Observed arrival · 2026-09-30
TCC Parser turns macOS permission records into an investigation timeline
A browser-based forensic tool that parses macOS TCC databases and related files into permissions, app records, and history.
- For
- macOS incident responders and digital forensic investigators
- Worth noticing
- The guide warns that granting Terminal Full Disk Access creates its own TCC.db record, which investigators should distinguish from a suspect grant.
Field notes
The acquisition instructions preserve the system and per-user folder layout so the parser can distinguish database sources, and they describe dropping either a folder or an archive. The guide compares collection methods: UAC and Aftermath are described as copying TCC.db without its WAL, while the quick method includes the associated files. It also cautions that using Terminal to collect data requires Full Disk Access, which adds a record investigators need to account for.
Observed signals
Read the marks
Editorial observations of this landing page, not a rating.
One card from the complete issue