Glossary
ZOBJECT
ZOBJECT is the knowledgeC.db event table: one row per event, with stream name, value, start and end dates, UTC offset, source and metadata links.
ZOBJECT is the main table of knowledgeC.db, with one row per event. Key columns:
ZSTREAMNAME: the stream, such as/app/usageor/device/isLocked.ZVALUESTRING: usually a bundle ID or a URL.ZVALUEINTEGERandZVALUEDOUBLE: numeric values, for example 1 = locked on/device/isLocked.ZSTARTDATE,ZENDDATE,ZCREATIONDATE: Mac absolute time in UTC.ZSECONDSFROMGMT,ZSTARTDAYOFWEEK(1 = Sunday) andZUUID.
Two columns are links. ZSOURCE points to the ZSOURCE table, which describes the producer (ZBUNDLEID, ZDEVICEID), and ZSTRUCTUREDMETADATA points to the ZSTRUCTUREDMETADATA table. Grouping by ZSOURCE.ZDEVICEID separates rows synced from other devices from those of the Mac itself, and ZENDDATE minus ZSTARTDATE gives a duration. See the knowledgeC.db forensics guide.