Skip to content

Glossary

Plain-language definitions of the knowledgeC, Biome and SQLite terms used across the blog and the tool.

App in focus (/app/inFocus, App.InFocus)
/app/inFocus (knowledgeC.db) and App.InFocus (Biome) record which app was frontmost on a Mac and when. What in focus shows, and what it cannot prove.
Biome tombstone
The Biome tombstone folder holds SEGB files expired from a stream's local directory. Many parsers skip it, yet it can extend the activity timeline.
Biome
Biome is Apple's newer event framework that stores macOS activity streams such as App.InFocus in SEGB files, taking over many knowledgeC.db streams.
Core Data
Core Data is Apple's persistence framework. It explains why knowledgeC.db tables and columns carry a Z prefix, as in ZOBJECT, Z_PK, Z_ENT and Z_OPT.
Full Disk Access
Full Disk Access is the macOS TCC permission a collector needs to read the user knowledgeC.db and the Biome streams on a running Mac, and what it leaves out.
knowledgeC.db
knowledgeC.db is the CoreDuet SQLite database where macOS records pattern-of-life events such as app focus, screen state and lock state as streams.
Mac absolute time
Mac absolute time counts seconds since 2001-01-01 00:00:00 UTC. Add 978307200 to get Unix time. knowledgeC.db and Biome both store dates this way.
Protocol Buffers (protobuf)
Protocol Buffers (protobuf) is the binary format of most Biome record payloads. Wire format basics, and why schema-less decoding stays ambiguous.
SEGB
SEGB is the binary container format of Biome stream files: v1 and v2 headers, record states (written, deleted, empty) and a CRC32 over each payload.
SQLite WAL (write-ahead log)
SQLite write-ahead logging keeps recent changes in a -wal file until a checkpoint. For knowledgeC.db, the newest events often exist only there.
System Integrity Protection (SIP)
System Integrity Protection (SIP) blocks live access to the system knowledgeC.db and /private/var/db/biome, even as root. Why an image beats disabling it.
ZOBJECT
ZOBJECT is the knowledgeC.db event table: one row per event, with stream name, value, start and end dates, UTC offset, source and metadata links.
ZSECONDSFROMGMT
ZSECONDSFROMGMT is the knowledgeC.db column with the device UTC offset in seconds. Local time = UTC + offset; changes hint at travel or time zone edits.
ZSTRUCTUREDMETADATA
ZSTRUCTUREDMETADATA is the knowledgeC.db table of stream-specific values such as web domains, page titles and bundle IDs. Its columns vary by release.