Palo Alto Networks Unit 42 reported a newly identified forensic artifact in macOS Tahoe 26.x that records user menu selections in Apple’s Biome system. The artifact, named App.MenuItem, is stored at ~/Library/Biome/streams/restricted/App.MenuItem/local and contains SEGB-encapsulated protobuf entries that preserve menu item text and timestamps. According to the report, the data can show deliberate actions taken through the user interface, including saving files, compressing folders, moving items to the trash, and emptying the trash.
The finding gives investigators a new way to reconstruct user intent during incident response and digital forensics, particularly in cases involving suspected data theft or post-activity cleanup. Unit 42 said common commercial forensic tools do not yet parse the stream, but analysts can extract and convert the records for review using the open-source ccl-segb utility. The researchers cautioned that generic menu labels may not identify the exact file or folder involved, so the artifact is most valuable when correlated with other macOS logs and evidence sources.

See real exploitation activity before you spend the cycle.
1 event from the most recent confirmed update back to the earliest known activity.
Unit 42 reported a newly identified macOS Tahoe 26.x forensic artifact in Apple's Biome system called App.MenuItem. The artifact records specific menu selections made by users and can help investigators reconstruct deliberate user actions across the operating system.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.