knowledgeC vs Biome: Where macOS Records App Usage
knowledgeC.db or Biome? How the two macOS activity stores differ, which Biome stream matches which knowledgeC stream, and what to expect on recent releases.
TL;DR. macOS keeps activity in two places. knowledgeC.db is a SQLite database with one row per event interval; Biome is a tree of stream folders holding SEGB files of protobuf records. On current releases app focus is expected in Biome's App.InFocus, not in knowledgeC's /app/inFocus, while states such as lock and backlight are still read from knowledgeC. Collect and examine both on every case, keep synced records from other devices apart, and treat an empty stream as "not recorded here", not as wiping.
If you are new to the database itself, start with the knowledgeC.db forensics guide.
Two stores, two designs
| knowledgeC | Biome | |
|---|---|---|
| Container | One SQLite database per scope (Core Data store) | One folder per stream, containing SEGB files |
| Record | A row in ZOBJECT with start and end | A record with a state, timestamps, a CRC and a protobuf payload |
| Stream names | Paths, for example /app/inFocus | Dotted names, for example App.InFocus |
| Time | Mac absolute time, UTC | Mac absolute time doubles in records |
| Local offset | ZSECONDSFROMGMT per row | Not among the publicly decoded fields |
| Other devices | Rows from other devices, told apart by ZSOURCE.ZDEVICEID | Separate remote/<device UUID>/ folders |
| Deletion | Rows removed; see the WAL for recent removals | Records flagged deleted (state 3), data can remain; expired files in tombstone/ |
| Decoding | Documented columns, stable enough for SQL | Payload fields from community reverse engineering |
The practical consequence is that the two stores need different habits. knowledgeC is queried with SQL on a copy, and the -wal must come with it. Biome needs a SEGB parser, then a per-stream protobuf decoder, and fields that no public decoder covers stay unknown. The byte layout is in the Biome SEGB file format.
Intervals versus transitions
A knowledgeC row is already an interval: ZSTARTDATE to ZENDDATE. A Biome App.InFocus record is a transition: an app moved into focus (status 1) or out of focus (status 0) at a given time. To get durations, a parser must pair each "in" record with the following "out" record for the same app.
KnowledgeC Parser does this pairing: an in-focus record ends at the next out-of-focus record for the same bundle ID, from the same user and the same origin, within 24 hours. An "in" with no matching "out" is shown without a duration rather than with a guessed one. Keep that in mind when a total focus time looks short: the last interval before a shutdown or a crash may be open.
Stream by stream
The table below pairs streams that record the same kind of activity. It is a functional comparison for examiners, not an Apple-documented migration map; field meanings on the Biome side come from mac_apt's BIOME plugin and iLEAPP.
| Activity | knowledgeC stream | Biome stream | Notes |
|---|---|---|---|
| App in focus | /app/inFocus | App.InFocus | Biome: status 1 in / 0 out, bundle ID, version strings |
| App in use | /app/usage | ScreenTime.AppUsage | Biome: status and bundle ID |
| Web usage per app | /app/webUsage | App.WebUsage | Biome: URL, domain, bundle ID |
| Safari | /safari/history | Safari.* | Biome: domain |
| Notifications | /notification/usage | Notification.Usage | Biome: app, title, subtitle |
| Lock, backlight, power | /device/isLocked, /display/isBacklit, /device/isPluggedIn | none in the decoded list | Read these from knowledgeC |
| Wi-Fi | none | Device.Wireless.WiFi | SSID and connect / disconnect status |
| Bluetooth | none | Device.Wireless.Bluetooth | Address, name, product ID, status |
| System Settings search | none | SystemSettings.SearchTerms | Term typed |
| Menu items selected | none | App.MenuItem | Documented by Unit 42 on macOS Tahoe 26; no public field map |
"None in the decoded list" means the public decoders do not cover such a stream, not that Biome cannot hold one. List the stream folders on your evidence rather than assuming names.
What to expect per macOS release
Public research gives only a few firm reference points, and they are summarised here without extrapolation.
| Release | What is known |
|---|---|
| macOS 10.15 Catalina | Biome appears as a distinct subsystem, according to a single source (Howard Oakley) |
| macOS 12 Monterey and later | Biome widely used |
| macOS 13 to 15 (Ventura, Sonoma, Sequoia) | No public per-release inventory of streams; on current releases app focus is expected in App.InFocus and knowledgeC can be sparse |
| macOS 26 Tahoe | New streams such as App.MenuItem (Unit 42) |
The SEGB container itself changed from v1 to v2. On iOS, v1 is reported for iOS 14 to 16 and v2 from iOS 17; the equivalent macOS boundary is not publicly documented, so tools detect the version from the file header. For any case where the exact release matters, compare against test data from the same build.
Common misreadings
- "knowledgeC is empty, so activity was wiped." A sparse
/app/inFocuson a recent Mac is expected. Check Biome, and check thatknowledgeC.db-walwas collected, before drawing any conclusion. - "The two sources disagree, so one is wrong." Different streams record different things with different triggers. A knowledgeC
/app/usageinterval and a BiomeApp.InFocusinterval for the same app will rarely match to the second. Explain the difference; do not pick the more convenient one. - "This record is from the Mac." Biome
remote/<device UUID>/folders and knowledgeC rows with anotherZDEVICEIDcome from other devices on the same Apple Account. An iPhone opening Maps at 10:12 is not the Mac opening Maps. - "Deleted means the user deleted it." Biome state 3 records and files in
tombstone/are normal lifecycle artifacts. Retention in both stores is measured in weeks (about four weeks for knowledgeC per Sarah Edwards, about 28 days for most Biome streams in iOS research). Measure the oldest record per stream on your evidence.
Working with both in one timeline
- Collect both stores with their companion files: the knowledgeC
-waland-shm, and Biome'srestricted/,public/,remote/andtombstone/folders. How to do that is in knowledgeC.db location and acquisition. - Convert everything to UTC first. knowledgeC gives you the device offset per row; for Biome, take the time zone from knowledgeC or other artifacts.
- Separate local from remote before sorting.
- Use knowledgeC lock and backlight intervals as the frame, and Biome focus records inside it.
In the synthetic FIN-MBP-03 sample, for example, the 10:04 to 10:49 UTC window shows the Mac unlocked (knowledgeC, /device/isLocked), Terminal, System Settings and Finder in focus (Biome App.InFocus), and App.MenuItem records naming "Full Disk Access". Maps and Messages records from Dana's iPhone sit in remote/ during the same minutes and must be excluded from the Mac's activity. KnowledgeC Parser merges both stores into one timeline and marks the origin of every row. What the combined timeline still cannot tell you is who was sitting in front of the Mac; that reasoning is covered in who was at the keyboard.