THE DFIR BLOG
Menu

MacOS Forensics

What's 'Installed' on your Mac?

7/20/2019

 
Install.log file has an immense value to see all the installations on you Mac. 
Use this command on your terminal to get the list: 
​

grep 'Installed' /private/var/log/install.log
This log file has an immense forensic value to identify the user installation activity. Questions like remotely installed applications, failed installation can be answered by analyzing the  'Install.log' file.
cat /private/var/log/install.log

    

Comments are closed.

    Archives

    May 2024
    July 2019
    April 2018

    Categories

    All
    Mac Forensics
    Plist

    RSS Feed

  • Infosec
  • Mac Forensics
  • Windows Forensics
  • Linux Forensics
  • Memory Forensics
  • Incident Response
  • Blog
  • About Me
  • Infosec
  • Mac Forensics
  • Windows Forensics
  • Linux Forensics
  • Memory Forensics
  • Incident Response
  • Blog
  • About Me