Skip to content

How to Analyze knowledgeC.db and Biome in Your Browser

Step-by-step: load knowledgeC.db with its -wal and Biome SEGB streams into a free in-browser parser, set a time range, review sessions and export a timeline.

Published on 6 min read

TL;DR. Collect knowledgeC.db with its -wal and the Biome streams folder, drop them (or a ZIP) on KnowledgeC Parser, check the Sources tab, read the Findings, set a time range, then work through Sessions, Timeline, Apps, Web and Biome. Export CSV, Timesketch CSV or JSON. Parsing runs in WebAssembly inside a Web Worker in your browser; the files are never uploaded.

This is the hands-on companion to the knowledgeC.db forensics guide. For the reasoning behind session analysis, read who was using the Mac. The examples use the built-in sample, which is synthetic and fictional: it was generated for this tool and does not come from a real case. Labels in the interface may change slightly over time; the steps stay the same.

Before you start

You needWhy
knowledgeC.db + -wal (+ -shm), system and userRecent events are often only in the WAL
The Biome streams folder, layout intactThe stream name, local / remote and tombstone come from the path
The Users/<name>/ part of the pathThe tool attributes files to that account
A current desktop browserParsing runs as WebAssembly in a Web Worker

Step 1: Collect the files

The user database (~/Library/Application Support/Knowledge/knowledgeC.db) and Biome user streams are protected by TCC: the collecting process needs Full Disk Access. The system database (/private/var/db/CoreDuet/Knowledge/knowledgeC.db) is restricted by SIP; a disk image is usually the cleaner route. Copy the -wal and -shm files with each database, and hash everything.

Commands, UAC and Velociraptor options and their gaps are covered in knowledgeC.db and Biome: locations and acquisition and in the collection guide on the home page.

Step 2: Load the files

Open the tool home page and drop:

  • individual files (knowledgeC.db, knowledgeC.db-wal, SEGB files);
  • a folder, for example a copied Library;
  • a ZIP of a collection.

To learn the interface first, click Try a sample. The workspace goes full screen; press Esc to leave it.

The sample is a fictional MacBook, FIN-MBP-03, user dana.whitlock: a system and a user knowledgeC.db, each with a -wal, and Biome files for App.InFocus (including an older tombstone file and a stream synced from an iPhone), App.WebUsage, Notification.Usage, Device.Metadata and App.MenuItem, in both SEGB v1 and v2.

Step 3: Check the Sources tab

Before reading any event, confirm what was parsed:

  • Each knowledgeC.db paired with its -wal. The tool reads the database as SQLite would after the WAL, and compares it with the main file alone. Rows that exist only in the WAL, and rows the WAL removed, are flagged. In the sample, every system row after 10:00 UTC on 2026-09-14 is WAL-only, and one old row is removed by the WAL. See knowledgeC WAL recovery.
  • Scope: system or user database, from the path.
  • Biome files: stream name, SEGB version, local, remote/<device UUID> or tombstone, record counts per state and CRC failures.
  • Problems: a file that starts with zeros (probably copied while locked), a truncated SEGB file, or a SEGB file whose stream name is unknown because the folder layout was lost. The -shm file is listed but not needed.

Step 4: Read the Findings

The Findings tab summarises what stands out. Treat each item as a lead: open it, check the underlying records, and decide whether it belongs in the report. The sample was built so that the leads worth following are an unlocked session during the lunch break, a first appearance of Terminal, deleted Biome web records and a short unlock in the middle of the night.

Step 5: Set the time range

A custom range keeps every tab focused on the same window:

ControlUse
From / ToSet to the second, for example 2026-09-14 10:00:00 to 10:55:00 UTC
PresetsQuick ranges
Around this eventCentres the range on a selected event
Density stripShows where events cluster, to spot bursts and gaps

The range is stored in the URL hash, so a colleague who opens the same link with the same files sees the same window, and it is written into export file names.

Step 6: Review sessions and the timeline

The Sessions tab answers "who was at the keyboard" as far as the data allows: unlocked intervals built from /device/isLocked, to read against backlight, power and app focus. In the sample, the session from 10:04:31 to 10:49:38 UTC (12:04 to 12:49 local) falls during Dana's lunch break. The session shows activity under her account, not who was typing; the method article explains the limits.

The Timeline tab merges knowledgeC and Biome events. Times are stored in UTC; for knowledgeC rows, ZSECONDSFROMGMT gives the local offset (+02:00 in the sample). Biome App.InFocus "in focus" and "out of focus" records are paired into intervals per app.

Step 7: Check apps, web and Biome details

  • Apps: focus and usage per bundle ID. In the sample, com.apple.Terminal appears only inside the incident session.
  • Web: URLs and domains from /app/webUsage, /safari/history and App.WebUsage, including files.example and transfer.example.
  • Biome: one line per stream, store and origin (local, remote with the device UUID, tombstone) with the SEGB version, record counts, deleted records and CRC failures. Click a stream to list its records; each record's details show its state, CRC result and the decoded protobuf fields. Streams without a public field map, such as App.MenuItem, are decoded without a schema and keep raw field numbers (SEGB format).

Synced records from the iPhone (remote/<UUID> in Biome, another ZDEVICEID in knowledgeC) are marked as such. Keep them out of the Mac's activity.

Step 8: Export the results

ExportContents
CSV: timelineEvents in the current range
CSV: appsPer-app totals
CSV: sessionsUnlocked sessions
Timesketch CSVEvents in a format Timesketch can import
JSONThe parsed events, for scripts and other tools

Keep the exports with the hashes of the source files. The range in each file name records which window the export covers.

Limits to keep in mind

  • Field meanings for Biome payloads come from mac_apt and iLEAPP, not Apple. Undecoded fields stay raw.
  • Records show activity under an account on a device, not identity.
  • Retention is limited (about four weeks in knowledgeC, around 28 days for most Biome streams on iOS research); measure it per stream.
  • For important records, cross-check with APOLLO, mac_apt or ccl-segb.

KnowledgeC Parser is an independent project, not affiliated with or endorsed by Apple.

Related articles

What knowledgeC.db records on macOS, where it lives, how ZOBJECT and its streams work, how to convert its timestamps, and what the data does not prove.
knowledgeC.db or Biome? How the two macOS activity stores differ, which Biome stream matches which knowledgeC stream, and what to expect on recent releases.
Rebuild unlocked sessions on a Mac from lock, backlight, power and app focus records in knowledgeC.db and Biome, and learn what they cannot prove.