Skip to content

Glossary

Core Data

Core Data is Apple's persistence framework. It explains why knowledgeC.db tables and columns carry a Z prefix, as in ZOBJECT, Z_PK, Z_ENT and Z_OPT.

Core Data is Apple's framework for storing an application's object model, frequently in a SQLite file. When it writes to SQLite, it generates the tables and columns from the model and prefixes their names with Z. That is why knowledgeC.db contains tables such as ZOBJECT, ZSOURCE and ZSTRUCTUREDMETADATA, and columns such as ZSTREAMNAME or ZSTARTDATE.

Core Data also adds bookkeeping columns. Z_PK is the row's primary key, which other tables reference: ZOBJECT.ZSOURCE points to ZSOURCE.Z_PK. Z_ENT identifies the entity (the object type) a row belongs to, and Z_OPT is a counter Core Data maintains for its own change tracking. Neither carries event data.

For the examiner, the practical point is that the schema follows Apple's model, so columns can appear, disappear or change between macOS releases. Run .schema before trusting a canned query. See ZOBJECT and the knowledgeC.db forensics guide.