How to Analyze knowledgeC.db and Biome in Your Browser
Step-by-step: load knowledgeC.db with its -wal and Biome SEGB streams into a free in-browser parser, set a time range, review sessions and export a timeline.
TL;DR. Collect knowledgeC.db with its -wal and the Biome streams folder, drop them (or a ZIP) on KnowledgeC Parser, check the Sources tab, read the Findings, set a time range, then work through Sessions, Timeline, Apps, Web and Biome. Export CSV, Timesketch CSV or JSON. Parsing runs in WebAssembly inside a Web Worker in your browser; the files are never uploaded.
This is the hands-on companion to the knowledgeC.db forensics guide. For the reasoning behind session analysis, read who was using the Mac. The examples use the built-in sample, which is synthetic and fictional: it was generated for this tool and does not come from a real case. Labels in the interface may change slightly over time; the steps stay the same.
Before you start
| You need | Why |
|---|---|
knowledgeC.db + -wal (+ -shm), system and user | Recent events are often only in the WAL |
The Biome streams folder, layout intact | The stream name, local / remote and tombstone come from the path |
The Users/<name>/ part of the path | The tool attributes files to that account |
| A current desktop browser | Parsing runs as WebAssembly in a Web Worker |
Step 1: Collect the files
The user database (~/Library/Application Support/Knowledge/knowledgeC.db) and Biome user streams are protected by TCC: the collecting process needs Full Disk Access. The system database (/private/var/db/CoreDuet/Knowledge/knowledgeC.db) is restricted by SIP; a disk image is usually the cleaner route. Copy the -wal and -shm files with each database, and hash everything.
Commands, UAC and Velociraptor options and their gaps are covered in knowledgeC.db and Biome: locations and acquisition and in the collection guide on the home page.
Step 2: Load the files
Open the tool home page and drop:
- individual files (
knowledgeC.db,knowledgeC.db-wal, SEGB files); - a folder, for example a copied
Library; - a ZIP of a collection.
To learn the interface first, click Try a sample. The workspace goes full screen; press Esc to leave it.
The sample is a fictional MacBook, FIN-MBP-03, user dana.whitlock: a system and a user knowledgeC.db, each with a -wal, and Biome files for App.InFocus (including an older tombstone file and a stream synced from an iPhone), App.WebUsage, Notification.Usage, Device.Metadata and App.MenuItem, in both SEGB v1 and v2.
Step 3: Check the Sources tab
Before reading any event, confirm what was parsed:
- Each knowledgeC.db paired with its
-wal. The tool reads the database as SQLite would after the WAL, and compares it with the main file alone. Rows that exist only in the WAL, and rows the WAL removed, are flagged. In the sample, every system row after 10:00 UTC on 2026-09-14 is WAL-only, and one old row is removed by the WAL. See knowledgeC WAL recovery. - Scope: system or user database, from the path.
- Biome files: stream name, SEGB version,
local,remote/<device UUID>ortombstone, record counts per state and CRC failures. - Problems: a file that starts with zeros (probably copied while locked), a truncated SEGB file, or a SEGB file whose stream name is unknown because the folder layout was lost. The
-shmfile is listed but not needed.
Step 4: Read the Findings
The Findings tab summarises what stands out. Treat each item as a lead: open it, check the underlying records, and decide whether it belongs in the report. The sample was built so that the leads worth following are an unlocked session during the lunch break, a first appearance of Terminal, deleted Biome web records and a short unlock in the middle of the night.
Step 5: Set the time range
A custom range keeps every tab focused on the same window:
| Control | Use |
|---|---|
| From / To | Set to the second, for example 2026-09-14 10:00:00 to 10:55:00 UTC |
| Presets | Quick ranges |
| Around this event | Centres the range on a selected event |
| Density strip | Shows where events cluster, to spot bursts and gaps |
The range is stored in the URL hash, so a colleague who opens the same link with the same files sees the same window, and it is written into export file names.
Step 6: Review sessions and the timeline
The Sessions tab answers "who was at the keyboard" as far as the data allows: unlocked intervals built from /device/isLocked, to read against backlight, power and app focus. In the sample, the session from 10:04:31 to 10:49:38 UTC (12:04 to 12:49 local) falls during Dana's lunch break. The session shows activity under her account, not who was typing; the method article explains the limits.
The Timeline tab merges knowledgeC and Biome events. Times are stored in UTC; for knowledgeC rows, ZSECONDSFROMGMT gives the local offset (+02:00 in the sample). Biome App.InFocus "in focus" and "out of focus" records are paired into intervals per app.
Step 7: Check apps, web and Biome details
- Apps: focus and usage per bundle ID. In the sample,
com.apple.Terminalappears only inside the incident session. - Web: URLs and domains from
/app/webUsage,/safari/historyandApp.WebUsage, includingfiles.exampleandtransfer.example. - Biome: one line per stream, store and origin (
local,remotewith the device UUID,tombstone) with the SEGB version, record counts, deleted records and CRC failures. Click a stream to list its records; each record's details show its state, CRC result and the decoded protobuf fields. Streams without a public field map, such asApp.MenuItem, are decoded without a schema and keep raw field numbers (SEGB format).
Synced records from the iPhone (remote/<UUID> in Biome, another ZDEVICEID in knowledgeC) are marked as such. Keep them out of the Mac's activity.
Step 8: Export the results
| Export | Contents |
|---|---|
| CSV: timeline | Events in the current range |
| CSV: apps | Per-app totals |
| CSV: sessions | Unlocked sessions |
| Timesketch CSV | Events in a format Timesketch can import |
| JSON | The parsed events, for scripts and other tools |
Keep the exports with the hashes of the source files. The range in each file name records which window the export covers.
Limits to keep in mind
- Field meanings for Biome payloads come from mac_apt and iLEAPP, not Apple. Undecoded fields stay raw.
- Records show activity under an account on a device, not identity.
- Retention is limited (about four weeks in knowledgeC, around 28 days for most Biome streams on iOS research); measure it per stream.
- For important records, cross-check with APOLLO, mac_apt or ccl-segb.
KnowledgeC Parser is an independent project, not affiliated with or endorsed by Apple.