Glossary
Plain-language definitions of the knowledgeC, Biome and SQLite terms used across the blog and the tool.
- App in focus (/app/inFocus, App.InFocus)
- /app/inFocus (knowledgeC.db) and App.InFocus (Biome) record which app was frontmost on a Mac and when. What in focus shows, and what it cannot prove.
- Biome tombstone
- The Biome tombstone folder holds SEGB files expired from a stream's local directory. Many parsers skip it, yet it can extend the activity timeline.
- Biome
- Biome is Apple's newer event framework that stores macOS activity streams such as App.InFocus in SEGB files, taking over many knowledgeC.db streams.
- Core Data
- Core Data is Apple's persistence framework. It explains why knowledgeC.db tables and columns carry a Z prefix, as in ZOBJECT, Z_PK, Z_ENT and Z_OPT.
- Full Disk Access
- Full Disk Access is the macOS TCC permission a collector needs to read the user knowledgeC.db and the Biome streams on a running Mac, and what it leaves out.
- knowledgeC.db
- knowledgeC.db is the CoreDuet SQLite database where macOS records pattern-of-life events such as app focus, screen state and lock state as streams.
- Mac absolute time
- Mac absolute time counts seconds since 2001-01-01 00:00:00 UTC. Add 978307200 to get Unix time. knowledgeC.db and Biome both store dates this way.
- Protocol Buffers (protobuf)
- Protocol Buffers (protobuf) is the binary format of most Biome record payloads. Wire format basics, and why schema-less decoding stays ambiguous.
- SEGB
- SEGB is the binary container format of Biome stream files: v1 and v2 headers, record states (written, deleted, empty) and a CRC32 over each payload.
- SQLite WAL (write-ahead log)
- SQLite write-ahead logging keeps recent changes in a -wal file until a checkpoint. For knowledgeC.db, the newest events often exist only there.
- System Integrity Protection (SIP)
- System Integrity Protection (SIP) blocks live access to the system knowledgeC.db and /private/var/db/biome, even as root. Why an image beats disabling it.
- ZOBJECT
- ZOBJECT is the knowledgeC.db event table: one row per event, with stream name, value, start and end dates, UTC offset, source and metadata links.
- ZSECONDSFROMGMT
- ZSECONDSFROMGMT is the knowledgeC.db column with the device UTC offset in seconds. Local time = UTC + offset; changes hint at travel or time zone edits.
- ZSTRUCTUREDMETADATA
- ZSTRUCTUREDMETADATA is the knowledgeC.db table of stream-specific values such as web domains, page titles and bundle IDs. Its columns vary by release.