SKIP TO CONTENT
FILE AND FOLDER ACCESS10 / 36

Spotlight Metadata Store

Also called Spotlight-V100, store.db, kMDItem attributes, mdls.

PLATFORM
macOS
CATEGORY
File and Folder Access
INDEX
10 of 36
PROVES
4 findings
CANNOT PROVE
5 limits
QUESTIONS
3 answered
WHAT IT IS

The macOS metadata index, holding per-file attributes including last-used dates, use counts, and the URL a downloaded file came from — often for files that no longer exist.

Where it lives

/.Spotlight-V100/Store-V2/ on each indexed volume, plus per-user stores

Name the location in the preservation request rather than describing the artifact in general terms. A request that asks for the record by its path is one the responding party can act on and one a court can enforce; a request for “all forensic evidence of spotlight metadata store” is neither.

What it records

Spotlight stores a rich attribute set for indexed items: name, path, size, content type, kind, and dates including when the item was added, alongside application-supplied attributes. Two attribute families matter most in litigation: last-used date and use count, written when an item is opened through a participating application, and the where-from and downloaded-date attributes recording the source URL of a downloaded file. Attributes are written by applications and by the launch services layer, so coverage varies by application.

What it proves — and what it cannot

These two panels carry equal weight, deliberately. The right-hand column is not a disclaimer: it is the specific, mechanical reason an inference fails, and it is the column opposing counsel will read back to a witness on cross-examination.

What it proves

FINDINGS THIS ARTIFACT WILL SUPPORT ON ITS OWN TERMS.

  • That a file with a given name and path existed on the volume, with its size and type, even after deletion
  • That a file was opened, and roughly how often, where the last-used and use-count attributes were populated
  • The URL a file was downloaded from, and when, from the where-from attributes — direct evidence of provenance rather than inference
  • That an external volume held particular content, where that volume carries its own Spotlight store

What it cannot prove

INFERENCES IT WILL NOT CARRY, HOWEVER STRONGLY IT POINTS.

  • Which user opened a file, on a multi-user machine, from the volume-level store. Attribution requires the per-user store or corroborating artifacts
  • That a file was never opened. Use-count and last-used attributes are written by participating applications; open a document with something that does not write them and nothing appears
  • That the use count is a complete tally. It counts opens through the mechanism that maintains it, not every read of the file's bytes
  • That an indexed attribute reflects the file's current state. The store is a cache and can be stale or hold entries for items that no longer exist
  • That excluded locations contain nothing of interest. Indexing is scoped, can be disabled per volume, and often is on servers and on volumes used for backups

How the finding is attacked

An opinion built on this artifact meets these arguments. Each of them is answerable, and each of them is answered before the report is served rather than at a deposition.

  • Showing that the application used to open the file does not maintain the last-used attribute, so the absence of a use record is meaningless
  • Arguing that a where-from URL records what the downloading application reported rather than an independently verified source
  • Establishing that the store was rebuilt after the events at issue, which erases the historical attribute values
  • Questioning attribution where only a volume-level store was examined on a machine with several accounts

What survives, and for how long

The store persists across reboots and can retain attributes for deleted files until it is maintained or rebuilt. Rebuilding the index — a routine troubleshooting step a user can trigger — destroys the historical values without leaving an obvious mark.

More matters are decided by what an artifact never kept than by what it says, which makes preservation timing the most consequential decision in the matter — and it is usually made months before anyone examines anything. The evidence preservation deadline calculator works from the date you first anticipated litigation.

Questions counsel ask

Can Spotlight metadata show that a file was opened on a Mac?

Yes, where the last-used date and use-count attributes were populated. Those are written when an item is opened through a participating application, so they are genuine evidence of use rather than of mere presence. The qualification matters: applications that do not maintain those attributes leave nothing, so an empty use count is not evidence that the file was never opened.

Does Spotlight record where a file was downloaded from?

Yes. The where-from and downloaded-date attributes record the source URL and the time, as reported by the application that performed the download. That is provenance evidence of an unusually direct kind — it survives on the file and in the metadata store, and it frequently outlives browser history, which rolls over far sooner.

Does Spotlight keep records of deleted files?

It can. The metadata store is a cache rather than a live view, so entries for deleted items may persist until the index is maintained or rebuilt, preserving names, paths, sizes, types and attribute values for files that are otherwise gone. Rebuilding the index removes that history in one step, which is worth checking before relying on an absence.

Terms used on this page

Every term below is defined in the forensic glossary — what it is, why a case turns on it, and what happens when it is mishandled.

No artifact carries a matter on its own. These are the records that corroborate, contradict, or supply the timeline this one cannot.

A FINDING ON THIS ARTIFACT

Whether the spotlight metadata storeevidence in your matter supports the opinion built on it is a question with a testable answer. Law & Forensics retains court-tested digital forensic expert witnesses and forensic neutrals.

A conflicts check and scoping call follow, normally within one business day. Please do not send privileged or case-sensitive material until conflicts have cleared.

WEEKLY BRIEFING

Digital evidence, explained for litigators.

One email a week on forensic method, digital evidence, and expert testimony — written for counsel, not for technicians. No pitches.

DOUBLE OPT-IN · UNSUBSCRIBE ANY TIME · PRIVACY POLICY

  • Can This Artifact Prove That?

    Start from the claim rather than the artifact: which records bear on it, and what no combination of them establishes.

  • Computer forensics

    The examination this artifact is collected and analysed in, scoped to a matter and reported so it can be tested.

  • The artifact index

    All 36 entries, grouped by what they bear on and filterable by platform.

  • Daubert and digital evidence

    Why an opinion stated one level too strongly is an admissibility problem rather than a point for cross-examination.

← BACK TO THE ARTIFACT INDEX

Attorney advertising / expert services. This page describes forensic artifacts and the procedural rules that govern expert evidence in general terms. Artifact behaviour varies by operating-system version, build, and configuration, and every observation has to be verified against the system actually in front of you. Nothing here is legal advice, and it is not a substitute for checking the rules, standing orders, and case law of your own forum.