knowledgeC.db Location and How to Collect Biome Streams
Where knowledgeC.db and Biome streams live on macOS, and how to collect them with Terminal, UAC, Velociraptor or a disk image without losing the WAL.
TL;DR. The user knowledgeC.db is in ~/Library/Application Support/Knowledge/, the system one in /private/var/db/CoreDuet/Knowledge/, and user Biome streams in ~/Library/Biome/streams/. Grant Full Disk Access to Terminal or the collector, copy each database with its -wal and -shm, copy the whole Biome folder, hash everything, and never open the originals. UAC and Velociraptor can help but each has gaps; for the SIP-protected system stores, image the disk or Data volume instead of disabling SIP.
For what these stores contain, start with the knowledgeC.db forensics guide. Quick references for both artifacts are on the macOS forensics cheat sheets: knowledgeC.db and Biome SEGB.
What to collect
| Store | Path | Protection |
|---|---|---|
| knowledgeC, system | /private/var/db/CoreDuet/Knowledge/knowledgeC.db + -wal, -shm | Root, SIP-restricted |
| knowledgeC, user | ~/Library/Application Support/Knowledge/knowledgeC.db + -wal, -shm | TCC: Full Disk Access |
| Biome, user streams | ~/Library/Biome/streams/restricted/<Stream>/local/ and ~/Library/Biome/streams/public/<Stream>/local/ | TCC: Full Disk Access |
| Biome, synced from other devices | …/<Stream>/remote/<device UUID>/ | Same |
| Biome, expired files | …/<Stream>/local/tombstone/ | Same |
| Biome, system streams | /private/var/db/biome/streams/ | Owned by _biome, SIP-restricted |
On iOS the user Biome store is /private/var/mobile/Library/Biome/; this article covers macOS.
The -wal line is not optional. knowledgeC runs in WAL mode, and recent events are often committed only in the WAL; why and how to use it is in recovering recent events from knowledgeC.db-wal. For Biome, collect remote/ and tombstone/ even if you do not plan to use them: remote records must be identified to be excluded, and tombstone files hold expired data that parsers often skip.
Access: TCC, Full Disk Access and SIP
Two protections apply, and they are different.
- TCC protects the user copies. A process that has not been granted Full Disk Access is refused access to these folders, even when it runs as root. Grant it to Terminal (System Settings, Privacy & Security, Full Disk Access) or to your collector, then restart the app.
- SIP protects the system stores. UAC documents that it only collects
/private/var/db/CoreDuet/Knowledge/knowledgeC.dband/private/var/db/biomelive when SIP is disabled. Disabling SIP means a reboot into recovery and a change to the evidence system, which is hard to justify. Prefer a full disk or Data volume image and extract the paths from it.
Option 1: a live copy with Terminal
With Terminal granted Full Disk Access and an existing destination folder on your collection drive:
cp -p ~/Library/Application\ Support/Knowledge/knowledgeC.db* <dest>/
ditto ~/Library/Biome <dest>/Biome_user
shasum -a 256 <dest>/knowledgeC.db*
The * picks up knowledgeC.db, knowledgeC.db-wal and knowledgeC.db-shm in one go; -p keeps modification times and permissions. ditto copies the Biome tree with its folder structure, which you need to tell local, remote and tombstone apart. Hash every file you copied, not only the database, and record the command, the time and the account used. Run this for each user of interest.
The copy is taken while CoreDuet may still be writing. That is acceptable for triage: copy the three knowledgeC files in one command, so the main file and its WAL are as close in time as possible.
Option 2: UAC
UAC has one artifact file for each store:
sudo ./uac -a ./artifacts/files/system/knowledgec.yaml -a ./artifacts/files/system/biome.yaml /tmp
The ir_triage and full profiles include both through files/system/*. Know the gaps before relying on them:
| UAC artifact | Collects | Misses |
|---|---|---|
knowledgec.yaml | knowledgeC.db for both paths | The -wal and -shm files; the system copy unless SIP is disabled |
biome.yaml | ~/Library/Biome/streams/restricted/*/local per user; /private/var/db/biome only with SIP disabled | public/, remote/ and tombstone/ folders |
So after a UAC run, add the WAL files and the missing Biome folders manually (Option 1), and give the UAC process Full Disk Access too.
Option 3: Velociraptor
Velociraptor has no built-in macOS triage target for knowledgeC or Biome. Use the generic file finder with uploads enabled:
velociraptor artifacts collect MacOS.Search.FileFinder --args 'SearchFilesGlob=/Users/*/Library/Application Support/Knowledge/knowledgeC.db*' --args Upload_File=Y --output knowledgec.zip
velociraptor artifacts collect MacOS.Search.FileFinder --args 'SearchFilesGlob=/Users/*/Library/Biome/streams/**' --args Upload_File=Y --output biome.zip
The glob ending in knowledgeC.db* brings the WAL and SHM files with it. The Velociraptor client also needs Full Disk Access; on a managed fleet, deploy it with an MDM privacy preferences (PPPC) profile before you need it. The exchange artifact MacOS.Applications.KnowledgeC parses rows in place, which is useful for hunting across endpoints but is not a substitute for collecting the files. See the Velociraptor documentation for running collections from the server.
Option 4: a disk or Data volume image
An image is the cleanest way to get the system stores without touching SIP, and it preserves everything else you may need later. From the mounted image, or with a tool such as mac_apt that exports files from an image, extract:
/private/var/db/CoreDuet/Knowledge/(whole folder, so the WAL files come along);/private/var/db/biome/;- for each user,
Library/Application Support/Knowledge/andLibrary/Biome/.
Mount read-only and extract to your case folder before parsing anything.
Tools that do not collect them
Aftermath (Jamf) does not collect knowledgeC or Biome. If it was your first responder tool, go back for these files with one of the options above.
Checking the collection
Before leaving the site, check that each knowledgeC copy has its -wal next to it, and that the Biome copy has a streams folder with stream subfolders. A quick parse of the Biome copy with mac_apt in artifact-only mode confirms the files are readable:
python3 mac_apt_artifact_only.py -i case/Biome_user/streams -o out -c BIOME
Or drop the whole case folder into KnowledgeC Parser: it pairs each database with its WAL, warns when a database in WAL mode arrives without one, and shows the oldest and newest record per stream.
Gotchas
| Problem | Cause | Fix |
|---|---|---|
| Access refused on copy | Terminal or the collector lacks Full Disk Access | Grant it, restart the app |
| No recent events | -wal not collected (UAC default) | Copy knowledgeC.db* |
| Database changed after collection | Original opened in place, WAL checkpointed | Never open originals; work on copies |
| Records attributed to the Mac that came from a phone | remote/ flattened or ignored | Keep the folder structure |
| System stores missing | SIP enabled during a live collection | Extract from a disk or Data volume image |
| Old data missing | tombstone/ not collected | Copy the whole Biome folder |
Integrity
Hash files as collected, record tools and commands, and work on copies. Never open the original knowledgeC.db with sqlite3 or a GUI browser: opening a WAL database can checkpoint it, which writes WAL pages into the main file and can reset the WAL you wanted to examine. The same care applies to your own copies: keep a pristine hashed set and parse a second copy.
Next step
Load the collection into KnowledgeC Parser, or read its collection guide for the same steps in short form.
FAQ
Where is knowledgeC.db stored on macOS?
The system copy is /private/var/db/CoreDuet/Knowledge/knowledgeC.db and the per-user copy is ~/Library/Application Support/Knowledge/knowledgeC.db. Both are in WAL mode, so collect knowledgeC.db-wal and knowledgeC.db-shm alongside each database.
Do I need to disable SIP to collect knowledgeC and Biome?
Not for the user copies: Full Disk Access for Terminal or the collector is enough. The system knowledgeC.db and /private/var/db/biome are only collected live with SIP disabled, according to UAC. Prefer a full disk or Data volume image and extract them from it instead of disabling SIP.
Does UAC collect the knowledgeC WAL file?
No. UAC's knowledgec artifact collects only knowledgeC.db, not the -wal and -shm files, and its biome artifact only takes restricted/*/local. Copy the WAL files and the other Biome folders separately.
Which Biome folders should I collect?
The whole ~/Library/Biome folder for each user if you can. At minimum take streams/restricted and streams/public, including each stream's local, remote/<device UUID> and local/tombstone subfolders, plus /private/var/db/biome/streams for the system store.