Type Apple Filesystem Events SQL
Jump to navigation
Jump to search
| Defined Constant | Type_Apple_Filesystem_Events_SQL
|
| File Type Value | 1183 |
| Parent Type | ASCII |
| Carve | No |
| Format Details | No |
| MIME Type | text/plain
|
| Filename Extension | sql
|
| Typical Filename | FSEvents.sql
|
Apple filesystem events exported as SQL statements.
Description
This is the result of Truxton stitching together all of the Apple Filesystem Event data files on the system. The output is a SQL script that can be used to create a SQLite database compatible with the output of other tools.
Details
- FSE Parser
- Another FSE Parser
- Joachim Metz
- Nicole Ibrahim
- Crowdstrike - More details about the events at Crowdstrike. Looks like they break out more bit fields.
Filenames Seen
The filename contains the Facebook account id.
FSEvents.sql