From 9a52d9f0b43706a88c2e32e48385fd8cca249d41 Mon Sep 17 00:00:00 2001 From: Brigs Date: Sat, 26 Sep 2026 23:53:56 -0400 Subject: [PATCH] Say why each flagged Source File column stays The new source-column finding flagged Chromium Autofill Entries, Chromium Saved Logins, Portable Devices, Contacts and Biome App In Focus. In each the other column does not separate the files on every input, and the notes now say so: two copies of one profile or database under Users/ and System/Volumes/Data/Users/, a hive under Windows.old, or several files in one Biome folder. The Chromium sentence replaces one that gave a reason Profile and User already cover. Notes only. Co-Authored-By: Claude Opus 5.5 --- scripts/artifacts/chromiumAutofill.py | 6 +- scripts/artifacts/chromiumBookmarks.py | 6 +- scripts/artifacts/chromiumCookies.py | 6 +- scripts/artifacts/chromiumExtensions.py | 6 +- scripts/artifacts/chromiumHistory.py | 24 ++-- scripts/artifacts/chromiumLoginData.py | 6 +- scripts/artifacts/chromiumTopSites.py | 12 +- scripts/artifacts/macosBiome.py | 131 ++++++++++++++++---- scripts/artifacts/macosContacts.py | 7 +- scripts/artifacts/windowsPortableDevices.py | 6 +- 10 files changed, 162 insertions(+), 48 deletions(-) diff --git a/scripts/artifacts/chromiumAutofill.py b/scripts/artifacts/chromiumAutofill.py index 9ad0179..8c333ec 100644 --- a/scripts/artifacts/chromiumAutofill.py +++ b/scripts/artifacts/chromiumAutofill.py @@ -15,8 +15,10 @@ "read; none of the tested " "databases lacked them. Browser, Profile and User come from the path: the browser from " "the user data folder, the profile from the folder inside it, and the user from the home " - "folder that holds it; Source File names the file each row came from, so rows from two " - "profiles or two users stay apart. A profile under User Data/Snapshots// is " + "folder that holds it; Source File names the file each row came from, since " + "Browser, Profile and User do not separate two copies of one profile, which a " + "logical extraction can hold under Users/ and System/Volumes/Data/Users/. A " + "profile under User Data/Snapshots// is " "reported with that path as its Profile, so a snapshot copy is not merged with the live " "profile; no registered image carries one, and that branch was exercised on a constructed " "tree only. Created and Last Used are date_created and date_last_used, seconds since " diff --git a/scripts/artifacts/chromiumBookmarks.py b/scripts/artifacts/chromiumBookmarks.py index 8ec7029..7b985be 100644 --- a/scripts/artifacts/chromiumBookmarks.py +++ b/scripts/artifacts/chromiumBookmarks.py @@ -27,8 +27,10 @@ "https://github.com/chromium/chromium/blob/abb5172872b726072a64dfabaf45894c6ecf7369/base/time/time.h#L5-L7); " "Date Last Used is blank where the file has no value or 0. Browser, Profile and User come " "from the path: the browser from the user data folder, the profile from the folder inside " - "it, and the user from the home folder that holds it; Source File names the file each row " - "came from, so rows from two profiles or two users stay apart. A profile under User " + "it, and the user from the home folder that holds it; Source File names the file " + "each row came from, since Browser, Profile and User do not separate two copies " + "of one profile, which a logical extraction can hold under Users/ and " + "System/Volumes/Data/Users/. A profile under User " "Data/Snapshots// is reported with that path as its Profile, so a snapshot copy " "is not merged with the live profile; no registered image carries one, and that branch " "was exercised on a constructed tree only. No registered image produced a row: the one " diff --git a/scripts/artifacts/chromiumCookies.py b/scripts/artifacts/chromiumCookies.py index 0358fb2..4e4e646 100644 --- a/scripts/artifacts/chromiumCookies.py +++ b/scripts/artifacts/chromiumCookies.py @@ -19,8 +19,10 @@ "and every cookie row of the tested images had an empty value and a non-empty " "encrypted_value: 840 on pc_mus_001_win11 and 2953 on lonewolf_win10. Browser, Profile " "and User come from the path: the browser from the user data folder, the profile from the " - "folder inside it, and the user from the home folder that holds it; Source File names the " - "file each row came from, so rows from two profiles or two users stay apart. A profile " + "folder inside it, and the user from the home folder that holds it; Source File " + "names the file each row came from, since Browser, Profile and User do not " + "separate two copies of one profile, which a logical extraction can hold under " + "Users/ and System/Volumes/Data/Users/. A profile " "under User Data/Snapshots// is reported with that path as its Profile, so a " "snapshot copy is not merged with the live profile; no registered image carries one, and " "that branch was exercised on a constructed tree only. Created, Expires, Last Access Time " diff --git a/scripts/artifacts/chromiumExtensions.py b/scripts/artifacts/chromiumExtensions.py index 52b1ea7..e528ead 100644 --- a/scripts/artifacts/chromiumExtensions.py +++ b/scripts/artifacts/chromiumExtensions.py @@ -25,8 +25,10 @@ "pc_mus_001_win11 and 10 on lonewolf_win10, and 20 entries with no location in the " "Microsoft Edge Secure Preferences of pc_mus_001_win11. Browser, Profile and User come " "from the path: the browser from the user data folder, the profile from the folder inside " - "it, and the user from the home folder that holds it; Source File names the file each row " - "came from, so rows from two profiles or two users stay apart. A profile under User " + "it, and the user from the home folder that holds it; Source File names the file " + "each row came from, since Browser, Profile and User do not separate two copies " + "of one profile, which a logical extraction can hold under Users/ and " + "System/Volumes/Data/Users/. A profile under User " "Data/Snapshots// is reported with that path as its Profile, so a snapshot copy " "is not merged with the live profile; no registered image carries one, and that branch " "was exercised on a constructed tree only. Name and Version are the name and version of " diff --git a/scripts/artifacts/chromiumHistory.py b/scripts/artifacts/chromiumHistory.py index eb970e7..f22bf8f 100644 --- a/scripts/artifacts/chromiumHistory.py +++ b/scripts/artifacts/chromiumHistory.py @@ -13,8 +13,10 @@ "joins each visit to its urls row for the URL and title; one row per visits row. Every " "visit on the tested images had a urls row. Browser, Profile and User come from the path: " "the browser from the user data folder, the profile from the folder inside it, and the " - "user from the home folder that holds it; Source File names the file each row came from, " - "so rows from two profiles or two users stay apart. A profile under User " + "user from the home folder that holds it; Source File names the file each row " + "came from, since Browser, Profile and User do not separate two copies of one " + "profile, which a logical extraction can hold under Users/ and " + "System/Volumes/Data/Users/. A profile under User " "Data/Snapshots// is reported with that path as its Profile, so a snapshot copy " "is not merged with the live profile; no registered image carries one, and that branch " "was exercised on a constructed tree only. Visit Time is visits.visit_time, microseconds " @@ -142,8 +144,10 @@ "row per urls row. On the tested images every urls row had at least one visits row, so " "this artifact names no URL that Chromium Web Visits does not. Browser, Profile and User " "come from the path: the browser from the user data folder, the profile from the folder " - "inside it, and the user from the home folder that holds it; Source File names the file " - "each row came from, so rows from two profiles or two users stay apart. A profile under " + "inside it, and the user from the home folder that holds it; Source File names " + "the file each row came from, since Browser, Profile and User do not separate two" + " copies of one profile, which a logical extraction can hold under Users/ and " + "System/Volumes/Data/Users/. A profile under " "User Data/Snapshots// is reported with that path as its Profile, so a snapshot " "copy is not merged with the live profile; no registered image carries one, and that " "branch was exercised on a constructed tree only. Last Visit Time is " @@ -247,8 +251,10 @@ "notes": "Reads the downloads table of each History database in a Chromium-based browser profile, " "with the URL chain from downloads_url_chains; one row per downloads row. Browser, " "Profile and User come from the path: the browser from the user data folder, the profile " - "from the folder inside it, and the user from the home folder that holds it; Source File " - "names the file each row came from, so rows from two profiles or two users stay apart. A " + "from the folder inside it, and the user from the home folder that holds it; " + "Source File names the file each row came from, since Browser, Profile and User " + "do not separate two copies of one profile, which a logical extraction can hold " + "under Users/ and System/Volumes/Data/Users/. A " "profile under User Data/Snapshots// is reported with that path as its Profile, " "so a snapshot copy is not merged with the live profile; no registered image carries one, " "and that branch was exercised on a constructed tree only. Start Time, End Time and Last " @@ -395,8 +401,10 @@ "Data of each profile whose History was read, where that Web Data's keywords " "table was read. Browser, Profile and User come from the path: the " "browser from the user data folder, the profile from the folder inside it, and the user " - "from the home folder that holds it; Source File names the file each row came from, so " - "rows from two profiles or two users stay apart. A profile under User " + "from the home folder that holds it; Source File names the file each row came " + "from, since Browser, Profile and User do not separate two copies of one profile," + " which a logical extraction can hold under Users/ and " + "System/Volumes/Data/Users/. A profile under User " "Data/Snapshots// is reported with that path as its Profile, so a snapshot copy " "is not merged with the live profile; no registered image carries one, and that branch " "was exercised on a constructed tree only. A database left with a rollback journal that " diff --git a/scripts/artifacts/chromiumLoginData.py b/scripts/artifacts/chromiumLoginData.py index 7edf397..4b30c14 100644 --- a/scripts/artifacts/chromiumLoginData.py +++ b/scripts/artifacts/chromiumLoginData.py @@ -16,8 +16,10 @@ "one row per logins row, and Store names the file. The password_value column is not " "queried. Browser, Profile and User come from the path: the browser from the user data " "folder, the profile from the folder inside it, and the user from the home folder that " - "holds it; Source File names the file each row came from, so rows from two profiles or " - "two users stay apart. A profile under User Data/Snapshots// is reported with " + "holds it; Source File names the file each row came from, since Browser, Profile " + "and User do not separate two copies of one profile, which a logical extraction " + "can hold under Users/ and System/Volumes/Data/Users/. A profile under User " + "Data/Snapshots// is reported with " "that path as its Profile, so a snapshot copy is not merged with the live profile; no " "registered image carries one, and that branch was exercised on a constructed tree only. " "Created, Last Used and Password Modified are date_created, date_last_used and " diff --git a/scripts/artifacts/chromiumTopSites.py b/scripts/artifacts/chromiumTopSites.py index 8fa5e96..1222c75 100644 --- a/scripts/artifacts/chromiumTopSites.py +++ b/scripts/artifacts/chromiumTopSites.py @@ -14,8 +14,10 @@ "current releases, or the thumbnails table the Chrome 65 release kept instead; one row " "per table row. Browser, Profile and User come from the path: the browser from the user " "data folder, the profile from the folder inside it, and the user from the home folder " - "that holds it; Source File names the file each row came from, so rows from two profiles " - "or two users stay apart. A profile under User Data/Snapshots// is reported with " + "that holds it; Source File names the file each row came from, since Browser, " + "Profile and User do not separate two copies of one profile, which a logical " + "extraction can hold under Users/ and System/Volumes/Data/Users/. A profile under" + " User Data/Snapshots// is reported with " "that path as its Profile, so a snapshot copy is not merged with the live profile; no " "registered image carries one, and that branch was exercised on a constructed tree only. " "Rank is url_rank as stored. The current source describes it as a 0-based index where the " @@ -110,8 +112,10 @@ "notes": "Reads the omni_box_shortcuts table of each Chromium-based browser profile's Shortcuts " "database; one row per table row. Browser, Profile and User come from the path: the " "browser from the user data folder, the profile from the folder inside it, and the user " - "from the home folder that holds it; Source File names the file each row came from, so " - "rows from two profiles or two users stay apart. A profile under User " + "from the home folder that holds it; Source File names the file each row came " + "from, since Browser, Profile and User do not separate two copies of one profile," + " which a logical extraction can hold under Users/ and " + "System/Volumes/Data/Users/. A profile under User " "Data/Snapshots// is reported with that path as its Profile, so a snapshot copy " "is not merged with the live profile; no registered image carries one, and that branch " "was exercised on a constructed tree only. Last Access Time is last_access_time, " diff --git a/scripts/artifacts/macosBiome.py b/scripts/artifacts/macosBiome.py index 6df68b7..d38bf6c 100644 --- a/scripts/artifacts/macosBiome.py +++ b/scripts/artifacts/macosBiome.py @@ -35,8 +35,13 @@ "https://github.com/cclgroupltd/ccl-segb/blob/23c3f7d3d969a79627b738ba0a2486c31d675753/ccl_segb/ccl_segb2.py#L133-L142, " "and ccl_segb/ccl_segb_common.py, " "https://github.com/cclgroupltd/ccl-segb/blob/23c3f7d3d969a79627b738ba0a2486c31d675753/ccl_segb/ccl_segb_common.py#L5-L21);" - " every file of the stream on the tested extraction is SEGB version 2. User is the folder after Users in the source path, or root under private/var/root, and is blank when the input is one user's home folder whose path names no user. Sync Origin is Local for the local folder, or Remote with " - "the name of the folder under remote the record came from. Record Offset is " + " every file of the stream on the tested extraction is SEGB version 2. User is " + "the folder after Users in the source path, or root under private/var/root, and " + "is blank when the input is one user's home folder whose path names no user. Sync" + " Origin is Local for the local folder, or Remote with the name of the folder " + "under remote the record came from. Sync Origin does not separate two files of " + "one folder, and every file in a folder is read, so Source File names the file " + "each row came from and the file its Record Offset counts from. Record Offset is " "where the record begins in its file: in a version 2 file that is the record's " "8-byte header, which starts with its stored CRC, and the record's data begins " "8 bytes later. When a logical extraction holds the stream under " @@ -105,8 +110,13 @@ "https://github.com/cclgroupltd/ccl-segb/blob/23c3f7d3d969a79627b738ba0a2486c31d675753/ccl_segb/ccl_segb2.py#L133-L142, " "and ccl_segb/ccl_segb_common.py, " "https://github.com/cclgroupltd/ccl-segb/blob/23c3f7d3d969a79627b738ba0a2486c31d675753/ccl_segb/ccl_segb_common.py#L5-L21);" - " every file of the stream on the tested extraction is SEGB version 2. User is the folder after Users in the source path, or root under private/var/root, and is blank when the input is one user's home folder whose path names no user. Sync Origin is Local for the local folder, or Remote with " - "the name of the folder under remote the record came from. Record Offset is " + " every file of the stream on the tested extraction is SEGB version 2. User is " + "the folder after Users in the source path, or root under private/var/root, and " + "is blank when the input is one user's home folder whose path names no user. Sync" + " Origin is Local for the local folder, or Remote with the name of the folder " + "under remote the record came from. Sync Origin does not separate two files of " + "one folder, and every file in a folder is read, so Source File names the file " + "each row came from and the file its Record Offset counts from. Record Offset is " "where the record begins in its file: in a version 2 file that is the record's " "8-byte header, which starts with its stored CRC, and the record's data begins " "8 bytes later. When a logical extraction holds the stream under " @@ -161,8 +171,13 @@ "https://github.com/cclgroupltd/ccl-segb/blob/23c3f7d3d969a79627b738ba0a2486c31d675753/ccl_segb/ccl_segb2.py#L133-L142, " "and ccl_segb/ccl_segb_common.py, " "https://github.com/cclgroupltd/ccl-segb/blob/23c3f7d3d969a79627b738ba0a2486c31d675753/ccl_segb/ccl_segb_common.py#L5-L21);" - " every file of the stream on the tested extraction is SEGB version 2. User is the folder after Users in the source path, or root under private/var/root, and is blank when the input is one user's home folder whose path names no user. Sync Origin is Local for the local folder, or Remote with " - "the name of the folder under remote the record came from. Record Offset is " + " every file of the stream on the tested extraction is SEGB version 2. User is " + "the folder after Users in the source path, or root under private/var/root, and " + "is blank when the input is one user's home folder whose path names no user. Sync" + " Origin is Local for the local folder, or Remote with the name of the folder " + "under remote the record came from. Sync Origin does not separate two files of " + "one folder, and every file in a folder is read, so Source File names the file " + "each row came from and the file its Record Offset counts from. Record Offset is " "where the record begins in its file: in a version 2 file that is the record's " "8-byte header, which starts with its stored CRC, and the record's data begins " "8 bytes later. When a logical extraction holds the stream under " @@ -216,8 +231,13 @@ "https://github.com/cclgroupltd/ccl-segb/blob/23c3f7d3d969a79627b738ba0a2486c31d675753/ccl_segb/ccl_segb2.py#L133-L142, " "and ccl_segb/ccl_segb_common.py, " "https://github.com/cclgroupltd/ccl-segb/blob/23c3f7d3d969a79627b738ba0a2486c31d675753/ccl_segb/ccl_segb_common.py#L5-L21);" - " every file of the stream on the tested extraction is SEGB version 2. User is the folder after Users in the source path, or root under private/var/root, and is blank when the input is one user's home folder whose path names no user. Sync Origin is Local for the local folder, or Remote with " - "the name of the folder under remote the record came from. Record Offset is " + " every file of the stream on the tested extraction is SEGB version 2. User is " + "the folder after Users in the source path, or root under private/var/root, and " + "is blank when the input is one user's home folder whose path names no user. Sync" + " Origin is Local for the local folder, or Remote with the name of the folder " + "under remote the record came from. Sync Origin does not separate two files of " + "one folder, and every file in a folder is read, so Source File names the file " + "each row came from and the file its Record Offset counts from. Record Offset is " "where the record begins in its file: in a version 2 file that is the record's " "8-byte header, which starts with its stored CRC, and the record's data begins " "8 bytes later. When a logical extraction holds the stream under " @@ -274,8 +294,13 @@ "https://github.com/cclgroupltd/ccl-segb/blob/23c3f7d3d969a79627b738ba0a2486c31d675753/ccl_segb/ccl_segb2.py#L133-L142, " "and ccl_segb/ccl_segb_common.py, " "https://github.com/cclgroupltd/ccl-segb/blob/23c3f7d3d969a79627b738ba0a2486c31d675753/ccl_segb/ccl_segb_common.py#L5-L21);" - " every file of the stream on the tested extraction is SEGB version 2. User is the folder after Users in the source path, or root under private/var/root, and is blank when the input is one user's home folder whose path names no user. Sync Origin is Local for the local folder, or Remote with " - "the name of the folder under remote the record came from. Record Offset is " + " every file of the stream on the tested extraction is SEGB version 2. User is " + "the folder after Users in the source path, or root under private/var/root, and " + "is blank when the input is one user's home folder whose path names no user. Sync" + " Origin is Local for the local folder, or Remote with the name of the folder " + "under remote the record came from. Sync Origin does not separate two files of " + "one folder, and every file in a folder is read, so Source File names the file " + "each row came from and the file its Record Offset counts from. Record Offset is " "where the record begins in its file: in a version 2 file that is the record's " "8-byte header, which starts with its stored CRC, and the record's data begins " "8 bytes later. When a logical extraction holds the stream under " @@ -331,8 +356,13 @@ "https://github.com/cclgroupltd/ccl-segb/blob/23c3f7d3d969a79627b738ba0a2486c31d675753/ccl_segb/ccl_segb2.py#L133-L142, " "and ccl_segb/ccl_segb_common.py, " "https://github.com/cclgroupltd/ccl-segb/blob/23c3f7d3d969a79627b738ba0a2486c31d675753/ccl_segb/ccl_segb_common.py#L5-L21);" - " every file of the stream on the tested extraction is SEGB version 2. User is the folder after Users in the source path, or root under private/var/root, and is blank when the input is one user's home folder whose path names no user. Sync Origin is Local for the local folder, or Remote with " - "the name of the folder under remote the record came from. Record Offset is " + " every file of the stream on the tested extraction is SEGB version 2. User is " + "the folder after Users in the source path, or root under private/var/root, and " + "is blank when the input is one user's home folder whose path names no user. Sync" + " Origin is Local for the local folder, or Remote with the name of the folder " + "under remote the record came from. Sync Origin does not separate two files of " + "one folder, and every file in a folder is read, so Source File names the file " + "each row came from and the file its Record Offset counts from. Record Offset is " "where the record begins in its file: in a version 2 file that is the record's " "8-byte header, which starts with its stored CRC, and the record's data begins " "8 bytes later. When a logical extraction holds the stream under " @@ -366,7 +396,12 @@ "last_update_date": "2026-09-26", "requirements": "none", "category": "Biome (macOS)", - "notes": "Reads the Siri.Remembers.InteractionHistory Biome stream. Each file in the stream's local folder, and in each folder under its remote folder, other than one whose name begins with a dot, is read as a SEGB file with the vendored ccl_segb package, one row per record the file marks as written whose data ccl_segb can still read, and each such record is read as one protobuf message whose fields are taken by number without a schema; a record that does not read as one is counted in the run log and not reported. Records the file does not mark as written are not reported; those ccl_segb returns are counted in the run log, and it returns none of the entries a version 2 file marks as empty. Files under a tombstone folder are not read. Record Time (UTC) is the time the SEGB file stores with each record, which ccl_segb reads from a version 2 file as seconds since 00:00:00 on 1 January 2001 and DLEAPP reports as UTC (Reference: CCL Solutions Group, ccl-segb, ccl_segb/ccl_segb2.py, https://github.com/cclgroupltd/ccl-segb/blob/23c3f7d3d969a79627b738ba0a2486c31d675753/ccl_segb/ccl_segb2.py#L133-L142, and ccl_segb/ccl_segb_common.py, https://github.com/cclgroupltd/ccl-segb/blob/23c3f7d3d969a79627b738ba0a2486c31d675753/ccl_segb/ccl_segb_common.py#L5-L21); every file of the stream on the tested extraction is SEGB version 2. User is the folder after Users in the source path, or root under private/var/root, and is blank when the input is one user's home folder whose path names no user. Sync Origin is Local for the local folder, or Remote with the name of the folder under remote the record came from. Record Offset is where the record begins in its file: in a version 2 file that is the record's 8-byte header, which starts with its stored CRC, and the record's data begins 8 bytes later. When a logical extraction holds the stream under Users/ and under System/Volumes/Data/Users/, a record with the same offset, time and bytes in both is reported once, and the run log counts the repeats. On dleapp_macos_bigsur no Biome stream folder exists. Each written record holds one field 1 submessage. Interaction Time (UTC) is that submessage's field 8, eight bytes read as a little-endian double of seconds since 1 January 1970 UTC; Bundle ID, Intent Class (as stored), GUID (as stored) and Interaction GUID (as stored) are its fields 4, 2, 1 and 13, as iLEAPP's biomeSiriRemembersInteractionHistory module reads them (Reference: iLEAPP, scripts/artifacts/biomeSiriRemembersInteractionHistory.py, https://github.com/abrignoni/iLEAPP/blob/8d6a44d946a2c79cecf196c2599e21e2d42ba2e2/scripts/artifacts/biomeSiriRemembersInteractionHistory.py#L139-L149). What each field records beyond the field name is not established, and the submessage's other fields are not reported. On the public MacBook Pro logical extraction (macOS 15.4, not a registered corpus key) the stream gives 129 rows, all from one user's local folder, so User and Sync Origin each held one value there; Bundle ID held one value, com.apple.news, on all 129 rows; Interaction Time fell in 2025 on the rows checked. The Device.Wireless.Bluetooth and Siri.Remembers.CallHistory streams were also examined and held no written records on that extraction or on the extraction this artifact was built against, so no artifact is added for them here.", + "notes": "Reads the Siri.Remembers.InteractionHistory Biome stream. Each file in the stream's local folder, and in each folder under its remote folder, other than one whose name begins with a dot, is read as a SEGB file with the vendored ccl_segb package, one row per record the file marks as written whose data ccl_segb can still read, and each such record is read as one protobuf message whose fields are taken by number without a schema; a record that does not read as one is counted in the run log and not reported. Records the file does not mark as written are not reported; those ccl_segb returns are counted in the run log, and it returns none of the entries a version 2 file marks as empty. Files under a tombstone folder are not read. Record Time (UTC) is the time the SEGB file stores with each record, which ccl_segb reads from a version 2 file as seconds since 00:00:00 on 1 January 2001 and DLEAPP reports as UTC (Reference: CCL Solutions Group, ccl-segb, ccl_segb/ccl_segb2.py, https://github.com/cclgroupltd/ccl-segb/blob/23c3f7d3d969a79627b738ba0a2486c31d675753/ccl_segb/ccl_segb2.py#L133-L142, and ccl_segb/ccl_segb_common.py, https://github.com/cclgroupltd/ccl-segb/blob/23c3f7d3d969a79627b738ba0a2486c31d675753/ccl_segb/ccl_segb_common.py#L5-L21); every file of the stream on the tested extraction is SEGB version 2. User is the folder after Users in the source path, or root under private/var/root, and is blank when the input is one user's home folder whose path names no user. " + "Sync Origin is Local for the local folder, or Remote with the name of the folder" + " under remote the record came from. Sync Origin does not separate two files of " + "one folder, and every file in a folder is read, so Source File names the file " + "each row came from and the file its Record Offset counts from." + " Record Offset is where the record begins in its file: in a version 2 file that is the record's 8-byte header, which starts with its stored CRC, and the record's data begins 8 bytes later. When a logical extraction holds the stream under Users/ and under System/Volumes/Data/Users/, a record with the same offset, time and bytes in both is reported once, and the run log counts the repeats. On dleapp_macos_bigsur no Biome stream folder exists. Each written record holds one field 1 submessage. Interaction Time (UTC) is that submessage's field 8, eight bytes read as a little-endian double of seconds since 1 January 1970 UTC; Bundle ID, Intent Class (as stored), GUID (as stored) and Interaction GUID (as stored) are its fields 4, 2, 1 and 13, as iLEAPP's biomeSiriRemembersInteractionHistory module reads them (Reference: iLEAPP, scripts/artifacts/biomeSiriRemembersInteractionHistory.py, https://github.com/abrignoni/iLEAPP/blob/8d6a44d946a2c79cecf196c2599e21e2d42ba2e2/scripts/artifacts/biomeSiriRemembersInteractionHistory.py#L139-L149). What each field records beyond the field name is not established, and the submessage's other fields are not reported. On the public MacBook Pro logical extraction (macOS 15.4, not a registered corpus key) the stream gives 129 rows, all from one user's local folder, so User and Sync Origin each held one value there; Bundle ID held one value, com.apple.news, on all 129 rows; Interaction Time fell in 2025 on the rows checked. The Device.Wireless.Bluetooth and Siri.Remembers.CallHistory streams were also examined and held no written records on that extraction or on the extraction this artifact was built against, so no artifact is added for them here.", "sample_data": { "dleapp_macos_bigsur": "macOS Big Sur (Josh Hickman public test image, thisisdfir) | 0 rows (no member matches the declared paths)", }, @@ -382,7 +417,12 @@ "last_update_date": "2026-09-26", "requirements": "none", "category": "Biome (macOS)", - "notes": "Reads the Siri.Remembers.MessageHistory Biome stream. Each file in the stream's local folder, and in each folder under its remote folder, other than one whose name begins with a dot, is read as a SEGB file with the vendored ccl_segb package, one row per record the file marks as written whose data ccl_segb can still read, and each such record is read as one protobuf message whose fields are taken by number without a schema; a record that does not read as one is counted in the run log and not reported. Records the file does not mark as written are not reported; those ccl_segb returns are counted in the run log, and it returns none of the entries a version 2 file marks as empty. Files under a tombstone folder are not read. Record Time (UTC) is the time the SEGB file stores with each record, which ccl_segb reads from a version 2 file as seconds since 00:00:00 on 1 January 2001 and DLEAPP reports as UTC (Reference: CCL Solutions Group, ccl-segb, ccl_segb/ccl_segb2.py, https://github.com/cclgroupltd/ccl-segb/blob/23c3f7d3d969a79627b738ba0a2486c31d675753/ccl_segb/ccl_segb2.py#L133-L142, and ccl_segb/ccl_segb_common.py, https://github.com/cclgroupltd/ccl-segb/blob/23c3f7d3d969a79627b738ba0a2486c31d675753/ccl_segb/ccl_segb_common.py#L5-L21); every file of the stream on the tested extraction is SEGB version 2. User is the folder after Users in the source path, or root under private/var/root, and is blank when the input is one user's home folder whose path names no user. Sync Origin is Local for the local folder, or Remote with the name of the folder under remote the record came from. Record Offset is where the record begins in its file: in a version 2 file that is the record's 8-byte header, which starts with its stored CRC, and the record's data begins 8 bytes later. When a logical extraction holds the stream under Users/ and under System/Volumes/Data/Users/, a record with the same offset, time and bytes in both is reported once, and the run log counts the repeats. On dleapp_macos_bigsur no Biome stream folder exists. Each written record holds one field 1 submessage and, at the top level, repeated field 2 items. Message Time (UTC) is the submessage's field 8, eight bytes read as a little-endian double of seconds since 1 January 1970 UTC; Direction (as stored), Bundle ID, Intent Class (as stored), Chat ID (as stored) and Message GUID (as stored) are its fields 6, 4, 2, 12 and 13, as iLEAPP's biomeSiriRemembersMessageHistory module reads them (Reference: iLEAPP, scripts/artifacts/biomeSiriRemembersMessageHistory.py, https://github.com/abrignoni/iLEAPP/blob/8d6a44d946a2c79cecf196c2599e21e2d42ba2e2/scripts/artifacts/biomeSiriRemembersMessageHistory.py#L148-L154). Participants (as stored) joins each top-level field 2 item as its field 1 name and the field 1 text of its field 2 entity, which that module reads as the parameter names and values (for example sender and recipients); what a value denotes is not established. On the public MacBook Pro logical extraction (macOS 15.4, not a registered corpus key) the stream gives 4 rows from one user's local folder, so User and Sync Origin each held one value there, and on those 4 rows Direction (1), Bundle ID (com.apple.MobileSMS), Intent Class (INSendMessageIntent) and Chat ID each held one value; Message Time fell in 2025 on the rows checked.", + "notes": "Reads the Siri.Remembers.MessageHistory Biome stream. Each file in the stream's local folder, and in each folder under its remote folder, other than one whose name begins with a dot, is read as a SEGB file with the vendored ccl_segb package, one row per record the file marks as written whose data ccl_segb can still read, and each such record is read as one protobuf message whose fields are taken by number without a schema; a record that does not read as one is counted in the run log and not reported. Records the file does not mark as written are not reported; those ccl_segb returns are counted in the run log, and it returns none of the entries a version 2 file marks as empty. Files under a tombstone folder are not read. Record Time (UTC) is the time the SEGB file stores with each record, which ccl_segb reads from a version 2 file as seconds since 00:00:00 on 1 January 2001 and DLEAPP reports as UTC (Reference: CCL Solutions Group, ccl-segb, ccl_segb/ccl_segb2.py, https://github.com/cclgroupltd/ccl-segb/blob/23c3f7d3d969a79627b738ba0a2486c31d675753/ccl_segb/ccl_segb2.py#L133-L142, and ccl_segb/ccl_segb_common.py, https://github.com/cclgroupltd/ccl-segb/blob/23c3f7d3d969a79627b738ba0a2486c31d675753/ccl_segb/ccl_segb_common.py#L5-L21); every file of the stream on the tested extraction is SEGB version 2. User is the folder after Users in the source path, or root under private/var/root, and is blank when the input is one user's home folder whose path names no user. " + "Sync Origin is Local for the local folder, or Remote with the name of the folder" + " under remote the record came from. Sync Origin does not separate two files of " + "one folder, and every file in a folder is read, so Source File names the file " + "each row came from and the file its Record Offset counts from." + " Record Offset is where the record begins in its file: in a version 2 file that is the record's 8-byte header, which starts with its stored CRC, and the record's data begins 8 bytes later. When a logical extraction holds the stream under Users/ and under System/Volumes/Data/Users/, a record with the same offset, time and bytes in both is reported once, and the run log counts the repeats. On dleapp_macos_bigsur no Biome stream folder exists. Each written record holds one field 1 submessage and, at the top level, repeated field 2 items. Message Time (UTC) is the submessage's field 8, eight bytes read as a little-endian double of seconds since 1 January 1970 UTC; Direction (as stored), Bundle ID, Intent Class (as stored), Chat ID (as stored) and Message GUID (as stored) are its fields 6, 4, 2, 12 and 13, as iLEAPP's biomeSiriRemembersMessageHistory module reads them (Reference: iLEAPP, scripts/artifacts/biomeSiriRemembersMessageHistory.py, https://github.com/abrignoni/iLEAPP/blob/8d6a44d946a2c79cecf196c2599e21e2d42ba2e2/scripts/artifacts/biomeSiriRemembersMessageHistory.py#L148-L154). Participants (as stored) joins each top-level field 2 item as its field 1 name and the field 1 text of its field 2 entity, which that module reads as the parameter names and values (for example sender and recipients); what a value denotes is not established. On the public MacBook Pro logical extraction (macOS 15.4, not a registered corpus key) the stream gives 4 rows from one user's local folder, so User and Sync Origin each held one value there, and on those 4 rows Direction (1), Bundle ID (com.apple.MobileSMS), Intent Class (INSendMessageIntent) and Chat ID each held one value; Message Time fell in 2025 on the rows checked.", "sample_data": { "dleapp_macos_bigsur": "macOS Big Sur (Josh Hickman public test image, thisisdfir) | 0 rows (no member matches the declared paths)", }, @@ -398,7 +438,12 @@ "last_update_date": "2026-09-26", "requirements": "none", "category": "Biome (macOS)", - "notes": "Reads the _DKEvent.Wifi.Connection Biome stream. Each file in the stream's local folder, and in each folder under its remote folder, other than one whose name begins with a dot, is read as a SEGB file with the vendored ccl_segb package, one row per record the file marks as written whose data ccl_segb can still read, and each such record is read as one protobuf message whose fields are taken by number without a schema; a record that does not read as one is counted in the run log and not reported. Records the file does not mark as written are not reported; those ccl_segb returns are counted in the run log, and it returns none of the entries a version 2 file marks as empty. Files under a tombstone folder are not read. Record Time (UTC) is the time the SEGB file stores with each record, which ccl_segb reads from a version 2 file as seconds since 00:00:00 on 1 January 2001 and DLEAPP reports as UTC (Reference: CCL Solutions Group, ccl-segb, ccl_segb/ccl_segb2.py, https://github.com/cclgroupltd/ccl-segb/blob/23c3f7d3d969a79627b738ba0a2486c31d675753/ccl_segb/ccl_segb2.py#L133-L142, and ccl_segb/ccl_segb_common.py, https://github.com/cclgroupltd/ccl-segb/blob/23c3f7d3d969a79627b738ba0a2486c31d675753/ccl_segb/ccl_segb_common.py#L5-L21); every file of the stream on the tested extraction is SEGB version 2. User is the folder after Users in the source path, or root under private/var/root, and is blank when the input is one user's home folder whose path names no user. Sync Origin is Local for the local folder, or Remote with the name of the folder under remote the record came from. Record Offset is where the record begins in its file: in a version 2 file that is the record's 8-byte header, which starts with its stored CRC, and the record's data begins 8 bytes later. When a logical extraction holds the stream under Users/ and under System/Volumes/Data/Users/, a record with the same offset, time and bytes in both is reported once, and the run log counts the repeats. On dleapp_macos_bigsur no Biome stream folder exists. Event Time (UTC) is field 2, eight bytes read as a little-endian double of seconds since 1 January 2001 UTC (the same reference DLEAPP reports the record time in); Event (as stored) is field 1's field 1, Device (as stored) is field 4's field 3, and GUID (as stored) is field 5, as iLEAPP's biomeWifi module reads them (Reference: iLEAPP, scripts/artifacts/biomeWifi.py, https://github.com/abrignoni/iLEAPP/blob/8d6a44d946a2c79cecf196c2599e21e2d42ba2e2/scripts/artifacts/biomeWifi.py#L116-L124). This is a DuetKnowledge event stream, separate from the Device.Wireless.WiFi stream the Biome Wi-Fi Connections artifact reads. On the public MacBook Pro logical extraction (macOS 15.4, not a registered corpus key) the stream gives 37 rows from one user's local folder, so User and Sync Origin each held one value there; Event (as stored) held /wifi/connection on the rows checked and Event Time fell in 2025.", + "notes": "Reads the _DKEvent.Wifi.Connection Biome stream. Each file in the stream's local folder, and in each folder under its remote folder, other than one whose name begins with a dot, is read as a SEGB file with the vendored ccl_segb package, one row per record the file marks as written whose data ccl_segb can still read, and each such record is read as one protobuf message whose fields are taken by number without a schema; a record that does not read as one is counted in the run log and not reported. Records the file does not mark as written are not reported; those ccl_segb returns are counted in the run log, and it returns none of the entries a version 2 file marks as empty. Files under a tombstone folder are not read. Record Time (UTC) is the time the SEGB file stores with each record, which ccl_segb reads from a version 2 file as seconds since 00:00:00 on 1 January 2001 and DLEAPP reports as UTC (Reference: CCL Solutions Group, ccl-segb, ccl_segb/ccl_segb2.py, https://github.com/cclgroupltd/ccl-segb/blob/23c3f7d3d969a79627b738ba0a2486c31d675753/ccl_segb/ccl_segb2.py#L133-L142, and ccl_segb/ccl_segb_common.py, https://github.com/cclgroupltd/ccl-segb/blob/23c3f7d3d969a79627b738ba0a2486c31d675753/ccl_segb/ccl_segb_common.py#L5-L21); every file of the stream on the tested extraction is SEGB version 2. User is the folder after Users in the source path, or root under private/var/root, and is blank when the input is one user's home folder whose path names no user. " + "Sync Origin is Local for the local folder, or Remote with the name of the folder" + " under remote the record came from. Sync Origin does not separate two files of " + "one folder, and every file in a folder is read, so Source File names the file " + "each row came from and the file its Record Offset counts from." + " Record Offset is where the record begins in its file: in a version 2 file that is the record's 8-byte header, which starts with its stored CRC, and the record's data begins 8 bytes later. When a logical extraction holds the stream under Users/ and under System/Volumes/Data/Users/, a record with the same offset, time and bytes in both is reported once, and the run log counts the repeats. On dleapp_macos_bigsur no Biome stream folder exists. Event Time (UTC) is field 2, eight bytes read as a little-endian double of seconds since 1 January 2001 UTC (the same reference DLEAPP reports the record time in); Event (as stored) is field 1's field 1, Device (as stored) is field 4's field 3, and GUID (as stored) is field 5, as iLEAPP's biomeWifi module reads them (Reference: iLEAPP, scripts/artifacts/biomeWifi.py, https://github.com/abrignoni/iLEAPP/blob/8d6a44d946a2c79cecf196c2599e21e2d42ba2e2/scripts/artifacts/biomeWifi.py#L116-L124). This is a DuetKnowledge event stream, separate from the Device.Wireless.WiFi stream the Biome Wi-Fi Connections artifact reads. On the public MacBook Pro logical extraction (macOS 15.4, not a registered corpus key) the stream gives 37 rows from one user's local folder, so User and Sync Origin each held one value there; Event (as stored) held /wifi/connection on the rows checked and Event Time fell in 2025.", "sample_data": { "dleapp_macos_bigsur": "macOS Big Sur (Josh Hickman public test image, thisisdfir) | 0 rows (no member matches the declared paths)", }, @@ -414,7 +459,12 @@ "last_update_date": "2026-09-26", "requirements": "none", "category": "Biome (macOS)", - "notes": "Each file in the stream's local folder, and in each folder under its remote folder, other than one whose name begins with a dot, is read as a SEGB file with the vendored ccl_segb package, one row per record the file marks as written whose data ccl_segb can still read, and each such record is read as one protobuf message whose fields are taken by number without a schema; a record that does not read as one is counted in the run log and not reported. Records the file does not mark as written are not reported; those ccl_segb returns are counted in the run log, and it returns none of the entries a version 2 file marks as empty. Files under a tombstone folder are not read. Record Time (UTC) is the time the SEGB file stores with each record, which ccl_segb reads from a version 2 file as seconds since 00:00:00 on 1 January 2001 and DLEAPP reports as UTC (Reference: CCL Solutions Group, ccl-segb, ccl_segb/ccl_segb2.py, https://github.com/cclgroupltd/ccl-segb/blob/23c3f7d3d969a79627b738ba0a2486c31d675753/ccl_segb/ccl_segb2.py#L133-L142, and ccl_segb/ccl_segb_common.py, https://github.com/cclgroupltd/ccl-segb/blob/23c3f7d3d969a79627b738ba0a2486c31d675753/ccl_segb/ccl_segb_common.py#L5-L21); every file of the stream on the tested extraction is SEGB version 2. User is the folder after Users in the source path, or root under private/var/root, and is blank when the input is one user's home folder whose path names no user. Sync Origin is Local for the local folder, or Remote with the name of the folder under remote the record came from. Record Offset is where the record begins in its file: in a version 2 file that is the record's 8-byte header, which starts with its stored CRC, and the record's data begins 8 bytes later. When a logical extraction holds the stream under Users/ and under System/Volumes/Data/Users/, a record with the same offset, time and bytes in both is reported once, and the run log counts the repeats. On dleapp_macos_bigsur no Biome stream folder exists. Each written record is one protobuf message. Bundle ID is field 3 and Event (as stored) is field 1, as iLEAPP's biomeScreenTimeAppUsage module reads them (Reference: iLEAPP, scripts/artifacts/biomeStreams.py, https://github.com/abrignoni/iLEAPP/blob/ea591113284c3e2e48bff4bee934fe45827a5c22/scripts/artifacts/biomeStreams.py#L249-L259). Event (as stored) held an integer on every record measured and is reported as stored; its meaning is not documented, and iLEAPP's notes for the same stream say the same. On the public MacBook Pro logical extraction (macOS 15.4, not a registered corpus key) the stream gives 370 rows from one user's local folder, so User and Sync Origin each held one value there; the rows name 18 distinct bundle IDs, Event (as stored) held 0 on 202 rows and 1 on 168, and Record Time fell in 2025 on every row.", + "notes": "Each file in the stream's local folder, and in each folder under its remote folder, other than one whose name begins with a dot, is read as a SEGB file with the vendored ccl_segb package, one row per record the file marks as written whose data ccl_segb can still read, and each such record is read as one protobuf message whose fields are taken by number without a schema; a record that does not read as one is counted in the run log and not reported. Records the file does not mark as written are not reported; those ccl_segb returns are counted in the run log, and it returns none of the entries a version 2 file marks as empty. Files under a tombstone folder are not read. Record Time (UTC) is the time the SEGB file stores with each record, which ccl_segb reads from a version 2 file as seconds since 00:00:00 on 1 January 2001 and DLEAPP reports as UTC (Reference: CCL Solutions Group, ccl-segb, ccl_segb/ccl_segb2.py, https://github.com/cclgroupltd/ccl-segb/blob/23c3f7d3d969a79627b738ba0a2486c31d675753/ccl_segb/ccl_segb2.py#L133-L142, and ccl_segb/ccl_segb_common.py, https://github.com/cclgroupltd/ccl-segb/blob/23c3f7d3d969a79627b738ba0a2486c31d675753/ccl_segb/ccl_segb_common.py#L5-L21); every file of the stream on the tested extraction is SEGB version 2. User is the folder after Users in the source path, or root under private/var/root, and is blank when the input is one user's home folder whose path names no user. " + "Sync Origin is Local for the local folder, or Remote with the name of the folder" + " under remote the record came from. Sync Origin does not separate two files of " + "one folder, and every file in a folder is read, so Source File names the file " + "each row came from and the file its Record Offset counts from." + " Record Offset is where the record begins in its file: in a version 2 file that is the record's 8-byte header, which starts with its stored CRC, and the record's data begins 8 bytes later. When a logical extraction holds the stream under Users/ and under System/Volumes/Data/Users/, a record with the same offset, time and bytes in both is reported once, and the run log counts the repeats. On dleapp_macos_bigsur no Biome stream folder exists. Each written record is one protobuf message. Bundle ID is field 3 and Event (as stored) is field 1, as iLEAPP's biomeScreenTimeAppUsage module reads them (Reference: iLEAPP, scripts/artifacts/biomeStreams.py, https://github.com/abrignoni/iLEAPP/blob/ea591113284c3e2e48bff4bee934fe45827a5c22/scripts/artifacts/biomeStreams.py#L249-L259). Event (as stored) held an integer on every record measured and is reported as stored; its meaning is not documented, and iLEAPP's notes for the same stream say the same. On the public MacBook Pro logical extraction (macOS 15.4, not a registered corpus key) the stream gives 370 rows from one user's local folder, so User and Sync Origin each held one value there; the rows name 18 distinct bundle IDs, Event (as stored) held 0 on 202 rows and 1 on 168, and Record Time fell in 2025 on every row.", "sample_data": { "dleapp_macos_bigsur": "macOS Big Sur (Josh Hickman public test image, thisisdfir) | 0 rows (no member matches the declared paths)", }, @@ -430,7 +480,12 @@ "last_update_date": "2026-09-26", "requirements": "none", "category": "Biome (macOS)", - "notes": "Each file in the stream's local folder, and in each folder under its remote folder, other than one whose name begins with a dot, is read as a SEGB file with the vendored ccl_segb package, one row per record the file marks as written whose data ccl_segb can still read, and each such record is read as one protobuf message whose fields are taken by number without a schema; a record that does not read as one is counted in the run log and not reported. Records the file does not mark as written are not reported; those ccl_segb returns are counted in the run log, and it returns none of the entries a version 2 file marks as empty. Files under a tombstone folder are not read. Record Time (UTC) is the time the SEGB file stores with each record, which ccl_segb reads from a version 2 file as seconds since 00:00:00 on 1 January 2001 and DLEAPP reports as UTC (Reference: CCL Solutions Group, ccl-segb, ccl_segb/ccl_segb2.py, https://github.com/cclgroupltd/ccl-segb/blob/23c3f7d3d969a79627b738ba0a2486c31d675753/ccl_segb/ccl_segb2.py#L133-L142, and ccl_segb/ccl_segb_common.py, https://github.com/cclgroupltd/ccl-segb/blob/23c3f7d3d969a79627b738ba0a2486c31d675753/ccl_segb/ccl_segb_common.py#L5-L21); every file of the stream on the tested extraction is SEGB version 2. User is the folder after Users in the source path, or root under private/var/root, and is blank when the input is one user's home folder whose path names no user. Sync Origin is Local for the local folder, or Remote with the name of the folder under remote the record came from. Record Offset is where the record begins in its file: in a version 2 file that is the record's 8-byte header, which starts with its stored CRC, and the record's data begins 8 bytes later. When a logical extraction holds the stream under Users/ and under System/Volumes/Data/Users/, a record with the same offset, time and bytes in both is reported once, and the run log counts the repeats. On dleapp_macos_bigsur no Biome stream folder exists. Each written record is one protobuf message holding two integer fields. Field 1 (as stored) is field 1 and Field 2 (as stored) is field 2, both reported as stored: no source documents what either records, so neither is named or interpreted. iLEAPP has no reader for this stream; its biomeBluetooth module reads the separate Device.Wireless.Bluetooth stream, which holds a device MAC and name and is not this one. On the public MacBook Pro logical extraction (macOS 15.4, not a registered corpus key) the stream gives 3,707 rows from one user's local folder, so User and Sync Origin each held one value there; Field 1 (as stored) held 0 on 1,849 rows and 1 on 1,858, Field 2 (as stored) held five distinct values (131090 on 3,346 rows, then 65553 on 167, 65544 on 162, 6 on 22 and 22 on 10), and Record Time fell in 2025 on every row.", + "notes": "Each file in the stream's local folder, and in each folder under its remote folder, other than one whose name begins with a dot, is read as a SEGB file with the vendored ccl_segb package, one row per record the file marks as written whose data ccl_segb can still read, and each such record is read as one protobuf message whose fields are taken by number without a schema; a record that does not read as one is counted in the run log and not reported. Records the file does not mark as written are not reported; those ccl_segb returns are counted in the run log, and it returns none of the entries a version 2 file marks as empty. Files under a tombstone folder are not read. Record Time (UTC) is the time the SEGB file stores with each record, which ccl_segb reads from a version 2 file as seconds since 00:00:00 on 1 January 2001 and DLEAPP reports as UTC (Reference: CCL Solutions Group, ccl-segb, ccl_segb/ccl_segb2.py, https://github.com/cclgroupltd/ccl-segb/blob/23c3f7d3d969a79627b738ba0a2486c31d675753/ccl_segb/ccl_segb2.py#L133-L142, and ccl_segb/ccl_segb_common.py, https://github.com/cclgroupltd/ccl-segb/blob/23c3f7d3d969a79627b738ba0a2486c31d675753/ccl_segb/ccl_segb_common.py#L5-L21); every file of the stream on the tested extraction is SEGB version 2. User is the folder after Users in the source path, or root under private/var/root, and is blank when the input is one user's home folder whose path names no user. " + "Sync Origin is Local for the local folder, or Remote with the name of the folder" + " under remote the record came from. Sync Origin does not separate two files of " + "one folder, and every file in a folder is read, so Source File names the file " + "each row came from and the file its Record Offset counts from." + " Record Offset is where the record begins in its file: in a version 2 file that is the record's 8-byte header, which starts with its stored CRC, and the record's data begins 8 bytes later. When a logical extraction holds the stream under Users/ and under System/Volumes/Data/Users/, a record with the same offset, time and bytes in both is reported once, and the run log counts the repeats. On dleapp_macos_bigsur no Biome stream folder exists. Each written record is one protobuf message holding two integer fields. Field 1 (as stored) is field 1 and Field 2 (as stored) is field 2, both reported as stored: no source documents what either records, so neither is named or interpreted. iLEAPP has no reader for this stream; its biomeBluetooth module reads the separate Device.Wireless.Bluetooth stream, which holds a device MAC and name and is not this one. On the public MacBook Pro logical extraction (macOS 15.4, not a registered corpus key) the stream gives 3,707 rows from one user's local folder, so User and Sync Origin each held one value there; Field 1 (as stored) held 0 on 1,849 rows and 1 on 1,858, Field 2 (as stored) held five distinct values (131090 on 3,346 rows, then 65553 on 167, 65544 on 162, 6 on 22 and 22 on 10), and Record Time fell in 2025 on every row.", "sample_data": { "dleapp_macos_bigsur": "macOS Big Sur (Josh Hickman public test image, thisisdfir) | 0 rows (no member matches the declared paths)", }, @@ -446,7 +501,12 @@ "last_update_date": "2026-09-26", "requirements": "none", "category": "Biome (macOS)", - "notes": "Each file in the stream's local folder, and in each folder under its remote folder, other than one whose name begins with a dot, is read as a SEGB file with the vendored ccl_segb package, one row per record the file marks as written whose data ccl_segb can still read, and each such record is read as one protobuf message whose fields are taken by number without a schema; a record that does not read as one is counted in the run log and not reported. Records the file does not mark as written are not reported; those ccl_segb returns are counted in the run log, and it returns none of the entries a version 2 file marks as empty. Files under a tombstone folder are not read. Record Time (UTC) is the time the SEGB file stores with each record, which ccl_segb reads from a version 2 file as seconds since 00:00:00 on 1 January 2001 and DLEAPP reports as UTC (Reference: CCL Solutions Group, ccl-segb, ccl_segb/ccl_segb2.py, https://github.com/cclgroupltd/ccl-segb/blob/23c3f7d3d969a79627b738ba0a2486c31d675753/ccl_segb/ccl_segb2.py#L133-L142, and ccl_segb/ccl_segb_common.py, https://github.com/cclgroupltd/ccl-segb/blob/23c3f7d3d969a79627b738ba0a2486c31d675753/ccl_segb/ccl_segb_common.py#L5-L21); every file of the stream on the tested extraction is SEGB version 2. User is the folder after Users in the source path, or root under private/var/root, and is blank when the input is one user's home folder whose path names no user. Sync Origin is Local for the local folder, or Remote with the name of the folder under remote the record came from. Record Offset is where the record begins in its file: in a version 2 file that is the record's 8-byte header, which starts with its stored CRC, and the record's data begins 8 bytes later. When a logical extraction holds the stream under Users/ and under System/Volumes/Data/Users/, a record with the same offset, time and bytes in both is reported once, and the run log counts the repeats. On dleapp_macos_bigsur no Biome stream folder exists. Bundle ID is field 2, Intent Class (as stored) is field 4 and Action (as stored) is field 5, and field 8 is read as an NSKeyedArchiver plist, as iLEAPP's biomeIntents module reads them (Reference: iLEAPP, scripts/artifacts/biomeIntents.py, https://github.com/abrignoni/iLEAPP/blob/ea591113284c3e2e48bff4bee934fe45827a5c22/scripts/artifacts/biomeIntents.py#L94-L127). On every record of the tested extraction the root object of that plist is an INInteraction, and the remaining columns are INInteraction properties that Apple's Intents framework declares in INInteraction.h (read from the macOS 27.0 SDK, where both enumerations below are marked available from macOS 11): Interval Start (UTC) is the start date of dateInterval, Direction is direction, Handling Status is intentHandlingStatus, Group ID (as stored) is groupIdentifier and Interaction ID (as stored) is identifier. Direction and Handling Status show the name INInteraction.h gives the stored number (INInteractionDirection: 0 Unspecified, 1 Outgoing, 2 Incoming; INIntentHandlingStatus: 0 Unspecified, 1 Ready, 2 In Progress, 3 Success, 4 Failure, 5 Deferred To Application, 6 User Confirmation Required) with the number beside it, and a number outside those lists is shown alone. When field 8 is absent or does not read as a keyed archive, those columns are blank and the run log counts the record. The intent's own payload (its backing store bytes) and the intent response are not reported: their content is written by each app, and iLEAPP's notes for the same stream say the fields inside it are not documented. Intent Class (as stored) is not always the class of the archived intent object: on 129 of the 135 records of the tested extraction the archived object is INIntent while field 4 names TodayIntent or TagIntent, and on the other 6 the two are equal. The end date of dateInterval equalled its start on all 135 records of the tested extraction and its duration was 0, so only the start is reported. On the public MacBook Pro logical extraction (macOS 15.4, not a registered corpus key) the stream gives 135 rows from one user's local folder, so User and Sync Origin each held one value there. Bundle ID was com.apple.news on 129 rows, com.apple.MobileSMS on 4 and com.apple.parsecd on 2, and Action (as stored) was filled on 6 rows. On the 4 com.apple.MobileSMS rows Direction was Incoming (2), Handling Status was Success (3), Group ID (as stored) was filled, and Record Time was later than Interval Start by up to 2,345,339 seconds (about 27 days); on the other 131 rows Direction and Handling Status were Unspecified (0), Group ID (as stored) was blank and Record Time was within one second of Interval Start. Both times fell in 2025 on every row.", + "notes": "Each file in the stream's local folder, and in each folder under its remote folder, other than one whose name begins with a dot, is read as a SEGB file with the vendored ccl_segb package, one row per record the file marks as written whose data ccl_segb can still read, and each such record is read as one protobuf message whose fields are taken by number without a schema; a record that does not read as one is counted in the run log and not reported. Records the file does not mark as written are not reported; those ccl_segb returns are counted in the run log, and it returns none of the entries a version 2 file marks as empty. Files under a tombstone folder are not read. Record Time (UTC) is the time the SEGB file stores with each record, which ccl_segb reads from a version 2 file as seconds since 00:00:00 on 1 January 2001 and DLEAPP reports as UTC (Reference: CCL Solutions Group, ccl-segb, ccl_segb/ccl_segb2.py, https://github.com/cclgroupltd/ccl-segb/blob/23c3f7d3d969a79627b738ba0a2486c31d675753/ccl_segb/ccl_segb2.py#L133-L142, and ccl_segb/ccl_segb_common.py, https://github.com/cclgroupltd/ccl-segb/blob/23c3f7d3d969a79627b738ba0a2486c31d675753/ccl_segb/ccl_segb_common.py#L5-L21); every file of the stream on the tested extraction is SEGB version 2. User is the folder after Users in the source path, or root under private/var/root, and is blank when the input is one user's home folder whose path names no user. " + "Sync Origin is Local for the local folder, or Remote with the name of the folder" + " under remote the record came from. Sync Origin does not separate two files of " + "one folder, and every file in a folder is read, so Source File names the file " + "each row came from and the file its Record Offset counts from." + " Record Offset is where the record begins in its file: in a version 2 file that is the record's 8-byte header, which starts with its stored CRC, and the record's data begins 8 bytes later. When a logical extraction holds the stream under Users/ and under System/Volumes/Data/Users/, a record with the same offset, time and bytes in both is reported once, and the run log counts the repeats. On dleapp_macos_bigsur no Biome stream folder exists. Bundle ID is field 2, Intent Class (as stored) is field 4 and Action (as stored) is field 5, and field 8 is read as an NSKeyedArchiver plist, as iLEAPP's biomeIntents module reads them (Reference: iLEAPP, scripts/artifacts/biomeIntents.py, https://github.com/abrignoni/iLEAPP/blob/ea591113284c3e2e48bff4bee934fe45827a5c22/scripts/artifacts/biomeIntents.py#L94-L127). On every record of the tested extraction the root object of that plist is an INInteraction, and the remaining columns are INInteraction properties that Apple's Intents framework declares in INInteraction.h (read from the macOS 27.0 SDK, where both enumerations below are marked available from macOS 11): Interval Start (UTC) is the start date of dateInterval, Direction is direction, Handling Status is intentHandlingStatus, Group ID (as stored) is groupIdentifier and Interaction ID (as stored) is identifier. Direction and Handling Status show the name INInteraction.h gives the stored number (INInteractionDirection: 0 Unspecified, 1 Outgoing, 2 Incoming; INIntentHandlingStatus: 0 Unspecified, 1 Ready, 2 In Progress, 3 Success, 4 Failure, 5 Deferred To Application, 6 User Confirmation Required) with the number beside it, and a number outside those lists is shown alone. When field 8 is absent or does not read as a keyed archive, those columns are blank and the run log counts the record. The intent's own payload (its backing store bytes) and the intent response are not reported: their content is written by each app, and iLEAPP's notes for the same stream say the fields inside it are not documented. Intent Class (as stored) is not always the class of the archived intent object: on 129 of the 135 records of the tested extraction the archived object is INIntent while field 4 names TodayIntent or TagIntent, and on the other 6 the two are equal. The end date of dateInterval equalled its start on all 135 records of the tested extraction and its duration was 0, so only the start is reported. On the public MacBook Pro logical extraction (macOS 15.4, not a registered corpus key) the stream gives 135 rows from one user's local folder, so User and Sync Origin each held one value there. Bundle ID was com.apple.news on 129 rows, com.apple.MobileSMS on 4 and com.apple.parsecd on 2, and Action (as stored) was filled on 6 rows. On the 4 com.apple.MobileSMS rows Direction was Incoming (2), Handling Status was Success (3), Group ID (as stored) was filled, and Record Time was later than Interval Start by up to 2,345,339 seconds (about 27 days); on the other 131 rows Direction and Handling Status were Unspecified (0), Group ID (as stored) was blank and Record Time was within one second of Interval Start. Both times fell in 2025 on every row.", "sample_data": { "dleapp_macos_bigsur": "macOS Big Sur (Josh Hickman public test image, thisisdfir) | 0 rows (no member matches the declared paths)", }, @@ -462,7 +522,12 @@ "last_update_date": "2026-09-26", "requirements": "none", "category": "Biome (macOS)", - "notes": "Each file in the stream's local folder, and in each folder under its remote folder, other than one whose name begins with a dot, is read as a SEGB file with the vendored ccl_segb package, one row per record the file marks as written whose data ccl_segb can still read, and each such record is read as one protobuf message whose fields are taken by number without a schema; a record that does not read as one is counted in the run log and not reported. Records the file does not mark as written are not reported; those ccl_segb returns are counted in the run log, and it returns none of the entries a version 2 file marks as empty. Files under a tombstone folder are not read. Record Time (UTC) is the time the SEGB file stores with each record, which ccl_segb reads from a version 2 file as seconds since 00:00:00 on 1 January 2001 and DLEAPP reports as UTC (Reference: CCL Solutions Group, ccl-segb, ccl_segb/ccl_segb2.py, https://github.com/cclgroupltd/ccl-segb/blob/23c3f7d3d969a79627b738ba0a2486c31d675753/ccl_segb/ccl_segb2.py#L133-L142, and ccl_segb/ccl_segb_common.py, https://github.com/cclgroupltd/ccl-segb/blob/23c3f7d3d969a79627b738ba0a2486c31d675753/ccl_segb/ccl_segb_common.py#L5-L21); every file of the stream on the tested extraction is SEGB version 2. User is the folder after Users in the source path, or root under private/var/root, and is blank when the input is one user's home folder whose path names no user. Sync Origin is Local for the local folder, or Remote with the name of the folder under remote the record came from. Record Offset is where the record begins in its file: in a version 2 file that is the record's 8-byte header, which starts with its stored CRC, and the record's data begins 8 bytes later. When a logical extraction holds the stream under Users/ and under System/Volumes/Data/Users/, a record with the same offset, time and bytes in both is reported once, and the run log counts the repeats. On dleapp_macos_bigsur no Biome stream folder exists. Signal is field 1 and Value is field 2, as iLEAPP's biomeDiscoverabilitySignals module reads them (Reference: iLEAPP, scripts/artifacts/biomeDiscoverabilitySignals.py, https://github.com/abrignoni/iLEAPP/blob/ea591113284c3e2e48bff4bee934fe45827a5c22/scripts/artifacts/biomeDiscoverabilitySignals.py#L93-L100). Field 3 (as stored) is field 3: that module reads field 3 as a submessage, but on every record of the tested extraction that holds it, field 3 is a plain string, macOS-24E248, and 24E248 is the ProductBuildVersion in that extraction's System/Library/CoreServices/SystemVersion.plist. That module also reads field 4 as a payload; no record of the tested extraction holds a field 4, so it is not reported. What each signal records beyond its name is not established. On the public MacBook Pro logical extraction (macOS 15.4, not a registered corpus key) the stream gives 30 rows from one user's local folder, so User and Sync Origin each held one value there; Signal held five distinct names: two in the com.apple.Safari namespace, on 13 rows and on 8, spotlightWillAppear on 6, com.apple.notificationcenter.opened on 2 and com.apple.controlcenter.presented on 1, Value was filled on 23 rows and Field 3 (as stored) on 9, and Record Time fell in 2025 on every row.", + "notes": "Each file in the stream's local folder, and in each folder under its remote folder, other than one whose name begins with a dot, is read as a SEGB file with the vendored ccl_segb package, one row per record the file marks as written whose data ccl_segb can still read, and each such record is read as one protobuf message whose fields are taken by number without a schema; a record that does not read as one is counted in the run log and not reported. Records the file does not mark as written are not reported; those ccl_segb returns are counted in the run log, and it returns none of the entries a version 2 file marks as empty. Files under a tombstone folder are not read. Record Time (UTC) is the time the SEGB file stores with each record, which ccl_segb reads from a version 2 file as seconds since 00:00:00 on 1 January 2001 and DLEAPP reports as UTC (Reference: CCL Solutions Group, ccl-segb, ccl_segb/ccl_segb2.py, https://github.com/cclgroupltd/ccl-segb/blob/23c3f7d3d969a79627b738ba0a2486c31d675753/ccl_segb/ccl_segb2.py#L133-L142, and ccl_segb/ccl_segb_common.py, https://github.com/cclgroupltd/ccl-segb/blob/23c3f7d3d969a79627b738ba0a2486c31d675753/ccl_segb/ccl_segb_common.py#L5-L21); every file of the stream on the tested extraction is SEGB version 2. User is the folder after Users in the source path, or root under private/var/root, and is blank when the input is one user's home folder whose path names no user. " + "Sync Origin is Local for the local folder, or Remote with the name of the folder" + " under remote the record came from. Sync Origin does not separate two files of " + "one folder, and every file in a folder is read, so Source File names the file " + "each row came from and the file its Record Offset counts from." + " Record Offset is where the record begins in its file: in a version 2 file that is the record's 8-byte header, which starts with its stored CRC, and the record's data begins 8 bytes later. When a logical extraction holds the stream under Users/ and under System/Volumes/Data/Users/, a record with the same offset, time and bytes in both is reported once, and the run log counts the repeats. On dleapp_macos_bigsur no Biome stream folder exists. Signal is field 1 and Value is field 2, as iLEAPP's biomeDiscoverabilitySignals module reads them (Reference: iLEAPP, scripts/artifacts/biomeDiscoverabilitySignals.py, https://github.com/abrignoni/iLEAPP/blob/ea591113284c3e2e48bff4bee934fe45827a5c22/scripts/artifacts/biomeDiscoverabilitySignals.py#L93-L100). Field 3 (as stored) is field 3: that module reads field 3 as a submessage, but on every record of the tested extraction that holds it, field 3 is a plain string, macOS-24E248, and 24E248 is the ProductBuildVersion in that extraction's System/Library/CoreServices/SystemVersion.plist. That module also reads field 4 as a payload; no record of the tested extraction holds a field 4, so it is not reported. What each signal records beyond its name is not established. On the public MacBook Pro logical extraction (macOS 15.4, not a registered corpus key) the stream gives 30 rows from one user's local folder, so User and Sync Origin each held one value there; Signal held five distinct names: two in the com.apple.Safari namespace, on 13 rows and on 8, spotlightWillAppear on 6, com.apple.notificationcenter.opened on 2 and com.apple.controlcenter.presented on 1, Value was filled on 23 rows and Field 3 (as stored) on 9, and Record Time fell in 2025 on every row.", "sample_data": { "dleapp_macos_bigsur": "macOS Big Sur (Josh Hickman public test image, thisisdfir) | 0 rows (no member matches the declared paths)", }, @@ -478,7 +543,12 @@ "last_update_date": "2026-09-26", "requirements": "none", "category": "Biome (macOS)", - "notes": "Each file in the stream's local folder, and in each folder under its remote folder, other than one whose name begins with a dot, is read as a SEGB file with the vendored ccl_segb package, one row per record the file marks as written whose data ccl_segb can still read, and each such record is read as one protobuf message whose fields are taken by number without a schema; a record that does not read as one is counted in the run log and not reported. Records the file does not mark as written are not reported; those ccl_segb returns are counted in the run log, and it returns none of the entries a version 2 file marks as empty. Files under a tombstone folder are not read. Record Time (UTC) is the time the SEGB file stores with each record, which ccl_segb reads from a version 2 file as seconds since 00:00:00 on 1 January 2001 and DLEAPP reports as UTC (Reference: CCL Solutions Group, ccl-segb, ccl_segb/ccl_segb2.py, https://github.com/cclgroupltd/ccl-segb/blob/23c3f7d3d969a79627b738ba0a2486c31d675753/ccl_segb/ccl_segb2.py#L133-L142, and ccl_segb/ccl_segb_common.py, https://github.com/cclgroupltd/ccl-segb/blob/23c3f7d3d969a79627b738ba0a2486c31d675753/ccl_segb/ccl_segb_common.py#L5-L21); every file of the stream on the tested extraction is SEGB version 2. User is the folder after Users in the source path, or root under private/var/root, and is blank when the input is one user's home folder whose path names no user. Sync Origin is Local for the local folder, or Remote with the name of the folder under remote the record came from. Record Offset is where the record begins in its file: in a version 2 file that is the record's 8-byte header, which starts with its stored CRC, and the record's data begins 8 bytes later. When a logical extraction holds the stream under Users/ and under System/Volumes/Data/Users/, a record with the same offset, time and bytes in both is reported once, and the run log counts the repeats. On dleapp_macos_bigsur no Biome stream folder exists. No iLEAPP module reads this stream, so the fields are reported as stored and each column is named for the form of its value, not for a meaning. Field 1 (as stored) is field 1. Bundle ID (as stored) is field 2, which held a reverse-DNS app identifier on every record. URL (as stored) is field 3 and Blob URL (as stored) is field 4, which held an https URL and a blob: URL where present. Field 5 (as stored) is field 5 and UUID (as stored) is field 8. Field 6, read as eight bytes of a little-endian double of seconds since 1 January 1970 UTC, was within 0.012 seconds of Record Time on every record of the tested extraction, so it is not reported separately. What each field records is not established. On the public MacBook Pro logical extraction (macOS 15.4, not a registered corpus key) the stream gives 14 rows from one user's local folder, so User and Sync Origin each held one value there; Bundle ID (as stored) was com.apple.AppStore on 10 rows and com.apple.Safari on 4, URL (as stored) and Blob URL (as stored) were filled on the 4 com.apple.Safari rows only, Field 5 (as stored) held 1 on every row, and each of the 7 UUID (as stored) values appeared on two rows with the same Bundle ID (as stored), the earlier with Field 1 (as stored) 1 and the later with 0, between 2 and 301 seconds apart. Record Time fell in 2025 on every row.", + "notes": "Each file in the stream's local folder, and in each folder under its remote folder, other than one whose name begins with a dot, is read as a SEGB file with the vendored ccl_segb package, one row per record the file marks as written whose data ccl_segb can still read, and each such record is read as one protobuf message whose fields are taken by number without a schema; a record that does not read as one is counted in the run log and not reported. Records the file does not mark as written are not reported; those ccl_segb returns are counted in the run log, and it returns none of the entries a version 2 file marks as empty. Files under a tombstone folder are not read. Record Time (UTC) is the time the SEGB file stores with each record, which ccl_segb reads from a version 2 file as seconds since 00:00:00 on 1 January 2001 and DLEAPP reports as UTC (Reference: CCL Solutions Group, ccl-segb, ccl_segb/ccl_segb2.py, https://github.com/cclgroupltd/ccl-segb/blob/23c3f7d3d969a79627b738ba0a2486c31d675753/ccl_segb/ccl_segb2.py#L133-L142, and ccl_segb/ccl_segb_common.py, https://github.com/cclgroupltd/ccl-segb/blob/23c3f7d3d969a79627b738ba0a2486c31d675753/ccl_segb/ccl_segb_common.py#L5-L21); every file of the stream on the tested extraction is SEGB version 2. User is the folder after Users in the source path, or root under private/var/root, and is blank when the input is one user's home folder whose path names no user. " + "Sync Origin is Local for the local folder, or Remote with the name of the folder" + " under remote the record came from. Sync Origin does not separate two files of " + "one folder, and every file in a folder is read, so Source File names the file " + "each row came from and the file its Record Offset counts from." + " Record Offset is where the record begins in its file: in a version 2 file that is the record's 8-byte header, which starts with its stored CRC, and the record's data begins 8 bytes later. When a logical extraction holds the stream under Users/ and under System/Volumes/Data/Users/, a record with the same offset, time and bytes in both is reported once, and the run log counts the repeats. On dleapp_macos_bigsur no Biome stream folder exists. No iLEAPP module reads this stream, so the fields are reported as stored and each column is named for the form of its value, not for a meaning. Field 1 (as stored) is field 1. Bundle ID (as stored) is field 2, which held a reverse-DNS app identifier on every record. URL (as stored) is field 3 and Blob URL (as stored) is field 4, which held an https URL and a blob: URL where present. Field 5 (as stored) is field 5 and UUID (as stored) is field 8. Field 6, read as eight bytes of a little-endian double of seconds since 1 January 1970 UTC, was within 0.012 seconds of Record Time on every record of the tested extraction, so it is not reported separately. What each field records is not established. On the public MacBook Pro logical extraction (macOS 15.4, not a registered corpus key) the stream gives 14 rows from one user's local folder, so User and Sync Origin each held one value there; Bundle ID (as stored) was com.apple.AppStore on 10 rows and com.apple.Safari on 4, URL (as stored) and Blob URL (as stored) were filled on the 4 com.apple.Safari rows only, Field 5 (as stored) held 1 on every row, and each of the 7 UUID (as stored) values appeared on two rows with the same Bundle ID (as stored), the earlier with Field 1 (as stored) 1 and the later with 0, between 2 and 301 seconds apart. Record Time fell in 2025 on every row.", "sample_data": { "dleapp_macos_bigsur": "macOS Big Sur (Josh Hickman public test image, thisisdfir) | 0 rows (no member matches the declared paths)", }, @@ -494,7 +564,12 @@ "last_update_date": "2026-09-26", "requirements": "none", "category": "Biome (macOS)", - "notes": "Each file in the stream's local folder, and in each folder under its remote folder, other than one whose name begins with a dot, is read as a SEGB file with the vendored ccl_segb package, one row per record the file marks as written whose data ccl_segb can still read, and each such record is read as one protobuf message whose fields are taken by number without a schema; a record that does not read as one is counted in the run log and not reported. Records the file does not mark as written are not reported; those ccl_segb returns are counted in the run log, and it returns none of the entries a version 2 file marks as empty. Files under a tombstone folder are not read. Record Time (UTC) is the time the SEGB file stores with each record, which ccl_segb reads from a version 2 file as seconds since 00:00:00 on 1 January 2001 and DLEAPP reports as UTC (Reference: CCL Solutions Group, ccl-segb, ccl_segb/ccl_segb2.py, https://github.com/cclgroupltd/ccl-segb/blob/23c3f7d3d969a79627b738ba0a2486c31d675753/ccl_segb/ccl_segb2.py#L133-L142, and ccl_segb/ccl_segb_common.py, https://github.com/cclgroupltd/ccl-segb/blob/23c3f7d3d969a79627b738ba0a2486c31d675753/ccl_segb/ccl_segb_common.py#L5-L21); every file of the stream on the tested extraction is SEGB version 2. User is the folder after Users in the source path, or root under private/var/root, and is blank when the input is one user's home folder whose path names no user. Sync Origin is Local for the local folder, or Remote with the name of the folder under remote the record came from. Record Offset is where the record begins in its file: in a version 2 file that is the record's 8-byte header, which starts with its stored CRC, and the record's data begins 8 bytes later. When a logical extraction holds the stream under Users/ and under System/Volumes/Data/Users/, a record with the same offset, time and bytes in both is reported once, and the run log counts the repeats. On dleapp_macos_bigsur no Biome stream folder exists. No iLEAPP module reads this stream, so the fields are reported as stored and each column is named for the form of its value, not for a meaning. Host (as stored) is field 1, which held a host name on every record. Field 3 (as stored), Field 4 (as stored) and Field 5 (as stored) are fields 3, 4 and 5. Field 2, read as eight bytes of a little-endian double of seconds since 1 January 1970 UTC, was the first half-hour boundary after Record Time on every record of the tested extraction, so it is not reported separately. What each field records is not established. On the public MacBook Pro logical extraction (macOS 15.4, not a registered corpus key) the stream gives 8 rows from one user's local folder, so User and Sync Origin each held one value there; Host (as stored) held three distinct host names, Field 3 (as stored), Field 4 (as stored) and Field 5 (as stored) held 2, US and 0 on every row, and Record Time fell in 2025 on every row.", + "notes": "Each file in the stream's local folder, and in each folder under its remote folder, other than one whose name begins with a dot, is read as a SEGB file with the vendored ccl_segb package, one row per record the file marks as written whose data ccl_segb can still read, and each such record is read as one protobuf message whose fields are taken by number without a schema; a record that does not read as one is counted in the run log and not reported. Records the file does not mark as written are not reported; those ccl_segb returns are counted in the run log, and it returns none of the entries a version 2 file marks as empty. Files under a tombstone folder are not read. Record Time (UTC) is the time the SEGB file stores with each record, which ccl_segb reads from a version 2 file as seconds since 00:00:00 on 1 January 2001 and DLEAPP reports as UTC (Reference: CCL Solutions Group, ccl-segb, ccl_segb/ccl_segb2.py, https://github.com/cclgroupltd/ccl-segb/blob/23c3f7d3d969a79627b738ba0a2486c31d675753/ccl_segb/ccl_segb2.py#L133-L142, and ccl_segb/ccl_segb_common.py, https://github.com/cclgroupltd/ccl-segb/blob/23c3f7d3d969a79627b738ba0a2486c31d675753/ccl_segb/ccl_segb_common.py#L5-L21); every file of the stream on the tested extraction is SEGB version 2. User is the folder after Users in the source path, or root under private/var/root, and is blank when the input is one user's home folder whose path names no user. " + "Sync Origin is Local for the local folder, or Remote with the name of the folder" + " under remote the record came from. Sync Origin does not separate two files of " + "one folder, and every file in a folder is read, so Source File names the file " + "each row came from and the file its Record Offset counts from." + " Record Offset is where the record begins in its file: in a version 2 file that is the record's 8-byte header, which starts with its stored CRC, and the record's data begins 8 bytes later. When a logical extraction holds the stream under Users/ and under System/Volumes/Data/Users/, a record with the same offset, time and bytes in both is reported once, and the run log counts the repeats. On dleapp_macos_bigsur no Biome stream folder exists. No iLEAPP module reads this stream, so the fields are reported as stored and each column is named for the form of its value, not for a meaning. Host (as stored) is field 1, which held a host name on every record. Field 3 (as stored), Field 4 (as stored) and Field 5 (as stored) are fields 3, 4 and 5. Field 2, read as eight bytes of a little-endian double of seconds since 1 January 1970 UTC, was the first half-hour boundary after Record Time on every record of the tested extraction, so it is not reported separately. What each field records is not established. On the public MacBook Pro logical extraction (macOS 15.4, not a registered corpus key) the stream gives 8 rows from one user's local folder, so User and Sync Origin each held one value there; Host (as stored) held three distinct host names, Field 3 (as stored), Field 4 (as stored) and Field 5 (as stored) held 2, US and 0 on every row, and Record Time fell in 2025 on every row.", "sample_data": { "dleapp_macos_bigsur": "macOS Big Sur (Josh Hickman public test image, thisisdfir) | 0 rows (no member matches the declared paths)", }, @@ -510,7 +585,12 @@ "last_update_date": "2026-09-26", "requirements": "none", "category": "Biome (macOS)", - "notes": "Each file in the stream's local folder, and in each folder under its remote folder, other than one whose name begins with a dot, is read as a SEGB file with the vendored ccl_segb package, one row per record the file marks as written whose data ccl_segb can still read, and each such record is read as one protobuf message whose fields are taken by number without a schema; a record that does not read as one is counted in the run log and not reported. Records the file does not mark as written are not reported; those ccl_segb returns are counted in the run log, and it returns none of the entries a version 2 file marks as empty. Files under a tombstone folder are not read. Record Time (UTC) is the time the SEGB file stores with each record, which ccl_segb reads from a version 2 file as seconds since 00:00:00 on 1 January 2001 and DLEAPP reports as UTC (Reference: CCL Solutions Group, ccl-segb, ccl_segb/ccl_segb2.py, https://github.com/cclgroupltd/ccl-segb/blob/23c3f7d3d969a79627b738ba0a2486c31d675753/ccl_segb/ccl_segb2.py#L133-L142, and ccl_segb/ccl_segb_common.py, https://github.com/cclgroupltd/ccl-segb/blob/23c3f7d3d969a79627b738ba0a2486c31d675753/ccl_segb/ccl_segb_common.py#L5-L21); every file of the stream on the tested extraction is SEGB version 2. User is the folder after Users in the source path, or root under private/var/root, and is blank when the input is one user's home folder whose path names no user. Sync Origin is Local for the local folder, or Remote with the name of the folder under remote the record came from. Record Offset is where the record begins in its file: in a version 2 file that is the record's 8-byte header, which starts with its stored CRC, and the record's data begins 8 bytes later. When a logical extraction holds the stream under Users/ and under System/Volumes/Data/Users/, a record with the same offset, time and bytes in both is reported once, and the run log counts the repeats. On dleapp_macos_bigsur no Biome stream folder exists. Search Term is field 1, and Result URIs and Result Labels are fields 1 and 2 of each field 2 submessage, joined with '; ', as iLEAPP's biomeSystemSettingsSearchTerms module reads them (Reference: iLEAPP, scripts/artifacts/biomeSystemSettingsSearchTerms.py, https://github.com/abrignoni/iLEAPP/blob/ea591113284c3e2e48bff4bee934fe45827a5c22/scripts/artifacts/biomeSystemSettingsSearchTerms.py#L78-L89). Result URIs and Result Labels are blank on a record that holds no field 2. What each record says about how the term was entered is not established; the values are reported as stored. Sync Origin is Local on every row when the extraction holds no remote folder for the stream.", + "notes": "Each file in the stream's local folder, and in each folder under its remote folder, other than one whose name begins with a dot, is read as a SEGB file with the vendored ccl_segb package, one row per record the file marks as written whose data ccl_segb can still read, and each such record is read as one protobuf message whose fields are taken by number without a schema; a record that does not read as one is counted in the run log and not reported. Records the file does not mark as written are not reported; those ccl_segb returns are counted in the run log, and it returns none of the entries a version 2 file marks as empty. Files under a tombstone folder are not read. Record Time (UTC) is the time the SEGB file stores with each record, which ccl_segb reads from a version 2 file as seconds since 00:00:00 on 1 January 2001 and DLEAPP reports as UTC (Reference: CCL Solutions Group, ccl-segb, ccl_segb/ccl_segb2.py, https://github.com/cclgroupltd/ccl-segb/blob/23c3f7d3d969a79627b738ba0a2486c31d675753/ccl_segb/ccl_segb2.py#L133-L142, and ccl_segb/ccl_segb_common.py, https://github.com/cclgroupltd/ccl-segb/blob/23c3f7d3d969a79627b738ba0a2486c31d675753/ccl_segb/ccl_segb_common.py#L5-L21); every file of the stream on the tested extraction is SEGB version 2. User is the folder after Users in the source path, or root under private/var/root, and is blank when the input is one user's home folder whose path names no user. " + "Sync Origin is Local for the local folder, or Remote with the name of the folder" + " under remote the record came from. Sync Origin does not separate two files of " + "one folder, and every file in a folder is read, so Source File names the file " + "each row came from and the file its Record Offset counts from." + " Record Offset is where the record begins in its file: in a version 2 file that is the record's 8-byte header, which starts with its stored CRC, and the record's data begins 8 bytes later. When a logical extraction holds the stream under Users/ and under System/Volumes/Data/Users/, a record with the same offset, time and bytes in both is reported once, and the run log counts the repeats. On dleapp_macos_bigsur no Biome stream folder exists. Search Term is field 1, and Result URIs and Result Labels are fields 1 and 2 of each field 2 submessage, joined with '; ', as iLEAPP's biomeSystemSettingsSearchTerms module reads them (Reference: iLEAPP, scripts/artifacts/biomeSystemSettingsSearchTerms.py, https://github.com/abrignoni/iLEAPP/blob/ea591113284c3e2e48bff4bee934fe45827a5c22/scripts/artifacts/biomeSystemSettingsSearchTerms.py#L78-L89). Result URIs and Result Labels are blank on a record that holds no field 2. What each record says about how the term was entered is not established; the values are reported as stored. Sync Origin is Local on every row when the extraction holds no remote folder for the stream.", "sample_data": {"dleapp_macos_bigsur": "macOS Big Sur (Josh Hickman public test image, thisisdfir) | 0 rows (no member matches the declared paths)"}, "paths": ("*/Biome/streams/*/SystemSettings.SearchTerms/local/*", "*/Biome/streams/*/SystemSettings.SearchTerms/remote/*"), @@ -525,7 +605,12 @@ "last_update_date": "2026-09-26", "requirements": "none", "category": "Biome (macOS)", - "notes": "Each file in the stream's local folder, and in each folder under its remote folder, other than one whose name begins with a dot, is read as a SEGB file with the vendored ccl_segb package, one row per record the file marks as written whose data ccl_segb can still read, and each such record is read as one protobuf message whose fields are taken by number without a schema; a record that does not read as one is counted in the run log and not reported. Records the file does not mark as written are not reported; those ccl_segb returns are counted in the run log, and it returns none of the entries a version 2 file marks as empty. Files under a tombstone folder are not read. Record Time (UTC) is the time the SEGB file stores with each record, which ccl_segb reads from a version 2 file as seconds since 00:00:00 on 1 January 2001 and DLEAPP reports as UTC (Reference: CCL Solutions Group, ccl-segb, ccl_segb/ccl_segb2.py, https://github.com/cclgroupltd/ccl-segb/blob/23c3f7d3d969a79627b738ba0a2486c31d675753/ccl_segb/ccl_segb2.py#L133-L142, and ccl_segb/ccl_segb_common.py, https://github.com/cclgroupltd/ccl-segb/blob/23c3f7d3d969a79627b738ba0a2486c31d675753/ccl_segb/ccl_segb_common.py#L5-L21); every file of the stream on the tested extraction is SEGB version 2. User is the folder after Users in the source path, or root under private/var/root, and is blank when the input is one user's home folder whose path names no user. Sync Origin is Local for the local folder, or Remote with the name of the folder under remote the record came from. Record Offset is where the record begins in its file: in a version 2 file that is the record's 8-byte header, which starts with its stored CRC, and the record's data begins 8 bytes later. When a logical extraction holds the stream under Users/ and under System/Volumes/Data/Users/, a record with the same offset, time and bytes in both is reported once, and the run log counts the repeats. On dleapp_macos_bigsur no Biome stream folder exists. Bundle ID is field 1 and Intent Time is field 4 read as a double of seconds since 1970 UTC, as iLEAPP's biomeAppIntentsTranscript module reads them (Reference: iLEAPP, scripts/artifacts/biomeAppIntentsTranscript.py, https://github.com/abrignoni/iLEAPP/blob/ea591113284c3e2e48bff4bee934fe45827a5c22/scripts/artifacts/biomeAppIntentsTranscript.py#L147-L149). That module takes the intent message from field 5 and falls back to field 6; this artifact takes it from field 6 and falls back to field 5, so a record whose parameters are held under field 6 and not under field 5 keeps them, and a record holding both reports field 6. Intent Class is field 1 of the intent message, and for each of its field 7 submessages Parameters is field 1, Entity Types is field 1 of field 3 of field 1 of field 2, Entity Titles is field 1 of field 1 of field 3 of field 2, and App URL is field 4 of that same message, each list joined with '; ' and App URL without repeats, as that module reads them (https://github.com/abrignoni/iLEAPP/blob/ea591113284c3e2e48bff4bee934fe45827a5c22/scripts/artifacts/biomeAppIntentsTranscript.py#L69-L97). Phrase Template is field 1 of field 1 of field 2 of field 8 (https://github.com/abrignoni/iLEAPP/blob/ea591113284c3e2e48bff4bee934fe45827a5c22/scripts/artifacts/biomeAppIntentsTranscript.py#L137-L145). Each of those columns is blank on a record that lacks the field. What an intent in this stream records beyond its stored values is not established. Sync Origin is Local on every row when the extraction holds no remote folder for the stream.", + "notes": "Each file in the stream's local folder, and in each folder under its remote folder, other than one whose name begins with a dot, is read as a SEGB file with the vendored ccl_segb package, one row per record the file marks as written whose data ccl_segb can still read, and each such record is read as one protobuf message whose fields are taken by number without a schema; a record that does not read as one is counted in the run log and not reported. Records the file does not mark as written are not reported; those ccl_segb returns are counted in the run log, and it returns none of the entries a version 2 file marks as empty. Files under a tombstone folder are not read. Record Time (UTC) is the time the SEGB file stores with each record, which ccl_segb reads from a version 2 file as seconds since 00:00:00 on 1 January 2001 and DLEAPP reports as UTC (Reference: CCL Solutions Group, ccl-segb, ccl_segb/ccl_segb2.py, https://github.com/cclgroupltd/ccl-segb/blob/23c3f7d3d969a79627b738ba0a2486c31d675753/ccl_segb/ccl_segb2.py#L133-L142, and ccl_segb/ccl_segb_common.py, https://github.com/cclgroupltd/ccl-segb/blob/23c3f7d3d969a79627b738ba0a2486c31d675753/ccl_segb/ccl_segb_common.py#L5-L21); every file of the stream on the tested extraction is SEGB version 2. User is the folder after Users in the source path, or root under private/var/root, and is blank when the input is one user's home folder whose path names no user. " + "Sync Origin is Local for the local folder, or Remote with the name of the folder" + " under remote the record came from. Sync Origin does not separate two files of " + "one folder, and every file in a folder is read, so Source File names the file " + "each row came from and the file its Record Offset counts from." + " Record Offset is where the record begins in its file: in a version 2 file that is the record's 8-byte header, which starts with its stored CRC, and the record's data begins 8 bytes later. When a logical extraction holds the stream under Users/ and under System/Volumes/Data/Users/, a record with the same offset, time and bytes in both is reported once, and the run log counts the repeats. On dleapp_macos_bigsur no Biome stream folder exists. Bundle ID is field 1 and Intent Time is field 4 read as a double of seconds since 1970 UTC, as iLEAPP's biomeAppIntentsTranscript module reads them (Reference: iLEAPP, scripts/artifacts/biomeAppIntentsTranscript.py, https://github.com/abrignoni/iLEAPP/blob/ea591113284c3e2e48bff4bee934fe45827a5c22/scripts/artifacts/biomeAppIntentsTranscript.py#L147-L149). That module takes the intent message from field 5 and falls back to field 6; this artifact takes it from field 6 and falls back to field 5, so a record whose parameters are held under field 6 and not under field 5 keeps them, and a record holding both reports field 6. Intent Class is field 1 of the intent message, and for each of its field 7 submessages Parameters is field 1, Entity Types is field 1 of field 3 of field 1 of field 2, Entity Titles is field 1 of field 1 of field 3 of field 2, and App URL is field 4 of that same message, each list joined with '; ' and App URL without repeats, as that module reads them (https://github.com/abrignoni/iLEAPP/blob/ea591113284c3e2e48bff4bee934fe45827a5c22/scripts/artifacts/biomeAppIntentsTranscript.py#L69-L97). Phrase Template is field 1 of field 1 of field 2 of field 8 (https://github.com/abrignoni/iLEAPP/blob/ea591113284c3e2e48bff4bee934fe45827a5c22/scripts/artifacts/biomeAppIntentsTranscript.py#L137-L145). Each of those columns is blank on a record that lacks the field. What an intent in this stream records beyond its stored values is not established. Sync Origin is Local on every row when the extraction holds no remote folder for the stream.", "sample_data": {"dleapp_macos_bigsur": "macOS Big Sur (Josh Hickman public test image, thisisdfir) | 0 rows (no member matches the declared paths)"}, "paths": ("*/Biome/streams/*/App.Intents.Transcript/local/*", "*/Biome/streams/*/App.Intents.Transcript/remote/*"), diff --git a/scripts/artifacts/macosContacts.py b/scripts/artifacts/macosContacts.py index abcf1c0..5b7fa77 100644 --- a/scripts/artifacts/macosContacts.py +++ b/scripts/artifacts/macosContacts.py @@ -18,8 +18,11 @@ "notes": "Reads each user's AddressBook-v22.abcddb under ~/Library/Application " "Support/AddressBook and the one in each Sources folder beneath it, one " "row per ZABCDRECORD row whose entity is ABCDContact in Z_PRIMARYKEY. " - "Store is Main for the top-level database and Sources/ with the folder " - "name for one under Sources. Created (UTC) and Modified (UTC) are " + "Store is Main for the top-level database and Sources/ with the folder name for " + "one under Sources. Store and User do not separate the Users/ and " + "System/Volumes/Data/Users/ copies of one database, which are both read when they" + " differ, so Source File names the file each row came from. Created (UTC) and " + "Modified (UTC) are " "ZCREATIONDATE and ZMODIFICATIONDATE read as seconds since 00:00:00 UTC " "on 1 January 2001, the reference date Apple documents for NSDate; read " "that way the 4 contacts on dleapp_macos_bigsur were created between " diff --git a/scripts/artifacts/windowsPortableDevices.py b/scripts/artifacts/windowsPortableDevices.py index af135d3..95d42f0 100644 --- a/scripts/artifacts/windowsPortableDevices.py +++ b/scripts/artifacts/windowsPortableDevices.py @@ -18,7 +18,11 @@ " and of Enum\\SWD\\WPDBUSENUM in the SYSTEM hive's control set named by the Select " "key's Current value (ControlSet001 when there is none), with each subkey's " "FriendlyName and DeviceDesc values as stored. Device Key is the subkey name as " - "stored and is not parsed. Registry Location names the key a row came from. Key Last " + "stored and is not parsed. " + "Registry Location names the key a row came from. Registry Location does not " + "separate two copies of one hive, and the declared paths also match a hive under " + "Windows.old, so Source File names the file each row came from." + " Key Last " "Written is when the subkey was last written, which is not established as when a " "device was connected.", "paths": (