Skip to content

User activityExecutionNetwork

Biome SEGB Streams: macOS App Focus and Activity

Biome stores macOS activity streams such as App.InFocus in SEGB files of protobuf records, the successor to many knowledgeC.db streams.

Location
~/Library/Biome/streams/restricted/<Stream>/local/
Proves
Which apps were in focus, sites visited, devices and networks connected, with per-record times
Timestamps
Mac absolute time (Cocoa) doubles in SEGB records; file names are Cocoa time in microseconds
Access
Full Disk Access (user streams); system streams are SIP-restricted
Retention
Weeks for most streams (about 28 days, a figure from iOS research); expired files move to tombstone
Collection
UAC, mac_apt, Disk image

What it is

Biome is Apple's newer framework for recording context and "pattern of life" events. It gradually took over many streams that used to live in knowledgeC.db, including application focus. Each stream is a folder of binary SEGB files, named after the SEGB magic value. Every SEGB record carries a state, one or two timestamps, a CRC and a payload that is usually a protocol buffer message specific to the stream.

Biome appeared as a distinct subsystem around macOS Catalina according to a single source (Howard Oakley), and it has been widely used since macOS 12 Monterey. It is active on all current releases, with new streams added over time (for example App.MenuItem, documented by Unit 42 on macOS Tahoe 26).

Where it lives

ScopePathProtection
User streams~/Library/Biome/streams/restricted/<Stream>/local/ and ~/Library/Biome/streams/public/<Stream>/local/TCC-protected, needs Full Disk Access
Synced from other devices.../<Stream>/remote/<device UUID>/Same as above
Expired files.../<Stream>/local/tombstone/Same as above
User sync state~/Library/Biome/sync/ (SQLite database)Same as above
System streams/private/var/db/biome/streams/Owned by _biome; UAC documents collecting it live only with SIP disabled

Stream folders also contain lock and metadata files. Stream names are dotted, for example App.InFocus; some sources show a _DKEvent. prefix on iOS. List the folders rather than assuming names.

What it proves

Streams that mac_apt's Biome plugin decodes on macOS:

StreamWhat it shows
App.InFocusApp moved into or out of focus (status 1 / 0), product name and version
App.WebUsageURL, domain and the app bundle ID used
Safari.*Domains visited in Safari
ScreenTime.AppUsageApp bundle ID with in or out of focus status
Notification.UsageApp, title and subtitle of notifications
Device.Wireless.WiFiSSID with connect or disconnect status
Device.Wireless.BluetoothDevice address, product name and ID, connect or disconnect
SystemSettings.SearchTermsTerms typed in System Settings search

Other streams exist, for example App.MenuItem (macOS Tahoe 26), which records menu items the user selected, as documented by Unit 42. mac_apt has no dedicated decoder for such streams and only gives them a generic schema-less protobuf decode.

Biome does not prove who was at the keyboard, and payload meanings come from community reverse engineering, not Apple documentation. Treat undecoded fields as unknown.

Key fields

SEGB record layer, as implemented in ccl-segb:

FormatHeaderPer-record fields
SEGB v156-byte header, SEGB magic in the last 4 bytes, end-of-data offset in the first 4length, state, timestamp1, timestamp2, CRC32, payload
SEGB v232-byte header starting with SEGB, entry count, creation time; a trailer of 16-byte entries (end offset, state, timestamp) at the end of the file indexes recordsCRC32 over the payload, payload (state and timestamp come from the trailer)

Record states: 1 written, 3 deleted, 4 empty or unused. Deleted records can still contain data. A CRC mismatch indicates a partially written or damaged record.

On iOS, SEGB v1 is documented for iOS 14 to 16 and v2 from iOS 17. The macOS boundary is not publicly documented; tools auto-detect by header.

Timestamps

  • Record timestamps are Mac absolute time stored as doubles: seconds since 2001-01-01 UTC. Add 978307200 for Unix time.
  • SEGB file names are integers that mac_apt interprets as Cocoa time in microseconds, which gives an approximate file creation time.
  • Some payloads carry additional fields whose meaning is stream specific; decode per stream before treating any value as a time.
# File name 781234567000000 (microseconds) -> UTC
date -u -r $(( 781234567000000 / 1000000 + 978307200 ))

Retention

Research on iOS reports that most streams keep active records for about 28 days, with some (for example Device.Metadata and Location.Visit) kept for months. Expired SEGB files move to tombstone/, which mac_apt skips by default but is worth examining manually. Measure retention on your evidence from the oldest record per stream.

Collection

# Terminal needs Full Disk Access
ditto ~/Library/Biome case/Biome_user
find case/Biome_user/streams -maxdepth 2 -type d | sort
  • UAC's biome artifact collects ~/Library/Biome/streams/restricted/*/local for each user and /private/var/db/biome (the latter only with SIP disabled, per UAC). Consider adding public/ and remote/ manually.
  • For the system store, prefer a full disk or Data volume image over disabling SIP.
  • Do not modify SEGB files in place; hash before parsing.

Parsing

  • mac_apt BIOME plugin reads user and system streams (restricted and public) from an image or, in artifact-only mode, from a streams folder, and decodes the streams listed above:
python3 mac_apt_artifact_only.py -i case/Biome_user/streams -o out -c BIOME
  • ccl-segb prints raw records from a single SEGB v1 or v2 file:
python3 ccl_segb_cli.py "case/Biome_user/streams/restricted/App.InFocus/local/<file>"

Payloads not covered by a parser can be decoded schema-less with a protobuf tool such as blackboxprotobuf (which mac_apt uses), then mapped manually. Some payload fields contain NSKeyedArchiver property lists.

KnowledgeC Parser decodes SEGB v1 and v2 files in the browser, with dedicated decoders for streams such as App.InFocus, App.WebUsage and ScreenTime.AppUsage and schema-less protobuf for the rest; nothing is uploaded.

Investigator tips

  • Check both knowledgeC.db and Biome on every case: on current macOS, app focus data is expected in App.InFocus, not in knowledgeC. See knowledgeC and Biome.
  • Separate local from remote/<device UUID>: remote files come from other devices on the same Apple Account and must not be attributed to the Mac under examination.
  • Look at deleted-state records and tombstone/ files; parsers often skip both.
  • Device.Wireless.WiFi and Device.Wireless.Bluetooth complement Wi-Fi and Bluetooth preference files with connect and disconnect times.
  • ScreenTime.AppUsage and Notification.Usage overlap with Screen Time and the notification database; disagreements between them are worth explaining.
  • Validate decoded fields against test data from the same macOS build before relying on them in a report.

See also