Skip to content

Blog

Guides to knowledgeC.db and Biome forensics on macOS: streams, SEGB format, WAL recovery, acquisition and interpretation.

Step-by-step: load knowledgeC.db with its -wal and Biome SEGB streams into a free in-browser parser, set a time range, review sessions and export a timeline.
Byte-level reference for Biome SEGB v1 and v2: headers, trailers, record states, CRC32, alignment, file-name times and protobuf field numbers per stream.
Where knowledgeC.db and Biome streams live on macOS, and how to collect them with Terminal, UAC, Velociraptor or a disk image without losing the WAL.
What knowledgeC.db records on macOS, where it lives, how ZOBJECT and its streams work, how to convert its timestamps, and what the data does not prove.
knowledgeC.db or Biome? How the two macOS activity stores differ, which Biome stream matches which knowledgeC stream, and what to expect on recent releases.
Why recent knowledgeC events often exist only in knowledgeC.db-wal, how SQLite WAL frames, salts and checkpoints work, and how to read added or removed rows.
Rebuild unlocked sessions on a Mac from lock, backlight, power and app focus records in knowledgeC.db and Biome, and learn what they cannot prove.