Skip to content

Series

knowledgeC and Biome fundamentals

4 posts in this series. Read them in order or jump to any one.

  1. knowledgeC.db Forensics: The Complete macOS Guide

    What knowledgeC.db records on macOS, where it lives, how ZOBJECT and its streams work, how to convert its timestamps, and what the data does not prove.

  2. knowledgeC vs Biome: Where macOS Records App Usage

    knowledgeC.db or Biome? How the two macOS activity stores differ, which Biome stream matches which knowledgeC stream, and what to expect on recent releases.

  3. knowledgeC.db Location and How to Collect Biome Streams

    Where knowledgeC.db and Biome streams live on macOS, and how to collect them with Terminal, UAC, Velociraptor or a disk image without losing the WAL.

  4. Biome SEGB File Format: v1 and v2 Byte-Level Reference

    Byte-level reference for Biome SEGB v1 and v2: headers, trailers, record states, CRC32, alignment, file-name times and protobuf field numbers per stream.

All posts in this series

What knowledgeC.db records on macOS, where it lives, how ZOBJECT and its streams work, how to convert its timestamps, and what the data does not prove.
knowledgeC.db or Biome? How the two macOS activity stores differ, which Biome stream matches which knowledgeC stream, and what to expect on recent releases.
Where knowledgeC.db and Biome streams live on macOS, and how to collect them with Terminal, UAC, Velociraptor or a disk image without losing the WAL.
Byte-level reference for Biome SEGB v1 and v2: headers, trailers, record states, CRC32, alignment, file-name times and protobuf field numbers per stream.