The right-hand column is not a disclaimer: it is the specific, mechanical reason an inference fails, and it is the column opposing counsel will read back to a witness on cross-examination.
What it proves
FINDINGS THIS ARTIFACT WILL SUPPORT ON ITS OWN TERMS.
- That a file with a given name and path existed on the volume, with its size and type, even after deletion
- That a file was opened, and roughly how often, where the last-used and use-count attributes were populated
- The URL a file was downloaded from, and when, from the where-from attributes — direct evidence of provenance rather than inference
- That an external volume held particular content, where that volume carries its own Spotlight store
What it cannot prove
INFERENCES IT WILL NOT CARRY, HOWEVER STRONGLY IT POINTS.
- Which user opened a file, on a multi-user machine, from the volume-level store. Attribution requires the per-user store or corroborating artifacts
- That a file was never opened. Use-count and last-used attributes are written by participating applications; open a document with something that does not write them and nothing appears
- That the use count is a complete tally. It counts opens through the mechanism that maintains it, not every read of the file's bytes
- That an indexed attribute reflects the file's current state. The store is a cache and can be stale or hold entries for items that no longer exist
- That excluded locations contain nothing of interest. Indexing is scoped, can be disabled per volume, and often is on servers and on volumes used for backups
How the finding is attacked
An opinion built on this artifact meets these arguments. Each of them is answerable, and each of them is answered before the report is served rather than at a deposition.
- Showing that the application used to open the file does not maintain the last-used attribute, so the absence of a use record is meaningless
- Arguing that a where-from URL records what the downloading application reported rather than an independently verified source
- Establishing that the store was rebuilt after the events at issue, which erases the historical attribute values
- Questioning attribution where only a volume-level store was examined on a machine with several accounts
What survives, and for how long
The store persists across reboots and can retain attributes for deleted files until it is maintained or rebuilt. Rebuilding the index — a routine troubleshooting step a user can trigger — destroys the historical values without leaving an obvious mark.
More matters are decided by what an artifact never kept than by what it says, which makes preservation timing the most consequential decision in the matter — and it is usually made months before anyone examines anything. The evidence preservation deadline calculator works from the date you first anticipated litigation.
Questions counsel ask
Can Spotlight metadata show that a file was opened on a Mac?
Yes, where the last-used date and use-count attributes were populated. Those are written when an item is opened through a participating application, so they are genuine evidence of use rather than of mere presence. The qualification matters: applications that do not maintain those attributes leave nothing, so an empty use count is not evidence that the file was never opened.
Does Spotlight record where a file was downloaded from?
Yes. The where-from and downloaded-date attributes record the source URL and the time, as reported by the application that performed the download. That is provenance evidence of an unusually direct kind — it survives on the file and in the metadata store, and it frequently outlives browser history, which rolls over far sooner.
Does Spotlight keep records of deleted files?
It can. The metadata store is a cache rather than a live view, so entries for deleted items may persist until the index is maintained or rebuilt, preserving names, paths, sizes, types and attribute values for files that are otherwise gone. Rebuilding the index removes that history in one step, which is worth checking before relying on an absence.
Terms used on this page
Every term below is defined in the forensic glossary — what it is, why a case turns on it, and what happens when it is mishandled.
Related artifacts
No artifact carries a matter on its own. These are the records that corroborate, contradict, or supply the timeline this one cannot.
FSEvents
A per-volume macOS log of directory-level change notifications recording that paths were created, renamed, modified or removed — ordered by event identifier rather than by clock time.
LSQuarantine
A per-user macOS database recording files downloaded by quarantine-aware applications, with the source URL, the downloading application, and a timestamp for each event.
KnowledgeC
A macOS database of user-activity streams recording which applications were in focus and for how long, when the display was lit, and when the device was locked.
Windows Search Index and WordWheelQuery
The desktop search database indexes file properties and, for many file types, full text — so it can retain the content of documents that were deleted before the index was rebuilt.
Whether the spotlight metadata storeevidence in your matter supports the opinion built on it is a question with a testable answer. Law & Forensics retains court-tested digital forensic expert witnesses and forensic neutrals.
A conflicts check and scoping call follow, normally within one business day. Please do not send privileged or case-sensitive material until conflicts have cleared.
- Can This Artifact Prove That?
Start from the claim rather than the artifact: which records bear on it, and what no combination of them establishes.
- Computer forensics
The examination this artifact is collected and analysed in, scoped to a matter and reported so it can be tested.
- The artifact index
All 36 entries, grouped by what they bear on and filterable by platform.
- Daubert and digital evidence
Why an opinion stated one level too strongly is an admissibility problem rather than a point for cross-examination.
Attorney advertising / expert services. This page describes forensic artifacts and the procedural rules that govern expert evidence in general terms. Artifact behaviour varies by operating-system version, build, and configuration, and every observation has to be verified against the system actually in front of you. Nothing here is legal advice, and it is not a substitute for checking the rules, standing orders, and case law of your own forum.