Skip to content

Glossary

App in focus (/app/inFocus, App.InFocus)

/app/inFocus (knowledgeC.db) and App.InFocus (Biome) record which app was frontmost on a Mac and when. What in focus shows, and what it cannot prove.

/app/inFocus is the knowledgeC.db stream that records which application was in focus: each ZOBJECT row carries the bundle ID in ZVALUESTRING, with a start and an end date. Its Biome counterpart is the App.InFocus stream. According to community reverse engineering in mac_apt and iLEAPP, its protobuf records hold a status in field 3 (1 = in focus, 0 = out of focus) and the bundle ID in field 6.

On recent macOS releases focus data is expected in Biome, so an empty or sparse /app/inFocus is normal and not a sign of wiping.

"In focus" means the app was the active, frontmost application. It does not prove that anyone was typing or even looking at the screen, and it does not identify a person. Pair it with /device/isLocked and /display/isBacklit, as described in who was at the keyboard and knowledgeC vs Biome.