Introduction
Determining when a macOS system was installed is a common requirement in digital forensic investigations.
Establishing the installation date can help investigators create accurate timelines, identify system rebuilds, correlate user activity, determine device ownership periods, and validate witness statements.
Unlike traditional evidence such as documents or photographs, operating system installation events leave behind numerous artefacts throughout the file system, system databases, logs, and configuration files.
Modern versions of macOS utilize the Apple File System (APFS), which introduces additional forensic opportunities and challenges compared to earlier versions that used HFS+.
Investigators should never rely on a single artefact when determining an installation date. Instead, multiple independent sources should be examined and correlated.
Why Installation Date Matters
The installation date of macOS may assist investigators in:
- Establishing device ownership timelines.
- Identifying system rebuilds following malicious activity.
- Determining whether evidence existed before or after an OS installation.
- Verifying compliance with corporate deployment policies.
- Correlating events in civil, criminal, and corporate investigations.
- Detecting attempts to destroy evidence through operating system reinstallation.
Primary macOS Installation Artefacts
1. Installation Log Files
One of the most reliable sources of installation information is the macOS installation log.
Location
Bash
/var/log/install.log
Forensic Value
The installation log records:
- Operating system installations
- Operating system upgrades
- Security updates
- Application installations
- Software package deployments
Investigators can search for entries such as:
- OSInstaller
- InstallAssistant
- macOS Installer
Example:
2025-08-12 09:14:23+0100 OSInstaller Setup completed successfully
This timestamp often provides direct evidence of the installation process.
Collection Method
Bash
cat /var/log/install.log
or
Bash
grep OSInstaller /var/log/install.log
Forensic tools such as Cellebrite Inspector, Magnet AXIOM, EnCase, and FTK can parse these logs automatically.
2. APFS Volume Creation Times
Modern macOS installations create APFS volumes during installation.
Relevant Volumes
- Macintosh HD
- Macintosh HD – Data
- Preboot
- Recovery
- VM
Examination
Investigators can query APFS metadata:
Bash
diskutil apfs list
or
Bash
fsapfsmeta
through forensic analysis tools.
Forensic Significance
The creation timestamp of the system volume frequently corresponds closely with the initial operating system installation.
Example:
Volume Creation:
2025-08-12 08:56:11 UTC
A newly created APFS container often indicates a clean installation.
3. System Version Files
macOS stores operating system version information in property list files.
Location
Bash
/System/Library/CoreServices/SystemVersion.plist
Information Available
- Product version
- Build number
- Installation version
Example:
XML
ProductVersion = 15.0
BuildVersion = 24A335
Although this file does not directly contain the installation date, its file metadata may reveal when the operating system was deployed.
4. File System Metadata
Investigators should examine creation timestamps of core system directories.
Important Directories
Bash
/System
/Applications
/Library
/usr
/private
APFS Timestamps
Metadata may include:
- Created Time
- Modified Time
- Changed Time
- Accessed Time
Example:
/System Created:
2025-08-12 09:03:17 UTC
These timestamps often align closely with the installation process.
5. Setup Assistant Artefacts
When macOS is first installed, Setup Assistant configures the system.
Key File
Bash
/var/db/.AppleSetupDone
Significance
This file is created after Setup Assistant completes.
Metadata associated with this file can provide a strong indicator of the first successful boot following installation.
Example:
Created:
2025-08-12 09:25:44 UTC
The timestamp often represents the first user configuration event after installation.
6. User Account Creation Timestamps
Initial user accounts are commonly created during installation.
Location
Bash
/var/db/dslocal/nodes/Default/users/
Each user account is represented by a property list file.
Example:
Bash
john.plist
Forensic Value
Creation timestamps of the first local user account may indicate when the operating system setup process was completed.
7. Unified Logging System
Modern macOS versions use the Unified Logging architecture.
Examination
Bash
log show
Example query:
Bash
log show --predicate 'eventMessage contains "OSInstaller"'
Relevant Events
Investigators may identify:
- Installation start times
- Installation completion times
- Recovery mode operations
- Upgrade events
- Setup Assistant execution
These records can provide highly accurate timestamps.
8. Recovery Volume Artefacts
The Recovery partition is typically created during operating system installation.
APFS Recovery Volume
Investigators should examine:
Bash
Recovery
Preboot
volumes for creation dates.
These timestamps can corroborate installation timelines.
9. Software Update Databases
macOS maintains records relating to updates and installations.
Potential Locations
Bash
/Library/Updates
and
Bash
/System/Library/AssetsV2
Evidence
Investigators may find:
- Initial update downloads
- Installation package records
- Security response installations
The earliest entries frequently occur shortly after installation.
10. Spotlight Metadata
Spotlight indexing begins shortly after installation.
Database Location
Bash
/.Spotlight-V100
Forensic Significance
The creation of the Spotlight index may indicate when the system first became operational.
Investigators should compare these timestamps with installation logs and user account creation records.
11. Time Machine Artefacts
If Time Machine backups exist, they can help establish installation timelines.
Relevant Information
The earliest backup may show:
- First operating system files
- Original system state
- Initial user account creation
This evidence may validate installation dates independently.
Clean Installation vs Upgrade
Clean Installation Indicators
- New APFS container creation.
- Fresh Recovery volume.
- Empty user profiles.
- Recent creation dates for system directories.
- Setup Assistant artefacts generated.
Upgrade Indicators
- Existing user accounts remain intact.
- Older APFS volumes preserved.
- Installation logs show upgrade activity.
- Historical artefacts predate current operating system version.
Example log entry:
Plain text
Installing macOS 15.0 over macOS 14.6
This indicates an upgrade rather than a clean installation.
Anti-Forensic Considerations
Investigators must be aware of attempts to manipulate installation evidence.
Potential anti-forensic techniques include:
- Reinstalling macOS to destroy evidence.
- Modifying system clocks prior to installation.
- Log deletion.
- APFS snapshot manipulation.
- Time Machine deletion.
- Secure erasure of previous volumes.
Because individual artefacts may be altered, multiple independent evidence sources should always be correlated.
Correlation Methodology
A robust forensic examination should compare:
Artefact Expected Relationship
install.log Installation event
APFS volume creation Near installation time
.AppleSetupDone First setup completion
First user account Initial user creation
Unified logs Installation records
Recovery volume creation Installation event
Spotlight database Initial indexing
System folder timestamps Installation timeframe
When these timestamps align, investigators can establish the installation date with a high degree of confidence.
Best Practice for Forensic Examiners
The most defensible approach is to identify at least three independent artefacts that support the same installation timeframe. A forensic report should document:
- Acquisition method.
- Hash verification.
- Artefact locations.
- Timestamp values.
- Time zone interpretation.
- Correlation between artefacts.
- Alternative explanations considered.
This methodology ensures findings remain reliable and defensible in legal proceedings.
Conclusion
Determining when macOS was installed requires the examination of multiple forensic artefacts rather than reliance on a single timestamp.
Key evidence sources include installation logs, APFS volume creation records, Setup Assistant artefacts, user account creation metadata, unified logging records, Recovery volumes, and system file timestamps.
By correlating these artefacts, investigators can accurately establish installation dates, distinguish between clean installations and upgrades, and identify potential anti-forensic activity.
Such analysis is essential for building reliable timelines and maintaining evidential integrity during digital forensic investigations.
About Athena Forensics
For information on our computer forensic expert services or if you require any advice or assistance please contact a member of our team on 0330 123 4448 or via email on enquiries@athenaforensics.co.uk, further details are available on our contact us page.
Our client’s confidentiality is of the utmost importance. All correspondence is treated with discretion, from initial contact to conclusion of the matter.
We are fully aware of the significance and importance of the information that they encounter and we have been accredited to ISO 9001 for 14 years.
Our premises along with our security procedures have been inspected and approved by law enforcement agencies and we do not disclose personal information to other companies or suppliers.
Our team are all security cleared and we offer non-disclosure agreements if required.
Our premises along with our security procedures have been inspected and approved by law enforcement agencies.
Athena Forensics do not disclose personal information to other companies or suppliers.