Skip to content

knowledgeC.db · -wal · Biome SEGB v1/v2

KnowledgeC Parser

Drop a Mac's knowledgeC.db (with its -wal) and Biome streams. App focus and usage, lock and screen sessions, web activity and synced devices become one timeline, with a who-was-at-the-keyboard view and plain-language findings. Parsed in your browser with WebAssembly; nothing is uploaded.

Drop knowledgeC.db, its -wal and Biome streams here

Files, a folder or a ZIP: knowledgeC.db with knowledgeC.db-wal (system and user copies), ~/Library/Biome or a whole UAC / Velociraptor collection. Keep the folder layout: the Biome stream name and the account come from the path.

The sample is synthetic: a fictional MacBook FIN-MBP-03 (user dana.whitlock) with two knowledgeC databases and nine SEGB files.

Parsed in your browser. Nothing is uploaded.

How to get your data

Full acquisition guide

knowledgeC.db lives in two places (system and per user) and runs in WAL mode; Biome keeps one folder of SEGB files per stream. Copy the databases with their -wal, and the Biome folders with their layout, then drop them here.

  1. Copy with Full Disk Access, UAC or Velociraptor
  2. Drop the folder or the ZIP here
  3. Parsed locally: nothing leaves the browser

On the live Mac, give Terminal Full Disk Access first (System Settings › Privacy & Security › Full Disk Access), then paste this block. It copies your knowledgeC.db with its -wal and -shm and your Biome folder, keeping the macOS layout.

zsh · Terminal (Full Disk Access)
C=~/Desktop/kc_case; U="$C/Users/$USER/Library"
mkdir -p "$U/Application Support/Knowledge"
cp -p ~/Library/Application\ Support/Knowledge/knowledgeC.db* "$U/Application Support/Knowledge/"
ditto ~/Library/Biome "$U/Biome"
(cd "$U/Application Support/Knowledge" && shasum -a 256 knowledgeC.db*) > "$C/sha256.txt"

Everything lands in ~/Desktop/kc_case. Drop that folder on the page.

Or zip it to move it off the Mac:

zsh
ditto -c -k --keepParent ~/Desktop/kc_case ~/Desktop/kc_case.zip

The system copy under /private/var/db needs root and is protected by System Integrity Protection: on most Macs this fails with “Operation not permitted”. Do not disable SIP to get it; take it from a disk image instead.

zsh · sudo
S=~/Desktop/kc_case/private/var/db/CoreDuet/Knowledge; mkdir -p "$S"
sudo cp -p /private/var/db/CoreDuet/Knowledge/knowledgeC.db* "$S/"

Gotchas

  • “Operation not permitted” means the copying app lacks Full Disk Access (or the path is SIP-protected), not that the file is missing.
  • Copy knowledgeC.db, -wal and -shm in one go, and work on the copy: opening the original with sqlite3 or a DB browser can checkpoint the WAL.
  • On current macOS releases app focus lives mostly in Biome (App.InFocus): a sparse knowledgeC.db is normal, not a sign of wiping.
  • Retention is short (weeks for most streams): collect early.

What this tool reads

knowledgeC.db is the SQLite database of Apple's CoreDuet framework. It records “pattern of life” intervals: an app in use or in focus, the screen lit or locked, the Mac on power, web domains visited, notifications. Each row of ZOBJECT belongs to a stream such as /app/usage and carries a start, an end and a UTC offset, which is why it answers “how long” and “when” questions that file system times cannot.

On recent macOS releases many of these streams moved to Biome, which stores each stream as SEGB files of protobuf records. KnowledgeC Parser reads both in your browser: the databases with their write-ahead log applied, and SEGB v1 and v2 containers with a decoder for the documented streams and a generic protobuf view for the others.

Artifacts and structures

  • knowledgeC.db (system: /private/var/db/CoreDuet/Knowledge/; user: ~/Library/Application Support/Knowledge/; iOS: /private/var/mobile/Library/CoreDuet/Knowledge/): ZOBJECT joined with ZSOURCE (bundle and device ID) and every ZSTRUCTUREDMETADATA column, whatever the release.
  • knowledgeC.db-wal: committed frames are applied (checksums and salts checked); rows only in the WAL and rows it deletes are marked.
  • Biome SEGB v1 (56-byte header, 32-byte record headers) and v2 (32-byte header, trailer index), record states (written, deleted, empty) and CRC32.
  • Decoded Biome streams: App.InFocus, App.WebUsage, Safari.*, ScreenTime.AppUsage, Notification.Usage, Device.Wireless.WiFi and Bluetooth, SystemSettings.SearchTerms, Device.Metadata, backlight; any other stream by protobuf field number.
  • Mac absolute time (seconds since 2001-01-01 UTC) is converted to UTC; ZSECONDSFROMGMT gives the device's local time.

What it answers

  • Which apps were in focus or in use, when and for how long, including apps used for the first time.
  • When the Mac was unlocked, the display lit and on power: the sessions during which someone could have been at the keyboard.
  • Which web domains and pages were visited from which app, including deleted Biome records that are still readable.
  • Which rows come from the WAL only, and which rows or records come from other devices on the same Apple Account.
  • Findings for triage: activity in the incident window, Terminal use, new apps, file-sharing sites, night-time unlocks, missing -wal files.

Limits

  • The data shows that the Mac was in use, not who used it, and it does not record file names or commands.
  • Biome payload meanings come from community research (mac_apt, iLEAPP); undecoded fields are shown raw. Validate on test data from the same OS build.
  • Freelist pages, older WAL generations and unallocated space are not carved: deleted rows are only recovered where the WAL still shows them.
  • Column and stream availability varies between macOS and iOS releases; absent streams are not evidence of deletion.
  • Very large collections (hundreds of thousands of events) are supported but slow down the browser; the table shows events page by page.

Getting the files

  • Give Terminal Full Disk Access and copy ~/Library/Application Support/Knowledge/knowledgeC.db* and ~/Library/Biome, keeping the layout (see “How to get your data” above).
  • For the system database and /private/var/db/biome, prefer a disk or Data volume image over disabling SIP.
  • UAC (knowledgec and biome artifacts) and Velociraptor (MacOS.Search.FileFinder with upload) collect them at scale; add the -wal files UAC leaves out.

FAQ

Are my files uploaded?

No. The parser is Rust compiled to WebAssembly and runs in a Web Worker in your browser. Files are read locally and nothing is sent to a server.

Why do I need the -wal file?

knowledgeC.db runs in WAL mode: new rows are written to knowledgeC.db-wal first and copied into the main file later. Without the -wal, the most recent hours or days of events are often missing. The tool marks every row that exists only in the WAL.

My knowledgeC.db has no /app/inFocus rows. Was it wiped?

Probably not. On current macOS releases app focus is recorded mainly in Biome (App.InFocus). Load ~/Library/Biome as well, and check the Sources tab for the oldest event per stream.

Does it prove who was using the Mac?

No. It shows when the Mac was unlocked, when the display was lit and which apps were in focus. Attribution needs other evidence, such as login records, other devices' activity and witness statements.

Which macOS and iOS versions are supported?

Any knowledgeC.db (columns are matched by name, so schema changes between releases are tolerated) and both SEGB v1 and v2. Biome streams without a published field map are shown with their raw protobuf fields.

Step-by-step: load knowledgeC.db with its -wal and Biome SEGB streams into a free in-browser parser, set a time range, review sessions and export a timeline.
Byte-level reference for Biome SEGB v1 and v2: headers, trailers, record states, CRC32, alignment, file-name times and protobuf field numbers per stream.
Where knowledgeC.db and Biome streams live on macOS, and how to collect them with Terminal, UAC, Velociraptor or a disk image without losing the WAL.