Join our Newsletter — 33% off our NHI Course

LSQuarantine Database

The LSQuarantine database records files downloaded through macOS applications that honor quarantine metadata, including browsers and email clients. It can help investigators recover file names, source URLs, sender details, and timestamps. The data is useful for triage, but it can be cleared through normal user actions, so it is not a complete record.

What the LSQuarantine Database Records

The LSQuarantine database is part of macOS’s quarantine metadata path, so it captures evidence that a file was downloaded by an application that honors that metadata. In practice, that makes it a useful triage source for understanding what arrived on a system and when.

Because the database is tied to download events rather than deep content inspection, it is best treated as a provenance and activity record. It can surface file names, source URLs, sender details, and timestamps, but it does not by itself prove whether a file was later opened, executed, or removed.

Why It Matters in Forensics and Triage

Investigators often use LSQuarantine to reconstruct user-facing acquisition paths, especially when the download came through a browser, email client, or another app that preserves quarantine markers. That can help establish the likely origin of a suspicious file and narrow the timeline of exposure.

The record is most valuable when you need quick context, not when you need a complete endpoint history. Since normal user actions can clear the entry, absence from LSQuarantine should never be treated as proof that no download occurred.

For a broader view of download-tracking artifacts and what they can reveal during incident triage, see MongoBleed breach, which shows how exposed data can become visible through database-side evidence and misconfiguration.

Limits of the Evidence

LSQuarantine is an artifact of convenience, not a preservation system. Its value depends on whether the originating application wrote quarantine metadata, whether the entry still exists, and whether the system has been cleaned, reset, or partially migrated.

That means the database should be corroborated with other endpoint, browser, mail, or telemetry sources when the question is attribution, execution, or full user activity reconstruction. A single preserved quarantine record can be strong supporting evidence, but it is rarely the whole story.

In security terms, this is a visibility problem: useful evidence may be present, partial, or gone, depending on user behavior and application handling. For comparison, macOS hardening and baseline expectations are often discussed alongside CIS Benchmarks.

How It Fits Into macOS Investigation Workflows

LSQuarantine is best interpreted as one artifact in a larger macOS investigation workflow. It becomes more meaningful when paired with browser history, mail artifacts, file system metadata, launch events, and any logs that show how the file moved from download to use.

The practical question is not just “was the file downloaded?”, but “what was the likely source, when did it arrive, and what other evidence supports that sequence?” For defenders, that helps separate benign user activity from suspicious acquisition patterns that may precede execution or staging.

Where quarantine metadata intersects with file provenance and defensive baselines, the NIST SP 800-53 Rev 5 Security and Privacy Controls and NIST National Vulnerability Database are useful reference points for control expectations and product-risk context.

Risk and Threat Considerations

LSQuarantine can be cleared through normal user activity, so relying on it as a sole source of truth creates a visibility gap. That gap matters when an adversary wants to hide download provenance, minimize forensic residue, or move a malicious file through a user-driven acquisition path.

Failure mechanism: The artifact is mutable and incomplete, and its presence depends on application support for quarantine metadata plus the user’s subsequent actions. Attackers and users can both reduce its evidentiary value by deleting, replacing, or avoiding the metadata path.

Impact: Investigators may lose source attribution, timing precision, or confidence in download lineage, which can slow incident scoping and make it harder to connect a suspicious file to its origin.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5, CIS Controls v8 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
NIST SP 800-53 Rev 5 AU-2 — Event Logging LSQuarantine is an evidentiary log source used in incident triage and provenance reconstruction.
Recommendation — Preserve and review artifact-derived evidence to support incident scoping and timeline reconstruction.
CIS Controls v8 CIS-8 — Audit Log Management Quarantine records function as a host-side trace that supports investigation and logging hygiene.
Recommendation — Retain endpoint and application logs that can corroborate download provenance and user activity.
NIST CSF 2.0 DE.CM-08 — Vulnerability Scans are performed Endpoint artifact review and corroborating telemetry support ongoing detection and monitoring activities.
Recommendation — Correlate endpoint artifacts with monitoring data to improve detection confidence and response speed.

Practitioner Guidance

What to watch for: Treat LSQuarantine as a fast triage signal, then validate it against independent evidence before drawing conclusions about execution or persistence. If the database is empty or partially populated, assume the record set may be incomplete rather than clean.

Practitioner takeaway: Use LSQuarantine to answer “where did this file likely come from?”, not “what happened to it afterward?”