Observed arrival · 2026-09-30
FSEvents Parser turns macOS file-system logs into a timeline
A browser-based tool for decoding macOS .fseventsd logs into searchable timelines, path trees, and investigation findings.
○Open
⊠Login
$Paid
†Ads
✦Pretty
●Pro
◎Niche
◉Human
⚑Risk
ƒJS
- For
- macOS incident responders and digital forensics investigators
- Worth noticing
- It accepts UAC, Aftermath, and Velociraptor collections; file modification times are treated as the only available clock.
Field notes
The collection guide gives copy-and-run Terminal commands, including separate examples for a boot volume and an external drive, and notes that Full Disk Access may be needed. It also warns that Aftermath does not collect .fseventsd by default, while UAC can collect it through a macOS artifact. The page says unrelated files are skipped.
Observed signals
Read the marks
Editorial observations of this landing page, not a rating.
○OpenPublic substance visible
✦PrettyNotable craft visible
●ProPolished or operationally mature
◎NicheUnusually specific use
ƒJavaScriptBrowser-side code central
One card from the complete issue