← Back to Help
WarpedWing Labs

Biome SEGB Parser

This module parses macOS Biome SEGB (Sequential Event Grid Block) files to extract system telemetry and application metrics.

Disclaimer

This report is for informational and investigative purposes only. The data presented should be independently verified before being relied upon for any legal, regulatory, or evidentiary purpose.

Limitations

What Are Biome Files?

Biome is Apple's system telemetry framework introduced in macOS 12 (Monterey). It records application usage, system events, and device metrics in binary SEGB format files stored under ~/Library/Biome/.

Forensically relevant data includes:

Parsed Data

SEGB Records

Each SEGB file contains a stream of timestamped records. The parser extracts:

Empty Record Detection

Records containing only null bytes are flagged as empty and can be filtered during analysis.

Data Sources

Artifact Path Pattern macOS Versions
Biome Streams ~/Library/Biome/streams/**/*.segb 12.0+ (Monterey)
Biome Streams ~/Library/Biome/streams/**/*store 12.0+

Common stream locations include:

Not Currently Parsed

Output Files

Dependencies

This module requires the ccl_segb library for SEGB file parsing.

Scan Type

Exemplar only - This module runs during live system scans to capture current Biome state. It is not used for carved/recovered file processing.