What this tool reads
knowledgeC.db is the SQLite database of Apple's CoreDuet framework. It records “pattern of life” intervals: an app in use or in focus, the screen lit or locked, the Mac on power, web domains visited, notifications. Each row of ZOBJECT belongs to a stream such as /app/usage and carries a start, an end and a UTC offset, which is why it answers “how long” and “when” questions that file system times cannot.
On recent macOS releases many of these streams moved to Biome, which stores each stream as SEGB files of protobuf records. KnowledgeC Parser reads both in your browser: the databases with their write-ahead log applied, and SEGB v1 and v2 containers with a decoder for the documented streams and a generic protobuf view for the others.
Artifacts and structures
- knowledgeC.db (system: /private/var/db/CoreDuet/Knowledge/; user: ~/Library/Application Support/Knowledge/; iOS: /private/var/mobile/Library/CoreDuet/Knowledge/): ZOBJECT joined with ZSOURCE (bundle and device ID) and every ZSTRUCTUREDMETADATA column, whatever the release.
- knowledgeC.db-wal: committed frames are applied (checksums and salts checked); rows only in the WAL and rows it deletes are marked.
- Biome SEGB v1 (56-byte header, 32-byte record headers) and v2 (32-byte header, trailer index), record states (written, deleted, empty) and CRC32.
- Decoded Biome streams: App.InFocus, App.WebUsage, Safari.*, ScreenTime.AppUsage, Notification.Usage, Device.Wireless.WiFi and Bluetooth, SystemSettings.SearchTerms, Device.Metadata, backlight; any other stream by protobuf field number.
- Mac absolute time (seconds since 2001-01-01 UTC) is converted to UTC; ZSECONDSFROMGMT gives the device's local time.
What it answers
- Which apps were in focus or in use, when and for how long, including apps used for the first time.
- When the Mac was unlocked, the display lit and on power: the sessions during which someone could have been at the keyboard.
- Which web domains and pages were visited from which app, including deleted Biome records that are still readable.
- Which rows come from the WAL only, and which rows or records come from other devices on the same Apple Account.
- Findings for triage: activity in the incident window, Terminal use, new apps, file-sharing sites, night-time unlocks, missing -wal files.
Limits
- The data shows that the Mac was in use, not who used it, and it does not record file names or commands.
- Biome payload meanings come from community research (mac_apt, iLEAPP); undecoded fields are shown raw. Validate on test data from the same OS build.
- Freelist pages, older WAL generations and unallocated space are not carved: deleted rows are only recovered where the WAL still shows them.
- Column and stream availability varies between macOS and iOS releases; absent streams are not evidence of deletion.
- Very large collections (hundreds of thousands of events) are supported but slow down the browser; the table shows events page by page.
Getting the files
- Give Terminal Full Disk Access and copy ~/Library/Application Support/Knowledge/knowledgeC.db* and ~/Library/Biome, keeping the layout (see “How to get your data” above).
- For the system database and /private/var/db/biome, prefer a disk or Data volume image over disabling SIP.
- UAC (knowledgec and biome artifacts) and Velociraptor (MacOS.Search.FileFinder with upload) collect them at scale; add the -wal files UAC leaves out.
FAQ
Are my files uploaded?
No. The parser is Rust compiled to WebAssembly and runs in a Web Worker in your browser. Files are read locally and nothing is sent to a server.
Why do I need the -wal file?
knowledgeC.db runs in WAL mode: new rows are written to knowledgeC.db-wal first and copied into the main file later. Without the -wal, the most recent hours or days of events are often missing. The tool marks every row that exists only in the WAL.
My knowledgeC.db has no /app/inFocus rows. Was it wiped?
Probably not. On current macOS releases app focus is recorded mainly in Biome (App.InFocus). Load ~/Library/Biome as well, and check the Sources tab for the oldest event per stream.
Does it prove who was using the Mac?
No. It shows when the Mac was unlocked, when the display was lit and which apps were in focus. Attribution needs other evidence, such as login records, other devices' activity and witness statements.
Which macOS and iOS versions are supported?
Any knowledgeC.db (columns are matched by name, so schema changes between releases are tolerated) and both SEGB v1 and v2. Biome streams without a published field map are shown with their raw protobuf fields.