Skip to content

Glossary

ZSTRUCTUREDMETADATA

ZSTRUCTUREDMETADATA is the knowledgeC.db table of stream-specific values such as web domains, page titles and bundle IDs. Its columns vary by release.

ZSTRUCTUREDMETADATA is the knowledgeC.db table that holds extra, stream-specific values that do not fit the generic columns of ZOBJECT. An event points to it through ZOBJECT.ZSTRUCTUREDMETADATA, which matches ZSTRUCTUREDMETADATA.Z_PK.

Column names encode the metadata key they hold. Examples: Z_DKDIGITALHEALTHMETADATAKEY__WEBDOMAIN and Z_DKDIGITALHEALTHMETADATAKEY__WEBPAGEURL for web usage, Z_DKSAFARIHISTORYMETADATAKEY__TITLE for the page title of a /safari/history entry, and Z_DKNOTIFICATIONUSAGEMETADATAKEY__BUNDLEID for the app behind a /notification/usage event.

The columns drift between macOS releases, so a query written for one version can fail or return empty values on another. List the columns with .schema ZSTRUCTUREDMETADATA before querying. Worked queries are in the knowledgeC.db forensics guide, and ZOBJECT describes the parent table.