Re-Opened Apps

Overview

Evidence: Re-Opened Apps
Description: Collect Re-Opened Apps
Category: System
Platform: macos
Short Name: reapps
Is Parsed: Yes
Sent to Investigation Hub: Yes
Collect File(s): No

Background

Re-opened apps preference tracks files and apps restored at login. This data is essential for understanding user session restoration and potential persistence via loginwindow.

Data Collected

This collector gathers structured data about re-opened apps.

Re-Opened Apps Data

FieldDescriptionExample
PlistPlistExample value
FilePathFile PathExample value
OriginalFilenameOriginal FilenameExample value
FileTypeFile TypeExample value
SHA1SHA1Example value
SizeInBytesSize In Bytes123
FileCreatedFile Created2023-10-15 14:30:25+03:00
FileLastAccessedFile Last Accessed2023-10-15 14:30:25+03:00
FileLastChangedFile Last Changed2023-10-15 14:30:25+03:00
FileLastModifiedFile Last Modified2023-10-15 14:30:25+03:00

Collection Method

This collector joins plist, hash, and file tables to enumerate ByHost loginwindow plists and referenced items, recording metadata into re_opened_apps.

Forensic Value

This evidence is crucial for forensic investigations as it highlights recently accessed items and auto‑restored apps that may indicate user behavior or malicious persistence.