Series
TCC database fundamentals
4 posts in this series. Read them in order or jump to any one.
- TCC.db Forensics: The Investigator's Guide
What the macOS TCC database records, what it proves and what it does not, the services that matter, and a repeatable workflow for reviewing TCC.db in a case.
- TCC.db Location and Acquisition on macOS
Where the system and per-user TCC.db files live, why Full Disk Access and SIP matter, and how to collect them with the WAL using UAC, Aftermath or Velociraptor.
- The TCC access Table Across macOS Versions
How the TCC.db access table changed from Mojave to Big Sur and Sonoma: allowed, auth_value, auth_reason, pid and last_reminded, plus the other tables.
- Decoding csreq Code Requirements in TCC.db
How to read the csreq and indirect_object_code_identity blobs in TCC.db: compiled code requirements, anchors, identifiers and cdhash-only ad-hoc clients.