Skip to content

Glossary

Mac absolute time

Mac absolute time counts seconds since 2001-01-01 00:00:00 UTC. Add 978307200 to get Unix time. knowledgeC.db and Biome both store dates this way.

Mac absolute time, also called Cocoa or Core Data time, counts seconds since 2001-01-01 00:00:00 UTC. knowledgeC.db stores ZSTARTDATE, ZENDDATE and ZCREATIONDATE this way, often with fractional seconds, and Biome SEGB records store their timestamps as Mac absolute doubles.

To convert to Unix time, add 978307200, the number of seconds between 1970-01-01 and 2001-01-01. Example: 694224000 + 978307200 = 1672531200, which is 2023-01-01 00:00:00 UTC. In SQLite:

SELECT datetime(ZSTARTDATE + 978307200, 'unixepoch') FROM ZOBJECT;

Stored values are UTC. Local time needs the offset in ZSECONDSFROMGMT. Biome file names are integers that mac_apt reads as Cocoa time in microseconds, so divide them by 1,000,000 before adding the offset. KnowledgeC Parser performs these conversions for you and shows UTC and local time side by side.