← Mac Change Notes

Compare Mac Files Before and After Installing an App

Save a before inventory, install the app, then inventory the same folder again and compare the results. Finder helps with a quick date check; Terminal's find, shasum, and diff provide a repeatable comparison. Differences do not identify their writer.

In this article

This workflow is useful around a trusted installation or update you already intend to perform. A file comparison does not make unfamiliar software safe to run. Its purpose is narrower: preserve two observations so you can explain what changed within a defined scope.

Choose the folder and the question

For a quick look, open the relevant folder in Finder's List view and sort by Date Modified. Apple's Finder guide describes the detailed columns available in that view.

A recent timestamp is a clue, not an installation record. Other apps may update files during the same period, and a current folder cannot show a file that has already disappeared. If you need a comparison, capture the baseline before the action.

Write down the app version, chosen folder, start time, and whether the comparison includes installation only or also the app's first launch. Keep that scope the same afterward. A first launch, sign-in, import, or update can be a separate observation.

For a PKG installer, its package receipt provides another kind of evidence. A receipt and a before/after comparison answer different questions; neither substitutes for the other.

Save two native file inventories

The following commands inspect one folder using tools included on the tested Mac. They do not modify the inspected files. They create comparison reports in a separate temporary directory.

First run comparison_dir="$(mktemp -d)" in Terminal. Keep this Terminal session open. Then run cd "/path/to/the/folder", replacing the quoted placeholder with the real folder you want to inspect. Confirm that the command succeeds before continuing.

For the before inventory, run:

/usr/bin/find -s . -type f -print > "$comparison_dir/before-paths.txt"

Perform the intended installation or update, return to the same Terminal session and folder, then run:

/usr/bin/find -s . -type f -print > "$comparison_dir/after-paths.txt"

Compare the reports with /usr/bin/diff -u "$comparison_dir/before-paths.txt" "$comparison_dir/after-paths.txt".

The Apple-distributed find manual documents traversal and selection options. Here, -s gives a consistent lexical traversal, -type f selects regular files, and -print records paths. Use man find and man diff for your Mac's installed manuals.

In a unified diff, lines beginning with - belong to the before report and lines beginning with + belong to the after report. The --- and +++ header lines label the reports. A diff exit status of 1 means differences were found; it is not, by itself, an execution failure.

Keep any permission or traversal errors with the result. An incomplete scan must not become an “all clear.”

Test the blind spot: a name can stay the same

We ran a controlled comparison on macOS 15.7.5 on September 30, 2026. The test used four artificial text files in a temporary folder. It did not install an application or inspect personal data.

Between observations, we added one file, removed one, renamed one, and changed edit.txt from AAAA to BBBB, retaining the same byte count.

Controlled changePath-only comparisonSHA-256 comparison
Add added.txtNew path visibleNew path and hash visible
Remove removed.txtOld path missingOld path and hash missing
Rename old-name.txtOld and new names appearSame content hash at a different name
Change edit.txt, same sizeNo difference for that fileContent hash changes
Leave keep.txt unchangedNo differenceHash stays identical

The path inventory answered “Which names are present?” It missed the in-place edit. A hash inventory answered an additional question: “Did the bytes read for this file change?”

To capture hashes, use /usr/bin/find -s . -type f -exec /usr/bin/shasum -a 256 {} + > "$comparison_dir/before-hashes.txt" before the action. Repeat it afterward with after-hashes.txt, then compare those two reports with diff -u.

Hashing reads file contents and can take longer on large folders. The test used ordinary filenames; line-oriented reports need extra handling for names containing newlines. These commands omit directories and symbolic links as selected items, and a content hash does not record every metadata change.

Interpret the comparison within its limits

Two inventories are observations made over time, not an atomic picture of an active filesystem. Files can change during either traversal. A file created and removed between captures may appear in neither report. An unchanged endpoint does not prove that nothing happened in between.

Apple's archived File System Events guide discusses combining notifications with scans and cached metadata, including the need to rescan when events are dropped. Even a monitoring design needs explicit coverage and failure handling.

Most importantly, a difference does not identify the process responsible. An updater, synchronization client, or your own actions may change the same folder. Record the timing and compare the result with vendor documentation before attributing it to the installer.

Do not turn the added-file list into a deletion script. An app's support data may contain documents, settings, or shared resources you need.

Use the comparison method that matches the evidence

If you already have two folder copies, a visual directory comparison can be more convenient than text manifests. VisualDiffer's upstream project describes side-by-side directory and file comparisons. That is an alternative for comparing available states, not a way to reconstruct a missing baseline; we did not benchmark it in this experiment.

VaultDog provides a different, app-centered comparison. It saves a local scan baseline and marks installed apps whose recorded fingerprint changes. The current fingerprint includes version, build, sandbox status, supported declaration identifiers, and associated artifact identifiers.

That helps direct attention to an app worth reviewing. It is not the SHA-256 file-content comparison demonstrated here, a record of every filesystem write, or a complete history from before scanning began. The getting started guide covers the scan workflow.

Keep the original reports, their scope, and any errors together. The defensible result is “these observed states differ in these ways,” followed by the separate evidence you use to explain why.