Biome SEGB Streams: macOS App Focus and Activity
Biome stores macOS activity streams such as App.InFocus in SEGB files of protobuf records, the successor to many knowledgeC.db streams.
- Location
- ~/Library/Biome/streams/restricted/<Stream>/local/
- Proves
- Which apps were in focus, sites visited, devices and networks connected, with per-record times
- Timestamps
- Mac absolute time (Cocoa) doubles in SEGB records; file names are Cocoa time in microseconds
- Access
- Full Disk Access (user streams); system streams are SIP-restricted
- Retention
- Weeks for most streams (about 28 days, a figure from iOS research); expired files move to tombstone
- Collection
- UAC, mac_apt, Disk image
Tools
Compare all toolsWhat it is
Biome is Apple's newer framework for recording context and "pattern of life" events. It gradually took over many streams that used to live in knowledgeC.db, including application focus. Each stream is a folder of binary SEGB files, named after the SEGB magic value. Every SEGB record carries a state, one or two timestamps, a CRC and a payload that is usually a protocol buffer message specific to the stream.
Biome appeared as a distinct subsystem around macOS Catalina according to a single source (Howard Oakley), and it has been widely used since macOS 12 Monterey. It is active on all current releases, with new streams added over time (for example App.MenuItem, documented by Unit 42 on macOS Tahoe 26).
Where it lives
| Scope | Path | Protection |
|---|---|---|
| User streams | ~/Library/Biome/streams/restricted/<Stream>/local/ and ~/Library/Biome/streams/public/<Stream>/local/ | TCC-protected, needs Full Disk Access |
| Synced from other devices | .../<Stream>/remote/<device UUID>/ | Same as above |
| Expired files | .../<Stream>/local/tombstone/ | Same as above |
| User sync state | ~/Library/Biome/sync/ (SQLite database) | Same as above |
| System streams | /private/var/db/biome/streams/ | Owned by _biome; UAC documents collecting it live only with SIP disabled |
Stream folders also contain lock and metadata files. Stream names are dotted, for example App.InFocus; some sources show a _DKEvent. prefix on iOS. List the folders rather than assuming names.
What it proves
Streams that mac_apt's Biome plugin decodes on macOS:
| Stream | What it shows |
|---|---|
App.InFocus | App moved into or out of focus (status 1 / 0), product name and version |
App.WebUsage | URL, domain and the app bundle ID used |
Safari.* | Domains visited in Safari |
ScreenTime.AppUsage | App bundle ID with in or out of focus status |
Notification.Usage | App, title and subtitle of notifications |
Device.Wireless.WiFi | SSID with connect or disconnect status |
Device.Wireless.Bluetooth | Device address, product name and ID, connect or disconnect |
SystemSettings.SearchTerms | Terms typed in System Settings search |
Other streams exist, for example App.MenuItem (macOS Tahoe 26), which records menu items the user selected, as documented by Unit 42. mac_apt has no dedicated decoder for such streams and only gives them a generic schema-less protobuf decode.
Biome does not prove who was at the keyboard, and payload meanings come from community reverse engineering, not Apple documentation. Treat undecoded fields as unknown.
Key fields
SEGB record layer, as implemented in ccl-segb:
| Format | Header | Per-record fields |
|---|---|---|
| SEGB v1 | 56-byte header, SEGB magic in the last 4 bytes, end-of-data offset in the first 4 | length, state, timestamp1, timestamp2, CRC32, payload |
| SEGB v2 | 32-byte header starting with SEGB, entry count, creation time; a trailer of 16-byte entries (end offset, state, timestamp) at the end of the file indexes records | CRC32 over the payload, payload (state and timestamp come from the trailer) |
Record states: 1 written, 3 deleted, 4 empty or unused. Deleted records can still contain data. A CRC mismatch indicates a partially written or damaged record.
On iOS, SEGB v1 is documented for iOS 14 to 16 and v2 from iOS 17. The macOS boundary is not publicly documented; tools auto-detect by header.
Timestamps
- Record timestamps are Mac absolute time stored as doubles: seconds since 2001-01-01 UTC. Add
978307200for Unix time. - SEGB file names are integers that mac_apt interprets as Cocoa time in microseconds, which gives an approximate file creation time.
- Some payloads carry additional fields whose meaning is stream specific; decode per stream before treating any value as a time.
# File name 781234567000000 (microseconds) -> UTC
date -u -r $(( 781234567000000 / 1000000 + 978307200 ))
Retention
Research on iOS reports that most streams keep active records for about 28 days, with some (for example Device.Metadata and Location.Visit) kept for months. Expired SEGB files move to tombstone/, which mac_apt skips by default but is worth examining manually. Measure retention on your evidence from the oldest record per stream.
Collection
# Terminal needs Full Disk Access
ditto ~/Library/Biome case/Biome_user
find case/Biome_user/streams -maxdepth 2 -type d | sort
- UAC's
biomeartifact collects~/Library/Biome/streams/restricted/*/localfor each user and/private/var/db/biome(the latter only with SIP disabled, per UAC). Consider addingpublic/andremote/manually. - For the system store, prefer a full disk or Data volume image over disabling SIP.
- Do not modify SEGB files in place; hash before parsing.
Parsing
- mac_apt
BIOMEplugin reads user and system streams (restrictedandpublic) from an image or, in artifact-only mode, from astreamsfolder, and decodes the streams listed above:
python3 mac_apt_artifact_only.py -i case/Biome_user/streams -o out -c BIOME
- ccl-segb prints raw records from a single SEGB v1 or v2 file:
python3 ccl_segb_cli.py "case/Biome_user/streams/restricted/App.InFocus/local/<file>"
Payloads not covered by a parser can be decoded schema-less with a protobuf tool such as blackboxprotobuf (which mac_apt uses), then mapped manually. Some payload fields contain NSKeyedArchiver property lists.
KnowledgeC Parser decodes SEGB v1 and v2 files in the browser, with dedicated decoders for streams such as App.InFocus, App.WebUsage and ScreenTime.AppUsage and schema-less protobuf for the rest; nothing is uploaded.
Investigator tips
- Check both knowledgeC.db and Biome on every case: on current macOS, app focus data is expected in
App.InFocus, not in knowledgeC. See knowledgeC and Biome. - Separate
localfromremote/<device UUID>: remote files come from other devices on the same Apple Account and must not be attributed to the Mac under examination. - Look at deleted-state records and
tombstone/files; parsers often skip both. Device.Wireless.WiFiandDevice.Wireless.Bluetoothcomplement Wi-Fi and Bluetooth preference files with connect and disconnect times.ScreenTime.AppUsageandNotification.Usageoverlap with Screen Time and the notification database; disagreements between them are worth explaining.- Validate decoded fields against test data from the same macOS build before relying on them in a report.