Shining a light on Spotlight: Leveraging Apple's desktop search utility to recover deleted file metadata on macOS

by   Tajvinder Singh Atwal, et al.

Spotlight is a proprietary desktop search technology released by Apple in 2004 for its Macintosh operating system Mac OS X 10.4 (Tiger) and remains as a feature in current releases of macOS. Spotlight allows users to search for files or information by querying databases populated with filesystem attributes, metadata, and indexed textual content. Existing forensic research into Spotlight has provided an understanding of the metadata attributes stored within the metadata store database. Current approaches in the literature have also enabled the extraction of metadata records for extant files, but not for deleted files. The objective of this paper is to research the persistence of records for deleted files within Spotlight's metadata store, identify if deleted database pages are recoverable from unallocated space on the volume, and to present a strategy for the processing of discovered records. In this paper, the structure of the metadata store database is outlined, and experimentation reveals that records persist for a period of time within the database but once deleted, are no longer recoverable. The experimentation also demonstrates that deleted pages from the database (containing metadata records) are recoverable from unused space on the filesystem.



page 1

page 2

page 3

page 5

page 6

page 7

page 8

page 9


Metadata Extraction from Raw Astroparticle Data of TAIGA Experiment

Today, the operating TAIGA (Tunka Advanced Instrument for cosmic rays an...

Evaluation of Semantic Metadata Pair Modelling Using Data Clustering

Metadata presents a medium for connection, elaboration, examination, and...

Forensic Analysis of Video Files Using Metadata

The unprecedented ease and ability to manipulate video content has led t...

The Variable Quality of Metadata About Biological Samples Used in Biomedical Experiments

We present an analytical study of the quality of metadata about samples ...

How Many Pages? Paper Length Prediction from the Metadata

Being able to predict the length of a scientific paper may be helpful in...

Cleaning Noisy and Heterogeneous Metadata for Record Linking Across Scholarly Big Datasets

Automatically extracted metadata from scholarly documents in PDF formats...

Harvest – An Open Source Toolkit for Extracting Posts and Post Metadata from Web Forums

Automatic extraction of forum posts and metadata is a crucial but challe...
This week in AI

Get the week's most popular data science and artificial intelligence research sent straight to your inbox every Saturday.