Skip to content

knowledgeC.db Location and How to Collect Biome Streams

Where knowledgeC.db and Biome streams live on macOS, and how to collect them with Terminal, UAC, Velociraptor or a disk image without losing the WAL.

Published on 7 min read

TL;DR. The user knowledgeC.db is in ~/Library/Application Support/Knowledge/, the system one in /private/var/db/CoreDuet/Knowledge/, and user Biome streams in ~/Library/Biome/streams/. Grant Full Disk Access to Terminal or the collector, copy each database with its -wal and -shm, copy the whole Biome folder, hash everything, and never open the originals. UAC and Velociraptor can help but each has gaps; for the SIP-protected system stores, image the disk or Data volume instead of disabling SIP.

For what these stores contain, start with the knowledgeC.db forensics guide. Quick references for both artifacts are on the macOS forensics cheat sheets: knowledgeC.db and Biome SEGB.

What to collect

StorePathProtection
knowledgeC, system/private/var/db/CoreDuet/Knowledge/knowledgeC.db + -wal, -shmRoot, SIP-restricted
knowledgeC, user~/Library/Application Support/Knowledge/knowledgeC.db + -wal, -shmTCC: Full Disk Access
Biome, user streams~/Library/Biome/streams/restricted/<Stream>/local/ and ~/Library/Biome/streams/public/<Stream>/local/TCC: Full Disk Access
Biome, synced from other devices…/<Stream>/remote/<device UUID>/Same
Biome, expired files…/<Stream>/local/tombstone/Same
Biome, system streams/private/var/db/biome/streams/Owned by _biome, SIP-restricted

On iOS the user Biome store is /private/var/mobile/Library/Biome/; this article covers macOS.

The -wal line is not optional. knowledgeC runs in WAL mode, and recent events are often committed only in the WAL; why and how to use it is in recovering recent events from knowledgeC.db-wal. For Biome, collect remote/ and tombstone/ even if you do not plan to use them: remote records must be identified to be excluded, and tombstone files hold expired data that parsers often skip.

Access: TCC, Full Disk Access and SIP

Two protections apply, and they are different.

  • TCC protects the user copies. A process that has not been granted Full Disk Access is refused access to these folders, even when it runs as root. Grant it to Terminal (System Settings, Privacy & Security, Full Disk Access) or to your collector, then restart the app.
  • SIP protects the system stores. UAC documents that it only collects /private/var/db/CoreDuet/Knowledge/knowledgeC.db and /private/var/db/biome live when SIP is disabled. Disabling SIP means a reboot into recovery and a change to the evidence system, which is hard to justify. Prefer a full disk or Data volume image and extract the paths from it.

Option 1: a live copy with Terminal

With Terminal granted Full Disk Access and an existing destination folder on your collection drive:

cp -p ~/Library/Application\ Support/Knowledge/knowledgeC.db* <dest>/
ditto ~/Library/Biome <dest>/Biome_user
shasum -a 256 <dest>/knowledgeC.db*

The * picks up knowledgeC.db, knowledgeC.db-wal and knowledgeC.db-shm in one go; -p keeps modification times and permissions. ditto copies the Biome tree with its folder structure, which you need to tell local, remote and tombstone apart. Hash every file you copied, not only the database, and record the command, the time and the account used. Run this for each user of interest.

The copy is taken while CoreDuet may still be writing. That is acceptable for triage: copy the three knowledgeC files in one command, so the main file and its WAL are as close in time as possible.

Option 2: UAC

UAC has one artifact file for each store:

sudo ./uac -a ./artifacts/files/system/knowledgec.yaml -a ./artifacts/files/system/biome.yaml /tmp

The ir_triage and full profiles include both through files/system/*. Know the gaps before relying on them:

UAC artifactCollectsMisses
knowledgec.yamlknowledgeC.db for both pathsThe -wal and -shm files; the system copy unless SIP is disabled
biome.yaml~/Library/Biome/streams/restricted/*/local per user; /private/var/db/biome only with SIP disabledpublic/, remote/ and tombstone/ folders

So after a UAC run, add the WAL files and the missing Biome folders manually (Option 1), and give the UAC process Full Disk Access too.

Option 3: Velociraptor

Velociraptor has no built-in macOS triage target for knowledgeC or Biome. Use the generic file finder with uploads enabled:

velociraptor artifacts collect MacOS.Search.FileFinder --args 'SearchFilesGlob=/Users/*/Library/Application Support/Knowledge/knowledgeC.db*' --args Upload_File=Y --output knowledgec.zip
velociraptor artifacts collect MacOS.Search.FileFinder --args 'SearchFilesGlob=/Users/*/Library/Biome/streams/**' --args Upload_File=Y --output biome.zip

The glob ending in knowledgeC.db* brings the WAL and SHM files with it. The Velociraptor client also needs Full Disk Access; on a managed fleet, deploy it with an MDM privacy preferences (PPPC) profile before you need it. The exchange artifact MacOS.Applications.KnowledgeC parses rows in place, which is useful for hunting across endpoints but is not a substitute for collecting the files. See the Velociraptor documentation for running collections from the server.

Option 4: a disk or Data volume image

An image is the cleanest way to get the system stores without touching SIP, and it preserves everything else you may need later. From the mounted image, or with a tool such as mac_apt that exports files from an image, extract:

  • /private/var/db/CoreDuet/Knowledge/ (whole folder, so the WAL files come along);
  • /private/var/db/biome/;
  • for each user, Library/Application Support/Knowledge/ and Library/Biome/.

Mount read-only and extract to your case folder before parsing anything.

Tools that do not collect them

Aftermath (Jamf) does not collect knowledgeC or Biome. If it was your first responder tool, go back for these files with one of the options above.

Checking the collection

Before leaving the site, check that each knowledgeC copy has its -wal next to it, and that the Biome copy has a streams folder with stream subfolders. A quick parse of the Biome copy with mac_apt in artifact-only mode confirms the files are readable:

python3 mac_apt_artifact_only.py -i case/Biome_user/streams -o out -c BIOME

Or drop the whole case folder into KnowledgeC Parser: it pairs each database with its WAL, warns when a database in WAL mode arrives without one, and shows the oldest and newest record per stream.

Gotchas

ProblemCauseFix
Access refused on copyTerminal or the collector lacks Full Disk AccessGrant it, restart the app
No recent events-wal not collected (UAC default)Copy knowledgeC.db*
Database changed after collectionOriginal opened in place, WAL checkpointedNever open originals; work on copies
Records attributed to the Mac that came from a phoneremote/ flattened or ignoredKeep the folder structure
System stores missingSIP enabled during a live collectionExtract from a disk or Data volume image
Old data missingtombstone/ not collectedCopy the whole Biome folder

Integrity

Hash files as collected, record tools and commands, and work on copies. Never open the original knowledgeC.db with sqlite3 or a GUI browser: opening a WAL database can checkpoint it, which writes WAL pages into the main file and can reset the WAL you wanted to examine. The same care applies to your own copies: keep a pristine hashed set and parse a second copy.

Next step

Load the collection into KnowledgeC Parser, or read its collection guide for the same steps in short form.

FAQ

Where is knowledgeC.db stored on macOS?

The system copy is /private/var/db/CoreDuet/Knowledge/knowledgeC.db and the per-user copy is ~/Library/Application Support/Knowledge/knowledgeC.db. Both are in WAL mode, so collect knowledgeC.db-wal and knowledgeC.db-shm alongside each database.

Do I need to disable SIP to collect knowledgeC and Biome?

Not for the user copies: Full Disk Access for Terminal or the collector is enough. The system knowledgeC.db and /private/var/db/biome are only collected live with SIP disabled, according to UAC. Prefer a full disk or Data volume image and extract them from it instead of disabling SIP.

Does UAC collect the knowledgeC WAL file?

No. UAC's knowledgec artifact collects only knowledgeC.db, not the -wal and -shm files, and its biome artifact only takes restricted/*/local. Copy the WAL files and the other Biome folders separately.

Which Biome folders should I collect?

The whole ~/Library/Biome folder for each user if you can. At minimum take streams/restricted and streams/public, including each stream's local, remote/<device UUID> and local/tombstone subfolders, plus /private/var/db/biome/streams for the system store.

Related articles

What knowledgeC.db records on macOS, where it lives, how ZOBJECT and its streams work, how to convert its timestamps, and what the data does not prove.
knowledgeC.db or Biome? How the two macOS activity stores differ, which Biome stream matches which knowledgeC stream, and what to expect on recent releases.
Step-by-step: load knowledgeC.db with its -wal and Biome SEGB streams into a free in-browser parser, set a time range, review sessions and export a timeline.