Skip to content

knowledgeC vs Biome: Where macOS Records App Usage

knowledgeC.db or Biome? How the two macOS activity stores differ, which Biome stream matches which knowledgeC stream, and what to expect on recent releases.

Published on 6 min read

TL;DR. macOS keeps activity in two places. knowledgeC.db is a SQLite database with one row per event interval; Biome is a tree of stream folders holding SEGB files of protobuf records. On current releases app focus is expected in Biome's App.InFocus, not in knowledgeC's /app/inFocus, while states such as lock and backlight are still read from knowledgeC. Collect and examine both on every case, keep synced records from other devices apart, and treat an empty stream as "not recorded here", not as wiping.

If you are new to the database itself, start with the knowledgeC.db forensics guide.

Two stores, two designs

knowledgeCBiome
ContainerOne SQLite database per scope (Core Data store)One folder per stream, containing SEGB files
RecordA row in ZOBJECT with start and endA record with a state, timestamps, a CRC and a protobuf payload
Stream namesPaths, for example /app/inFocusDotted names, for example App.InFocus
TimeMac absolute time, UTCMac absolute time doubles in records
Local offsetZSECONDSFROMGMT per rowNot among the publicly decoded fields
Other devicesRows from other devices, told apart by ZSOURCE.ZDEVICEIDSeparate remote/<device UUID>/ folders
DeletionRows removed; see the WAL for recent removalsRecords flagged deleted (state 3), data can remain; expired files in tombstone/
DecodingDocumented columns, stable enough for SQLPayload fields from community reverse engineering

The practical consequence is that the two stores need different habits. knowledgeC is queried with SQL on a copy, and the -wal must come with it. Biome needs a SEGB parser, then a per-stream protobuf decoder, and fields that no public decoder covers stay unknown. The byte layout is in the Biome SEGB file format.

Intervals versus transitions

A knowledgeC row is already an interval: ZSTARTDATE to ZENDDATE. A Biome App.InFocus record is a transition: an app moved into focus (status 1) or out of focus (status 0) at a given time. To get durations, a parser must pair each "in" record with the following "out" record for the same app.

KnowledgeC Parser does this pairing: an in-focus record ends at the next out-of-focus record for the same bundle ID, from the same user and the same origin, within 24 hours. An "in" with no matching "out" is shown without a duration rather than with a guessed one. Keep that in mind when a total focus time looks short: the last interval before a shutdown or a crash may be open.

Stream by stream

The table below pairs streams that record the same kind of activity. It is a functional comparison for examiners, not an Apple-documented migration map; field meanings on the Biome side come from mac_apt's BIOME plugin and iLEAPP.

ActivityknowledgeC streamBiome streamNotes
App in focus/app/inFocusApp.InFocusBiome: status 1 in / 0 out, bundle ID, version strings
App in use/app/usageScreenTime.AppUsageBiome: status and bundle ID
Web usage per app/app/webUsageApp.WebUsageBiome: URL, domain, bundle ID
Safari/safari/historySafari.*Biome: domain
Notifications/notification/usageNotification.UsageBiome: app, title, subtitle
Lock, backlight, power/device/isLocked, /display/isBacklit, /device/isPluggedInnone in the decoded listRead these from knowledgeC
Wi-FinoneDevice.Wireless.WiFiSSID and connect / disconnect status
BluetoothnoneDevice.Wireless.BluetoothAddress, name, product ID, status
System Settings searchnoneSystemSettings.SearchTermsTerm typed
Menu items selectednoneApp.MenuItemDocumented by Unit 42 on macOS Tahoe 26; no public field map

"None in the decoded list" means the public decoders do not cover such a stream, not that Biome cannot hold one. List the stream folders on your evidence rather than assuming names.

What to expect per macOS release

Public research gives only a few firm reference points, and they are summarised here without extrapolation.

ReleaseWhat is known
macOS 10.15 CatalinaBiome appears as a distinct subsystem, according to a single source (Howard Oakley)
macOS 12 Monterey and laterBiome widely used
macOS 13 to 15 (Ventura, Sonoma, Sequoia)No public per-release inventory of streams; on current releases app focus is expected in App.InFocus and knowledgeC can be sparse
macOS 26 TahoeNew streams such as App.MenuItem (Unit 42)

The SEGB container itself changed from v1 to v2. On iOS, v1 is reported for iOS 14 to 16 and v2 from iOS 17; the equivalent macOS boundary is not publicly documented, so tools detect the version from the file header. For any case where the exact release matters, compare against test data from the same build.

Common misreadings

  • "knowledgeC is empty, so activity was wiped." A sparse /app/inFocus on a recent Mac is expected. Check Biome, and check that knowledgeC.db-wal was collected, before drawing any conclusion.
  • "The two sources disagree, so one is wrong." Different streams record different things with different triggers. A knowledgeC /app/usage interval and a Biome App.InFocus interval for the same app will rarely match to the second. Explain the difference; do not pick the more convenient one.
  • "This record is from the Mac." Biome remote/<device UUID>/ folders and knowledgeC rows with another ZDEVICEID come from other devices on the same Apple Account. An iPhone opening Maps at 10:12 is not the Mac opening Maps.
  • "Deleted means the user deleted it." Biome state 3 records and files in tombstone/ are normal lifecycle artifacts. Retention in both stores is measured in weeks (about four weeks for knowledgeC per Sarah Edwards, about 28 days for most Biome streams in iOS research). Measure the oldest record per stream on your evidence.

Working with both in one timeline

  1. Collect both stores with their companion files: the knowledgeC -wal and -shm, and Biome's restricted/, public/, remote/ and tombstone/ folders. How to do that is in knowledgeC.db location and acquisition.
  2. Convert everything to UTC first. knowledgeC gives you the device offset per row; for Biome, take the time zone from knowledgeC or other artifacts.
  3. Separate local from remote before sorting.
  4. Use knowledgeC lock and backlight intervals as the frame, and Biome focus records inside it.

In the synthetic FIN-MBP-03 sample, for example, the 10:04 to 10:49 UTC window shows the Mac unlocked (knowledgeC, /device/isLocked), Terminal, System Settings and Finder in focus (Biome App.InFocus), and App.MenuItem records naming "Full Disk Access". Maps and Messages records from Dana's iPhone sit in remote/ during the same minutes and must be excluded from the Mac's activity. KnowledgeC Parser merges both stores into one timeline and marks the origin of every row. What the combined timeline still cannot tell you is who was sitting in front of the Mac; that reasoning is covered in who was at the keyboard.

Related articles

What knowledgeC.db records on macOS, where it lives, how ZOBJECT and its streams work, how to convert its timestamps, and what the data does not prove.
Step-by-step: load knowledgeC.db with its -wal and Biome SEGB streams into a free in-browser parser, set a time range, review sessions and export a timeline.
Where knowledgeC.db and Biome streams live on macOS, and how to collect them with Terminal, UAC, Velociraptor or a disk image without losing the WAL.