# Tagging Rule Reference Generated from `rules/examples/*.toml` — the actual shipped rule files, not a hand-transcribed summary that can drift from them. Regenerate (`python3 scripts/gen_rules_reference.py`) after adding/editing a rule file rather than hand-editing this doc directly. All five packs below ship **embedded in the binary itself** (`build.rs` + `src/tagging/builtin.rs`) and every rule in them is enabled by default — see [user-guide.md](user-guide.md#tagging) for the "Built-in rules..." picker that lets you enable/disable individual rules rather than only a whole pack at once. ## AUL pattern-of-life rules (51) Most predicates sourced from ["Apple Unified Log Predicates in iLEAPP: The Reference"](https://leapps.org/blog-post?post=2026-08-01-unified-log-predicate-reference) (Alexis Brignoni), with a handful of newer, higher-precision ones from Tim Korver's [Thesis Friday](https://thesisfriday.com/) series instead — see each rule file's header comment for the specific citation either way. Every rule matches `sourcetype = "aul"`. | Rule name | Match | Tag | Description | |---|---|---|---| | `aul_airdrop` | message contains any of:
• `AirDrop ID`
• `SharingDaemon State`
• `Scanning mode`
• `startSending`
• `New incoming transfer`
• `alertLog: idx:`
• `Activating com.apple.sharing.sharesheet` | `airdrop` | AirDrop discoverability, ID, and transfer activity | | `aul_airplane_mode` | message contains any of:
• `Airplane Mode is now 1`
• `Airplane Mode is now On`
• `Setting airplane mode to true`
• `Airplane mode now active`
• `enabling airplanemode`
• `Airplane mode changed`
• `Airplane Mode is now 0`
• `Airplane Mode is now Off`
• `Setting airplane mode to false`
• `Airplane mode now inactive`
• `Airplane mode Disabled`
• `Toggle AirPlane Mode state`
• `Setting airplane mode enabled`
• `isAirplaneMode = 1`
• `isAirplaneMode = 0` | `airplane_mode` | Airplane mode enabled or disabled | | `aul_app_focus_lifecycle` | message contains any of:
• `/device/app/inFocus`
• `Bootstrapping app<`
• `Bootstrapping application<`
• `killed from app switcher`
• `elementWithFocusBundleID changed`
• `Icon tapped`
• `Initiating launch from icon view`
• `Scene lifecycle state did change` | `app_focus_lifecycle` | Foreground app focus changes, cold starts vs. resumes, force-kills | | `aul_app_launch` | message contains any of:
• `Allowing tap for icon view`
• `Launching application`
• `transition source:` | `app_launch` | App icon taps and application launches | | `aul_audio_routes` | message contains any of:
• `vaemConfigurePVMSettings`
• `vaemVADRouteChangeListener`
• `cmsmActivateEndpointFromRouteDescription`
• `currently activating endpoint` | `audio_routes` | Audio output routing — receiver, speaker, or Bluetooth device | | `aul_audio_volume` | message contains any of:
• `AudioQueueIsPlaying`
• `VolumeIncrement`
• `rawVolumeIncreasePress`
• `rawVolumeDecreasePress`
• `Volume active`
• `PlaybackQueueInvalidation`
• `volumeValueDidChange` | `audio_volume` | Volume button presses and audio playback state changes | | `aul_battery_state` | message contains any of:
• `Battery capacity change posted`
• `battery info changed to` | `battery_state` | Battery charge level and charging state changes | | `aul_biometric_match` | message contains any of:
• `matchResultHandler: MATCH`
• `matchResult:timestamp:`
• `has received no-match`
• `Base unlock behavior received biometric event` | `biometric_match` | Face ID / Touch ID match results (MATCH, NO-MATCH, biometric events) — a match is not an unlock | | `aul_biometric_sensor_events` | message contains any of:
• `PearlCamFrameReceived`
• `getFaceDetectInfo`
• `[User Presence Monitor]`
• `kAppleBiometricFinger`
• `Home Button Was Pressed`
• `setFingerOnState: FingerON`
• `TouchID button pressed: 1` | `biometric_sensor_events` | Face ID / Touch ID sensor-level events (not the unlock decision itself) | | `aul_bluetooth_pairing` | message contains any of:
• `Device found: CBDevice`
• `pairing complete`
• `pairing started`
• `numeric comparison`
• `Running SDP` | `bluetooth_pairing` | Bluetooth device discovery and pairing (not routine reconnection) | | `aul_bluetooth_status` | message contains any of:
• `Bluetooth state changed`
• `Sending new bluetooth state`
• `Bluetooth state changed PoweredOn`
• `ServiceManager disconnection result for`
• `Device type is`
• `is asking to connect device`
• `Received connection result for`
• `Received disconnection result for`
• `Received handsfree disconnection`
• `Sending ring notification for call`
• `Accepting incoming audio connection`
• `Received voice audio connected`
• `Stopping A2DP audio streaming`
• `Bluetooth A2DP device`
• `Bluetooth Daemon: A2DP streaming`
• `Starting Media connection to device`
• `Received voice disconnection`
• `Disconnecting audio from device`
• `Audio was already disconnected`
• `Toggled Bluetooth state from`
• `CUBluetoothDevice`
• `handsfree device disconnected`
• `handsfree device connected`
• `Bluetooth state updated`
• `Bluetooth power is now off`
• `Bluetooth state`
• `Sending call state update`
• `A2DP LinkQualityReport` | `bluetooth_status` | Bluetooth connect/disconnect and call/handsfree audio routing | | `aul_call_events` | message contains any of:
• `Started tracking call`
• `Dialed call`
• `Call started outgoing`
• `All calls ended`
• `Received trusted open application request`
• `Resuming to tab type`
• `tab bar tab changed`
• `Incoming Request : actionID 120` | `call_events` | Phone call tracking, call-app navigation, and keypad tone requests | | `aul_call_status_update` | `category` = `call`
message contains `Call(StatusUpdate)` | `call_status_update` | CommCenter call state transitions (Call(StatusUpdate) ... -> ...) — shows whether a dialed call reached Dialing or connected, or collapsed to Disconnected | | `aul_camera_capture` | message contains any of:
• `will change to: Photo`
• `MomentCapture`
• `Still image capture type`
• `IrisWillBeginCapture`
• `added photo to library`
• `added video to library`
• `Created asset IMG` | `camera_capture` | Camera shutter to photo/video library capture chain | | `aul_carplay_connection` | message contains any of:
• `carPlayCapable = 1`
• `Found USB DirectLink`
• `session isAuthenticated:1, isActivated:1`
• `Persisting widget state for vehicle ID`
• `WiFiDeviceManagerSetCarPlaySessionState` | `carplay_connection` | CarPlay accessory handshake, wired-session marker (USB DirectLink), CarKit session auth, and per-vehicle state | | `aul_device_orientation` | message contains any of:
• `Received orientation.`
• `[TTW] Orientation changed` | `device_orientation` | Device orientation transitions (portrait/landscape/face up-down) | | `aul_dialed_number_recovery` | `category` = `call.provider`
message contains any of:
• `kPhoneNumber`
• `kActionType` | `dialed_number_recovery` | CommCenter call.provider transaction blocks: the setup block carries a dialed number in plain text (kPhoneNumber), the hang-up block shares its kUuid (kActionType) — a setup without a matching hang-up is an attempt, not a connected call | | `aul_dialpad_entry` | `category` = `ContactSearchManager`
message contains any of:
• `Searching for`
• `Search cancelled for` | `dialpad_entry` | Phone app dial-field contact search (ContactSearchManager) — the digits typed on the handset, step by step; absence does not rule out other entry surfaces | | `aul_dictation` | message contains any of:
• `DictationConnection startDictation`
• `Dictation did begin`
• `Dictation did end`
• `CSAudioRecordTypeDictation` | `dictation` | Voice dictation (keyboard mic input) start/end | | `aul_driving_state` | message contains any of:
• `MotionState: Driving`
• `vehicularStartTime`
• `PedestrianAfterDriving`
• `Engaging Driving`
• `com.apple.donotdisturb.mode.driving`
• `ATXModeDrivingFeaturizer` | `driving_state` | Vehicular motion classification (does not distinguish driver from passenger) | | `aul_emergency_sos` | message contains any of:
• `broadcasting SOSStatus`
• `flowStartedOnEitherDevice`
• `sosTriggeredOnPairedDevice`
• `EmergencyEnablementAssertion`
• `kCLEmergencyEnablementAssertion` | `emergency_sos` | Emergency SOS engine status/flow (presence alone is not proof of a call) | | `aul_flashlight` | message contains any of:
• `[Flashlight Controller]`
• `<<<>>>-`
• `<<<< AVFlashlight >>>>` | `flashlight` | Flashlight/torch turned on or off | | `aul_hardware_buttons` | `category` = `Button`
message contains `firstDown:` | `hardware_buttons` | Physical button press began/finished (backboardd, HID usage and hold time) | | `aul_hardware_buttons_springboard` | `subsystem` = `com.apple.SpringBoard.buttons`
message contains any of:
• `press count:`
• `Lock button single press recognized`
• `SOS button gesture: press type=` | `hardware_buttons` | Side button press count, single-press recognition and button press type (SpringBoard) | | `aul_interface_navigation` | message contains any of:
• `Control Center launched`
• `Control Center Visible`
• `Setting visibility of widget`
• `Today view overlay`
• `user-initiated scroll` | `interface_navigation` | Control Center, Today view, widgets, and home screen scrolling | | `aul_keyboard_activity` | message contains any of:
• `Incoming Request : actionID 1104`
• `Incoming Request : actionID 1155`
• `Incoming Request : actionID 1156` | `keyboard_activity` | Active typing — keyboard touch signposts and key-sound requests | | `aul_keyboard_activity_signposts` | `category` = `KeyboardSignposts` | `keyboard_activity` | Keyboard touch signposts (subsystem UIKitCore / com.apple.TextInput) | | `aul_keyboard_activity_touch` | `category` = `KeyboardTouch` | `keyboard_activity` | Raw on-screen-keyboard touch down/drag (subsystem UIKitCore / com.apple.UIKit:KeyboardTouch) | | `aul_lift_to_wake` | `subsystem` = `com.apple.SpringBoard`
`category` = `LiftToWake`
message contains `Transition received:` | `wake_gesture` | Lift-to-wake transition (SpringBoard LiftToWake, e.g. sleep -> wake) — the screen woke because the device was lifted | | `aul_media_playback` | `category` = `MediaRemote` | `media_playback` | Media now-playing state, playback changes, and route info | | `aul_motion_state` | message contains `Motion State Transition:` | `motion_state` | Motion/activity state transitions (walking, stationary, etc.) | | `aul_navigation` | subsystem starts with any of:
• `com.apple.Navigation`
• `com.apple.navigation.VirtualGarage` | `maps_navigation_activity` | Maps navigation framework activity (subsystem com.apple.Navigation) — route planning and navigation-service traffic, not proof a route was followed | | `aul_notification_interactions` | message contains any of:
• `removing notification request`
• `expanding notification group`
• `notification cell executing default action`
• `will present long look`
• `action reply for notification` | `notification_interactions` | User interaction with a notification (removal, tap-through, reply, ...) | | `aul_passcode_field` | message contains any of:
• `forSetDelegate:• `_teardownExistingDelegate:• `Doppler in pocket state`
• `PocketState changed` | `pocket_state` | Front infrared sensor: device face-down/stowed vs. out | | `aul_power_events` | message contains any of:
• `iBoot version`
• `Deferring device orientation updates for reason: shutdown`
• `locationd shutting down` | `power_events` | Boot and orderly shutdown markers | | `aul_screen_lock_state` | message contains any of:
• `Screen did lock`
• `ScreenOn changed`
• `Screen shut off`
• `screen is locked`
• `screen is unlocked`
• `Device unlocked`
• `Device lock status`
• `Biometric match complete` | `screen_lock_state` | Screen lock/unlock and biometric match events | | `aul_sim_cellular_state` | message contains any of:
• `kCTSIMSupportSIMStatus`
• `dataNetwork changed to`
• `disabling dataNetwork`
• `ISNetworkObserver: Set network type` | `sim_cellular_state` | SIM slot status and cellular/WiFi data network type changes | | `aul_sysdiagnose_generation` | message contains `Generating sysdiagnose` | `sysdiagnose_generation` | User-initiated sysdiagnose generation via the AssistiveTouch menu | | `aul_system_gestures` | message contains `system gesture stealing the touches` | `system_gestures` | Touches taken over by a system edge gesture (backboardd) — one entry is an edge touch, a swipe writes many | | `aul_system_gestures_springboard` | category starts with any of:
• `SystemGesture`
message contains `gestureRecognizerShouldBegin` | `system_gestures` | SpringBoard system gesture recognizer began (app switcher, Control Center, Cover Sheet) — not that the gesture completed | | `aul_tethering` | message contains any of:
• `Tethering is now enabled with`
• `Received notification that wireless modem state changed`
• `Previous tethering state was` | `tethering` | Personal hotspot / tethering enabled or disabled | | `aul_time_change` | message contains any of:
• `Time change: Clock shifted by`
• `Significant time change`
• `TMSetManualTime`
• `setting manual time` | `time_change` | System clock shifted, including manual time-setting | | `aul_touchscreen_events` | message contains any of:
• `contact 0 presence:`
• `contact 1 presence:`
• `contact 2 presence:`
• `contact 3 presence:`
• `contact 4 presence:`
• `contact 5 presence:`
• `contact 6 presence:`
• `contact 7 presence:`
• `contact 8 presence:`
• `contact 9 presence:`
• `touchstats`
• `received tapToWake`
• `AttentionAwareness.Touch`
• `Touch entered` | `touchscreen_events` | Touchscreen digitizer activity — per-finger contact presence changes (touching, within range, none), touch entered, touch statistics, tap-to-wake | | `aul_unlock_keybag_transitions` | `subsystem` = `com.apple.chrono`
`category` = `keybag`
message contains `Transition:` | `unlock_sessions` | ChronoServices keybag state transitions (all states) — written by several processes per transition, not a count of unlocks | | `aul_unlock_sessions` | message contains any of:
• `Screen did unlock (Was locked for`
• `Screen did lock (Was unlocked for`
• `Processed authentication request`
• `Unlock attempt succeeded`
• `Transition: locked ->`
• `apfs is being UN-locked`
• `is now UN-locked`
• `handle_async_keybag_unlock`
• `Sending notification for volume`
• `lock button source`
• `lockScreenImmediateFromTouchIDPress`
• `authenticated as user`
• `right 'system.login.screensaver'`
• `LWDefaultScreenLockUI loginPressed:]`
• `password is CORRECT`
• `ODRecordVerifyPassword failed`
• `pam_authenticate failed` | `unlock_sessions` | Unlock session duration, authentication method and outcome, kernel keybag/volume unlock endpoint | | `aul_usb_host` | message contains any of:
• `AppleUSBCableType`
• `launching clients due to connectType`
• `usb_host_connected`
• `bump_connection_count` | `usb_host_connection` | USB connection to a computer (cable type, connect type, lockdownd host session) — an acquisition produces these too | | `aul_usb_power_connections` | message contains any of:
• `plugin state changed to`
• `IOAccessoryUSBConnectShim`
• `pluggedIn 1` | `usb_power_connections` | USB/power cable attach and detach | | `aul_wake_gesture` | message contains `Gesture notification:` | `wake_gesture` | Wake gesture notifications (raise-to-wake recognizer: detected, dismissed, pre-detection) — 1(Detected) reads as a pick-up | | `aul_watch_crown_button` | message contains any of:
• `Description: Crown down`
• `Description: Button held`
• `Description: Button long-held` | `watch_crown_button` | Apple Watch Digital Crown / side button physical interaction | | `aul_wifi_status` | message contains any of:
• `WiFi state changed:`
• `Toggled WiFi state`
• `is WiFi associated?`
• `link status changed`
• `reachability changed`
• `ISNetworkObserver`
• `ForgetSSID`
• `en0: SSID`
• `Removing Lease SSID`
• `SysMon: WiFi state changed:`
• `WiFiManagerClientRemoveNetworkWithReason:`
• `WiFiSecurityRemovePassword`
• `AlwaysOnWifi:`
• `WiFiDeviceManagerSetNetworks:`
• `Scanning For Broadcast found:`
• `Scanning Remaining Channels`
• `WiFiSettlementObserver _handleScanResults`
• `Attempting to join`
• `WiFiLQAMgrSetCurrentNetwork: Joined SSID:`
• `Preparing background scan request for`
• `WiFiNetworkPrepareKnownBssList`
• `to list of known networks`
• `{AUTOJOIN, SCAN*} Scanning 2Ghz Channels found:`
• `{AUTOJOIN, SCAN*} Scanning 5Ghz Channels found:`
• `WFMacRandomisation`
• `manual association`
• `Copy password for Network`
• `Attempting auto join association`
• `Link went down`
• `Total connection time` | `wifi_status` | WiFi state changes, network joins, and scan activity | ## EVTX rules (59) Security-Auditing events are cross-checked against [Microsoft's official Security Auditing event reference](https://learn.microsoft.com/windows/security/threat-protection/auditing/); the Remote Desktop / Terminal Services and kernel events rest on the providers' own manifest texts and EricZimmerman's EvtxECmd maps — see each rule file's header comment for its specific citation and for whether it was checked against real records. Every rule matches `sourcetype = "evtx"`; companion to the built-in EVTX message templates (see [field-extraction.md](field-extraction.md#message-templates-evtx)). | Rule name | Match | Tag | Description | |---|---|---|---| | `evtx_kernel_general_os_started` | `provider` = `Microsoft-Windows-Kernel-General`
`event_id` = `12` | `system_boot` | The operating system started (Kernel-General 12) - StartTime in the record | | `evtx_kernel_general_os_shutdown` | `provider` = `Microsoft-Windows-Kernel-General`
`event_id` = `13` | `system_shutdown` | The operating system is shutting down (Kernel-General 13) - StopTime in the record | | `evtx_ts_session_logon` | `provider` = `Microsoft-Windows-TerminalServices-LocalSessionManager`
`event_id` = `21` | `ts_session_logon` | Terminal Services session logon succeeded (LocalSessionManager 21) - user, session ID and source address; LOCAL means console | | `evtx_ts_shell_start` | `provider` = `Microsoft-Windows-TerminalServices-LocalSessionManager`
`event_id` = `22` | `ts_shell_start` | Terminal Services shell start notification received (LocalSessionManager 22) - the session's desktop shell starting; LOCAL means console | | `evtx_ts_session_logoff` | `provider` = `Microsoft-Windows-TerminalServices-LocalSessionManager`
`event_id` = `23` | `ts_session_logoff` | Terminal Services session logoff succeeded (LocalSessionManager 23) - the session ended, not merely disconnected | | `evtx_ts_session_disconnected` | `provider` = `Microsoft-Windows-TerminalServices-LocalSessionManager`
`event_id` = `24` | `session_disconnected` | Terminal Services session disconnected (LocalSessionManager 24) - the same event Security 4779 records | | `evtx_ts_session_reconnected` | `provider` = `Microsoft-Windows-TerminalServices-LocalSessionManager`
`event_id` = `25` | `session_reconnected` | Terminal Services session reconnection succeeded (LocalSessionManager 25) - the same event Security 4778 records | | `evtx_kernel_power_unexpected_reboot` | `event_id` = `41` | `unexpected_shutdown` | Kernel-Power's own unexpected-reboot marker (41) | | `evtx_kernel_power_sleep` | `provider` = `Microsoft-Windows-Kernel-Power`
`event_id` = `42` | `system_sleep` | The system is entering sleep (Kernel-Power 42) | | `evtx_kernel_power_shutdown_transition` | `provider` = `Microsoft-Windows-Kernel-Power`
`event_id` = `109` | `system_shutdown` | The kernel power manager initiated a shutdown transition (Kernel-Power 109) | | `evtx_rdp_connection_accepted` | `provider` = `Microsoft-Windows-RemoteDesktopServices-RdpCoreTS`
`event_id` = `131` | `rdp_connection_accepted` | The RDP server accepted a new connection from a client (RdpCoreTS 131) - connection type and client IP | | `evtx_rdp_client_connect` | `provider` = `Microsoft-Windows-TerminalServices-ClientActiveXCore`
`event_id` = `1024` | `rdp_client_connect` | This machine's RDP client is trying to connect to a server (ClientActiveXCore 1024, RDPClient/Operational) - outbound RDP, destination in Value | | `evtx_system_shutdown_requested` | `event_id` = `1074` | `system_shutdown` | A system shutdown or restart was requested, with requestor and reason (1074) | | `evtx_audit_log_cleared` | `event_id` = `1102` | `audit_log_cleared` | The Security audit log was cleared (1102) — investigate why | | `evtx_rdp_connection_established` | `provider` = `Microsoft-Windows-TerminalServices-RemoteConnectionManager`
`event_id` = `1149` | `rdp_connection_established` | An RDP network connection was authenticated (RemoteConnectionManager 1149) - not proof of a successful logon | | `evtx_powershell_module_logging` | `event_id` = `4103` | `powershell_module_logging` | PowerShell Module Logging — records pipeline execution/command invocations (4103) | | `evtx_powershell_script_block` | `event_id` = `4104` | `powershell_script_block` | PowerShell Script Block Logging — records the actual (de-obfuscated) code executed (4104) | | `evtx_system_time_changed` | `event_id` = `4616` | `system_time_changed` | The system clock was changed (Security-Auditing 4616) | | `evtx_logon_success` | `event_id` = `4624` | `logon_success` | Successful account logon (Security-Auditing 4624) | | `evtx_rdp_logon_success` | `provider` = `Microsoft-Windows-Security-Auditing`
`event_id` = `4624`
event data has:
• `LogonType` = `10` | `rdp_logon` | Successful logon of type RemoteInteractive (Security-Auditing 4624, LogonType 10) - a Terminal Services / Remote Desktop logon | | `evtx_auth_failure` | `event_id` = `4625` | `auth_failure` | Failed account logon (Security-Auditing 4625) | | `evtx_rdp_logon_failure` | `provider` = `Microsoft-Windows-Security-Auditing`
`event_id` = `4625`
event data has:
• `LogonType` = `10` | `rdp_logon_failure` | Failed logon of type RemoteInteractive (Security-Auditing 4625, LogonType 10) - a failed Terminal Services / Remote Desktop logon | | `evtx_logoff` | `event_id` = `4634` | `logoff` | Account logoff (Security-Auditing 4634) | | `evtx_logoff_user_initiated` | `event_id` = `4647` | `logoff` | User initiated logoff (Security-Auditing 4647) - companion to 4634 | | `evtx_explicit_credentials` | `event_id` = `4648` | `explicit_credentials` | Logon attempted using explicit credentials, e.g. RunAs (Security-Auditing 4648) | | `evtx_kerberos_replay_attack` | `event_id` = `4649` | `kerberos_replay_attack` | A Kerberos replay attack was detected — domain controllers only (Security-Auditing 4649) | | `evtx_object_access_attempt` | `event_id` = `4663` | `object_access_attempt` | An attempt was made to access an object — file/registry/etc., requires SACL (Security-Auditing 4663) | | `evtx_privileged_logon` | `event_id` = `4672` | `privileged_logon` | Special privileges assigned to a new logon (Security-Auditing 4672) | | `evtx_process_creation` | `event_id` = `4688` | `process_creation` | New process created (Security-Auditing 4688) | | `evtx_process_exited` | `event_id` = `4689` | `process_exited` | A process has exited (Security-Auditing 4689) | | `evtx_service_install` | `event_id` = `4697` | `service_install` | A service was installed (Security-Auditing 4697) | | `evtx_scheduled_task_created` | `event_id` = `4698` | `scheduled_task_created` | A scheduled task was created (Security-Auditing 4698) | | `evtx_scheduled_task_deleted` | `event_id` = `4699` | `scheduled_task_deleted` | A scheduled task was deleted (Security-Auditing 4699) | | `evtx_account_created` | `event_id` = `4720` | `account_created` | A user account was created (Security-Auditing 4720) | | `evtx_account_enabled` | `event_id` = `4722` | `account_enabled` | A user account was enabled (Security-Auditing 4722) | | `evtx_password_change_self` | `event_id` = `4723` | `password_change_self` | An attempt was made to change an account's own password (Security-Auditing 4723) | | `evtx_password_reset_attempt` | `event_id` = `4724` | `password_reset_attempt` | An attempt was made to reset an account's password (Security-Auditing 4724) | | `evtx_account_disabled` | `event_id` = `4725` | `account_disabled` | A user account was disabled (Security-Auditing 4725) | | `evtx_account_deleted` | `event_id` = `4726` | `account_deleted` | A user account was deleted (Security-Auditing 4726) | | `evtx_group_membership_change_global` | `event_id` = `4728` | `group_membership_change` | Member added to a security-enabled global group (Security-Auditing 4728) | | `evtx_group_membership_removed_global` | `event_id` = `4729` | `group_membership_change` | Member removed from a security-enabled global group (Security-Auditing 4729) | | `evtx_group_membership_change_local` | `event_id` = `4732` | `group_membership_change` | Member added to a security-enabled local group (Security-Auditing 4732) | | `evtx_group_membership_removed_local` | `event_id` = `4733` | `group_membership_change` | Member removed from a security-enabled local group (Security-Auditing 4733) | | `evtx_account_modified` | `event_id` = `4738` | `account_modified` | A user account was changed (Security-Auditing 4738) | | `evtx_account_lockout` | `event_id` = `4740` | `account_lockout` | A user account was locked out (Security-Auditing 4740) | | `evtx_group_membership_change_universal` | `event_id` = `4756` | `group_membership_change` | Member added to a security-enabled universal group (Security-Auditing 4756) | | `evtx_group_membership_removed_universal` | `event_id` = `4757` | `group_membership_change` | Member removed from a security-enabled universal group (Security-Auditing 4757) | | `evtx_account_unlocked` | `event_id` = `4767` | `account_unlocked` | A user account was unlocked (Security-Auditing 4767) | | `evtx_kerberos_tgt_requested` | `event_id` = `4768` | `kerberos_tgt_requested` | A Kerberos TGT was requested — domain controllers only (Security-Auditing 4768) | | `evtx_kerberos_service_ticket_requested` | `event_id` = `4769` | `kerberos_service_ticket_requested` | A Kerberos service ticket was requested — domain controllers only (Security-Auditing 4769) | | `evtx_credential_validation` | `event_id` = `4776` | `credential_validation` | NTLM credential validation attempt, success or failure (Security-Auditing 4776) | | `evtx_session_reconnected` | `event_id` = `4778` | `session_reconnected` | A session was reconnected to a Window Station (Security-Auditing 4778) | | `evtx_session_disconnected` | `event_id` = `4779` | `session_disconnected` | A session was disconnected from a Window Station (Security-Auditing 4779) | | `evtx_network_share_accessed` | `event_id` = `5140` | `network_share_access` | A network share (SMB) was connected to — once per session (Security-Auditing 5140) | | `evtx_network_share_access_check` | `event_id` = `5145` | `network_share_access` | A network share (SMB) object access was checked (Security-Auditing 5145) | | `evtx_system_boot` | `event_id` = `6005` | `system_boot` | System startup — Event Log service started (6005) | | `evtx_unexpected_shutdown_detected` | `event_id` = `6008` | `unexpected_shutdown` | An unexpected/dirty shutdown was detected on the previous boot (6008) | | `evtx_service_start_type_changed` | `event_id` = `7040` | `service_start_type_changed` | A service's start type was changed, e.g. disabled (System log, Service Control Manager, 7040) | | `evtx_service_install_system_log` | `event_id` = `7045` | `service_install` | A service was installed, from the System log (Service Control Manager, event 7045) | ## journald rules (18) Message text sourced directly from the logging daemons' own source (OpenSSH, sudo, shadow-utils) rather than re-derived from memory — see each rule file's header comment for the specific citation. Every rule matches `sourcetype = "journald"` and scopes itself to a specific `process` (journald's `SYSLOG_IDENTIFIER`), since message text alone is the only signal journald offers — unlike EVTX's structured `event_id`. | Rule name | Match | Tag | Description | |---|---|---|---| | `journald_account_created` | `process` = `useradd`
message contains `new user:` | `account_created` | A local user account was created via useradd | | `journald_account_deleted` | `process` = `userdel`
message contains `delete user '` | `account_deleted` | A local user account was deleted via userdel | | `journald_account_lock_state_changed` | `process` = `usermod`
message contains `lock user '` | `account_lock_state_changed` | An account was locked or unlocked via usermod -L/-U | | `journald_account_modified` | `process` = `usermod`
message contains `change user '` | `account_modified` | A local user account was modified via usermod | | `journald_cron_command_cronie` | `process` = `CROND`
message contains `CMD (` | `cron_command` | A cron job command executed (cronie / RHEL family) | | `journald_cron_command_debian` | `process` = `CRON`
message contains `CMD (` | `cron_command` | A cron job command executed (vixie-cron / Debian family) | | `journald_group_membership_change` | `process` = `usermod`
message contains any of:
• `' to group '`
• `' from group '` | `group_membership_change` | A user was added to or removed from a group via usermod | | `journald_kernel_boot` | `_TRANSPORT` = `kernel`
message contains `Linux version` | `system_boot` | System boot — kernel version banner, the first ring-buffer message of every boot | | `journald_logind_session_closed` | `process` = `systemd-logind`
message contains `logged out. Waiting for processes to exit.` | `logoff` | A login session was closed — console, graphical, or su/sudo (systemd-logind "logged out") | | `journald_logind_session_opened` | `process` = `systemd-logind`
message contains `New session` | `logon_success` | A login session was opened — console, graphical, or su/sudo (systemd-logind "New session") | | `journald_pam_auth_failure_generic` | message contains `authentication failure` | `auth_failure` | A PAM authentication attempt failed, any service (pam_unix "authentication failure") | | `journald_password_changed` | `process` = `passwd`
message contains `changed by '` | `password_changed` | A user's password was changed via passwd | | `journald_ssh_logoff` | `process` = `sshd`
message contains `session closed for user` | `logoff` | An SSH session ended (sshd "session closed for user") | | `journald_ssh_logon_failure` | `process` = `sshd`
message contains any of:
• `Failed password for`
• `Failed publickey for`
• `Invalid user`
• `maximum authentication attempts exceeded` | `auth_failure` | Failed SSH authentication attempt (sshd "Failed ..."/"Invalid user") | | `journald_ssh_logon_success` | `process` = `sshd`
message contains any of:
• `Accepted password for`
• `Accepted publickey for`
• `Accepted keyboard-interactive` | `logon_success` | Successful SSH authentication (sshd "Accepted ...") | | `journald_su_session` | `process` = `su`
message contains `session opened for user` | `privilege_escalation` | A user switched accounts via su ("session opened for user") | | `journald_sudo_command` | `process` = `sudo`
message contains `COMMAND=` | `privileged_command` | A command was run via sudo ("COMMAND=") | | `journald_sudo_denied` | `process` = `sudo`
message contains any of:
• `incorrect password attempt`
• `is not allowed to run sudo`
• `is not in the sudoers file`
• `command not allowed` | `privileged_command_denied` | A sudo attempt failed authentication or was refused by policy | ## Android Intrusion Log rules (48) For Android's Advanced Protection Mode "Intrusion Logging" feature (Android 16+, built by Google with [Amnesty International's Security Lab](https://securitylab.amnesty.org/latest/2026/05/android-intrusion-logging-as-a-new-source-of-data-for-consensual-forensic-analysis/) for spyware forensics) — one rule per Android SecurityLog tag plus `dns_event`/`connect_event`. Tag IDs and descriptions sourced from Android's own AOSP `SecurityLogTags.logtags`/`SecurityLog.java` (Apache-2.0); the JSON format and each event's tag key cross-confirmed against two independent tools that parse real device exports of the same format — Amnesty's own [Mobile Verification Toolkit](https://github.com/mvt-project/mvt) and [ALEAPP](https://github.com/abrignoni/ALEAPP) — see each rule file's header comment for the specific citation. Every rule matches `sourcetype = "intrusion_log"`. | Rule name | Match | Tag | Description | |---|---|---|---| | `intrusion_log_adb_shell_cmd` | `event_type` = `security_event`
`security_event_tag` = `adb_shell_cmd` | `adb_shell_cmd` | A single command was run over ADB via 'adb shell ' (SecurityLog tag 210002) | | `intrusion_log_adb_shell_interactive` | `event_type` = `security_event`
`security_event_tag` = `adb_shell_interactive` | `adb_shell_interactive` | An interactive ADB shell session was opened on the device (SecurityLog tag 210001) | | `intrusion_log_adb_sync_recv_file` | `event_type` = `security_event`
`security_event_tag` = `adb_sync_recv_file` | `adb_sync_recv_file` | A file was copied off the device over ADB ('adb pull') (SecurityLog tag 210003) | | `intrusion_log_adb_sync_send_file` | `event_type` = `security_event`
`security_event_tag` = `adb_sync_send_file` | `adb_sync_send_file` | A file was copied onto the device over ADB ('adb push') (SecurityLog tag 210004) | | `intrusion_log_app_process_start` | `event_type` = `security_event`
`security_event_tag` = `app_process_start` | `app_process_start` | An application process was launched (SecurityLog tag 210005) | | `intrusion_log_backup_service_toggled` | `event_type` = `security_event`
`security_event_tag` = `backup_service_toggled` | `backup_service_toggled` | An administrator enabled or disabled the device backup service (SecurityLog tag 210044) | | `intrusion_log_bluetooth_connection` | `event_type` = `security_event`
`security_event_tag` = `bluetooth_connection` | `bluetooth_connection` | The device attempted to connect to a Bluetooth device (SecurityLog tag 210039) | | `intrusion_log_bluetooth_disconnection` | `event_type` = `security_event`
`security_event_tag` = `bluetooth_disconnection` | `bluetooth_disconnection` | The device disconnected from a connected Bluetooth device (SecurityLog tag 210040) | | `intrusion_log_camera_policy_set` | `event_type` = `security_event`
`security_event_tag` = `camera_policy_set` | `camera_policy_set` | An administrator set a policy disabling the camera (SecurityLog tag 210034) | | `intrusion_log_cert_authority_installed` | `event_type` = `security_event`
`security_event_tag` = `cert_authority_installed` | `cert_authority_installed` | A root/CA certificate was added to the system's trusted credential store — a classic prerequisite for TLS interception (SecurityLog tag 210029) | | `intrusion_log_cert_authority_removed` | `event_type` = `security_event`
`security_event_tag` = `cert_authority_removed` | `cert_authority_removed` | A root/CA certificate was removed from the system's trusted credential store (SecurityLog tag 210030) | | `intrusion_log_cert_validation_failure` | `event_type` = `security_event`
`security_event_tag` = `cert_validation_failure` | `cert_validation_failure` | An X.509 certificate failed validation (SecurityLog tag 210033) | | `intrusion_log_connect_event` | `event_type` = `connect_event` | `connect_event` | An app made an outbound network connection | | `intrusion_log_crypto_self_test_completed` | `event_type` = `security_event`
`security_event_tag` = `crypto_self_test_completed` | `crypto_self_test_completed` | The device's cryptographic subsystem completed its self-test (SecurityLog tag 210031) | | `intrusion_log_dns_event` | `event_type` = `dns_event` | `dns_event` | An app performed a DNS lookup | | `intrusion_log_key_destruction` | `event_type` = `security_event`
`security_event_tag` = `key_destruction` | `key_destruction` | A cryptographic key was deleted from the device's keystore (SecurityLog tag 210026) | | `intrusion_log_key_generated` | `event_type` = `security_event`
`security_event_tag` = `key_generated` | `key_generated` | A cryptographic key was generated in the device's keystore (SecurityLog tag 210024) | | `intrusion_log_key_import` | `event_type` = `security_event`
`security_event_tag` = `key_import` | `key_import` | A cryptographic key was imported into the device's keystore (SecurityLog tag 210025) | | `intrusion_log_key_integrity_violation` | `event_type` = `security_event`
`security_event_tag` = `key_integrity_violation` | `key_integrity_violation` | A stored cryptographic key failed an integrity check (SecurityLog tag 210032) | | `intrusion_log_keyguard_disabled_features_set` | `event_type` = `security_event`
`security_event_tag` = `keyguard_disabled_features_set` | `keyguard_disabled_features_set` | An administrator disabled specific lockscreen features (SecurityLog tag 210021) | | `intrusion_log_keyguard_dismiss_auth_attempt` | `event_type` = `security_event`
`security_event_tag` = `keyguard_dismiss_auth_attempt` | `keyguard_dismiss_auth_attempt` | An authentication attempt was made to unlock the lockscreen, successful or not (SecurityLog tag 210007) | | `intrusion_log_keyguard_dismissed` | `event_type` = `security_event`
`security_event_tag` = `keyguard_dismissed` | `keyguard_dismissed` | The lockscreen was dismissed, on a device with a secure lock screen configured (SecurityLog tag 210006) | | `intrusion_log_keyguard_secured` | `event_type` = `security_event`
`security_event_tag` = `keyguard_secured` | `keyguard_secured` | The device screen was locked, either by the user or after an inactivity timeout (SecurityLog tag 210008) | | `intrusion_log_log_buffer_size_critical` | `event_type` = `security_event`
`security_event_tag` = `log_buffer_size_critical` | `log_buffer_size_critical` | The on-device security log buffer reached 90% of its capacity (SecurityLog tag 210015) | | `intrusion_log_logging_started` | `event_type` = `security_event`
`security_event_tag` = `logging_started` | `logging_started` | Security audit logging (this feature) was turned on (SecurityLog tag 210011) | | `intrusion_log_logging_stopped` | `event_type` = `security_event`
`security_event_tag` = `logging_stopped` | `logging_stopped` | Security audit logging (this feature) was turned off (SecurityLog tag 210012) | | `intrusion_log_max_password_attempts_set` | `event_type` = `security_event`
`security_event_tag` = `max_password_attempts_set` | `max_password_attempts_set` | An administrator configured how many failed unlock attempts trigger a device wipe (SecurityLog tag 210020) | | `intrusion_log_max_screen_lock_timeout_set` | `event_type` = `security_event`
`security_event_tag` = `max_screen_lock_timeout_set` | `max_screen_lock_timeout_set` | An administrator configured the maximum allowed screen-lock timeout (SecurityLog tag 210019) | | `intrusion_log_media_mount` | `event_type` = `security_event`
`security_event_tag` = `media_mount` | `media_mount` | Removable storage media was mounted (SecurityLog tag 210013) | | `intrusion_log_media_unmount` | `event_type` = `security_event`
`security_event_tag` = `media_unmount` | `media_unmount` | Removable storage media was unmounted (SecurityLog tag 210014) | | `intrusion_log_nfc_disabled` | `event_type` = `security_event`
`security_event_tag` = `nfc_disabled` | `nfc_disabled` | NFC was disabled (SecurityLog tag 210046) | | `intrusion_log_nfc_enabled` | `event_type` = `security_event`
`security_event_tag` = `nfc_enabled` | `nfc_enabled` | NFC was enabled (SecurityLog tag 210045) | | `intrusion_log_os_shutdown` | `event_type` = `security_event`
`security_event_tag` = `os_shutdown` | `os_shutdown` | The Android OS shut down (SecurityLog tag 210010) | | `intrusion_log_os_startup` | `event_type` = `security_event`
`security_event_tag` = `os_startup` | `os_startup` | The Android OS finished starting up, including its boot-time integrity/verification state (SecurityLog tag 210009) | | `intrusion_log_package_installed` | `event_type` = `security_event`
`security_event_tag` = `package_installed` | `package_installed` | An application package was installed (SecurityLog tag 210041) | | `intrusion_log_package_uninstalled` | `event_type` = `security_event`
`security_event_tag` = `package_uninstalled` | `package_uninstalled` | An application package was uninstalled (SecurityLog tag 210043) | | `intrusion_log_package_updated` | `event_type` = `security_event`
`security_event_tag` = `package_updated` | `package_updated` | An application package was updated to a new version (SecurityLog tag 210042) | | `intrusion_log_password_changed` | `event_type` = `security_event`
`security_event_tag` = `password_changed` | `password_changed` | The user changed their lockscreen password (SecurityLog tag 210036) | | `intrusion_log_password_complexity_required` | `event_type` = `security_event`
`security_event_tag` = `password_complexity_required` | `password_complexity_required` | An administrator required one of the platform's predefined lockscreen password complexity levels (SecurityLog tag 210035) | | `intrusion_log_password_complexity_set` | `event_type` = `security_event`
`security_event_tag` = `password_complexity_set` | `password_complexity_set` | An administrator configured a minimum lockscreen password complexity requirement (SecurityLog tag 210017) | | `intrusion_log_password_expiration_set` | `event_type` = `security_event`
`security_event_tag` = `password_expiration_set` | `password_expiration_set` | An administrator configured a lockscreen password expiration policy (SecurityLog tag 210016) | | `intrusion_log_password_history_length_set` | `event_type` = `security_event`
`security_event_tag` = `password_history_length_set` | `password_history_length_set` | An administrator configured how many previous passwords are remembered to prevent reuse (SecurityLog tag 210018) | | `intrusion_log_remote_lock` | `event_type` = `security_event`
`security_event_tag` = `remote_lock` | `remote_lock` | An administrator remotely locked the device or a work profile (SecurityLog tag 210022) | | `intrusion_log_user_restriction_added` | `event_type` = `security_event`
`security_event_tag` = `user_restriction_added` | `user_restriction_added` | An administrator added a restriction on what the user is allowed to do on the device (SecurityLog tag 210027) | | `intrusion_log_user_restriction_removed` | `event_type` = `security_event`
`security_event_tag` = `user_restriction_removed` | `user_restriction_removed` | An administrator removed a previously-set user restriction (SecurityLog tag 210028) | | `intrusion_log_wifi_connection` | `event_type` = `security_event`
`security_event_tag` = `wifi_connection` | `wifi_connection` | The device attempted to connect to a Wi-Fi network under management policy (SecurityLog tag 210037) | | `intrusion_log_wifi_disconnection` | `event_type` = `security_event`
`security_event_tag` = `wifi_disconnection` | `wifi_disconnection` | The device disconnected from a managed Wi-Fi network (SecurityLog tag 210038) | | `intrusion_log_wipe_failure` | `event_type` = `security_event`
`security_event_tag` = `wipe_failure` | `wipe_failure` | A device or user-data wipe was attempted and failed (SecurityLog tag 210023) | ## Apple Biome rules (58) Stream names and field semantics sourced from iLEAPP's `biome*.py` artifact modules (Apache-2.0). The SEGB v2 envelope format decoded underneath these streams is a Rust port of [CCL Forensics' ccl_segb project](https://github.com/cclgroupltd/ccl-segb) (MIT) — see [docs/design/biome-rule-pack-research.md](design/biome-rule-pack-research.md) for the full sourcing and scope rationale, including why SEGB v1 isn't supported yet. Every rule matches `sourcetype = "biome"`; most match on the normalized `stream` field alone (Tier 1 — no payload decoding needed), a handful also match on a stream-conditioned normalized key like `bundle_id`/`app_id` (Tier 2 — see [supported-sources.md](supported-sources.md#biome-segb)). | Rule name | Match | Tag | Description | |---|---|---|---| | `biome_airplane_mode_off_event` | `stream` = `Device.Wireless.AirplaneMode`
`state_raw` = `0` | `airplane_mode_off_event` | Airplane Mode turned off | | `biome_airplane_mode_on_event` | `stream` = `Device.Wireless.AirplaneMode`
`state_raw` = `1` | `airplane_mode_on_event` | Airplane Mode turned on | | `biome_app_activity` | `stream` = `App.Activity` | `app_activity` | Biome stream present: App.Activity (application activity event) | | `biome_app_infocus` | `stream` = `App.InFocus` | `app_in_focus` | Biome stream present: App.InFocus (application brought into foreground focus) | | `biome_app_installation` | `stream` = `App.Installation` | `app_installed` | Biome stream present: App.Installation (application installed) | | `biome_app_intent` | `stream` = `App.Intent` | `app_intent_recorded` | Biome stream present: App.Intent (an app intent/action was recorded) | | `biome_app_intent_instagram` | `stream` = `App.Intent`
`app_id` = `com.instagram.android` | `app_intent_instagram` | An Instagram app intent/action was recorded | | `biome_app_intent_safari` | `stream` = `App.Intent`
`app_id` = `com.apple.mobilesafari` | `app_intent_safari` | A Safari app intent/action was recorded | | `biome_app_intent_whatsapp` | `stream` = `App.Intent`
`app_id` = `com.whatsapp` | `app_intent_whatsapp` | A WhatsApp app intent/action was recorded | | `biome_carplay_connected` | `stream` = `CarPlay.Connected` | `carplay_connected` | Biome stream present: CarPlay.Connected (CarPlay connection state change) | | `biome_carplay_connected_event` | `stream` = `CarPlay.Connected`
`state_raw` = `1` | `carplay_connected_event` | CarPlay connected | | `biome_carplay_disconnected_event` | `stream` = `CarPlay.Connected`
`state_raw` = `0` | `carplay_disconnected_event` | CarPlay disconnected | | `biome_cellular_data_disabled_event` | `stream` = `Device.Wireless.CellularDataEnabled`
`state_raw` = `0` | `cellular_data_disabled_event` | Cellular data disabled | | `biome_cellular_data_enabled_event` | `stream` = `Device.Wireless.CellularDataEnabled`
`state_raw` = `1` | `cellular_data_enabled_event` | Cellular data enabled | | `biome_clock_alarm` | `stream` = `Clock.Alarm` | `clock_alarm` | Biome stream present: Clock.Alarm (an alarm was set, fired, or dismissed) | | `biome_deleted` | `entry_state` = `deleted` | `deleted` | A Biome/SEGB record marked deleted (entry_state = "deleted") | | `biome_device_keybag_locked_event` | `stream` = `Device.KeybagLocked`
`state_raw` = `1` | `device_keybag_locked_event` | Device keybag (encryption keys) locked | | `biome_device_keybag_unlocked_event` | `stream` = `Device.KeybagLocked`
`state_raw` = `0` | `device_keybag_unlocked_event` | Device keybag (encryption keys) unlocked | | `biome_device_keybaglocked` | `stream` = `Device.KeybagLocked` | `keybag_locked` | Biome stream present: Device.KeybagLocked (device keybag (encryption keys) locked state) | | `biome_device_plugged_in_event` | `stream` = `Device.Power.PluggedIn`
`state_raw` = `1` | `device_plugged_in_event` | Device plugged in to power | | `biome_device_power_batterylevel` | `stream` = `Device.Power.BatteryLevel` | `battery_level` | Biome stream present: Device.Power.BatteryLevel (battery level change) | | `biome_device_power_lowpowermode` | `stream` = `Device.Power.LowPowerMode` | `low_power_mode` | Biome stream present: Device.Power.LowPowerMode (Low Power Mode toggled) | | `biome_device_power_pluggedin` | `stream` = `Device.Power.PluggedIn` | `power_plugged_in` | Biome stream present: Device.Power.PluggedIn (device plugged in/unplugged) | | `biome_device_screen_locked_event` | `stream` = `Device.ScreenLocked`
`state_raw` = `1` | `device_screen_locked_event` | Device screen locked | | `biome_device_screen_unlocked_event` | `stream` = `Device.ScreenLocked`
`state_raw` = `0` | `device_screen_unlocked_event` | Device screen unlocked | | `biome_device_screenlocked` | `stream` = `Device.ScreenLocked` | `screen_locked` | Biome stream present: Device.ScreenLocked (device screen locked/unlocked) | | `biome_device_thermals_batterytemperature` | `stream` = `Device.Thermals.BatteryTemperature` | `battery_temperature` | Biome stream present: Device.Thermals.BatteryTemperature (battery temperature reading) | | `biome_device_timezone` | `stream` = `Device.TimeZone` | `timezone_change` | Biome stream present: Device.TimeZone (device time zone changed) | | `biome_device_unplugged_event` | `stream` = `Device.Power.PluggedIn`
`state_raw` = `0` | `device_unplugged_event` | Device unplugged from power | | `biome_device_wireless_airplanemode` | `stream` = `Device.Wireless.AirplaneMode` | `airplane_mode` | Biome stream present: Device.Wireless.AirplaneMode (Airplane Mode toggled) | | `biome_device_wireless_bluetooth` | `stream` = `Device.Wireless.Bluetooth` | `bluetooth_activity` | Biome stream present: Device.Wireless.Bluetooth (Bluetooth radio state change) | | `biome_device_wireless_cellulardataenabled` | `stream` = `Device.Wireless.CellularDataEnabled` | `cellular_toggle` | Biome stream present: Device.Wireless.CellularDataEnabled (cellular data enabled/disabled) | | `biome_device_wireless_wifi` | `stream` = `Device.Wireless.WiFi` | `wifi_activity` | Biome stream present: Device.Wireless.WiFi (Wi-Fi radio state change) | | `biome_dkevent_app_infocus` | `stream` = `_DKEvent.App.InFocus` | `app_in_focus` | Biome stream present: _DKEvent.App.InFocus (application brought into foreground focus) | | `biome_dkevent_app_locationactivity` | `stream` = `_DKEvent.App.LocationActivity` | `app_location_activity` | Biome stream present: _DKEvent.App.LocationActivity (an app's location-related activity) | | `biome_dkevent_device_islockedimputed` | `stream` = `_DKEvent.Device.IsLockedImputed` | `device_locked_imputed` | Biome stream present: _DKEvent.Device.IsLockedImputed (inferred device lock state change) | | `biome_dkevent_safari_history` | `stream` = `_DKEvent.Safari.History` | `safari_activity` | Biome stream present: _DKEvent.Safari.History (Safari browsing history event) | | `biome_dkevent_wifi_connection` | `stream` = `_DKEvent.Wifi.Connection` | `wifi_connection` | Biome stream present: _DKEvent.Wifi.Connection (Wi-Fi connection event) | | `biome_emoji_engagement` | `stream` = `Emoji.Engagement` | `emoji_engagement` | Biome stream present: Emoji.Engagement (emoji usage/engagement) | | `biome_keyboard_tokenfrequency` | `stream` = `Keyboard.TokenFrequency` | `keyboard_activity_recorded` | Biome stream present: Keyboard.TokenFrequency (keyboard typed-token frequency recorded) | | `biome_location_visit` | `stream` = `Location.Visit` | `location_visit` | Biome stream present: Location.Visit (a significant location visit) | | `biome_low_power_mode_off_event` | `stream` = `Device.Power.LowPowerMode`
`state_raw` = `0` | `low_power_mode_off_event` | Low Power Mode turned off | | `biome_low_power_mode_on_event` | `stream` = `Device.Power.LowPowerMode`
`state_raw` = `1` | `low_power_mode_on_event` | Low Power Mode turned on | | `biome_messages_read` | `stream` = `Messages.Read` | `message_read` | Biome stream present: Messages.Read (a message was read) | | `biome_notification` | `stream` = `Notification` | `notification_activity` | Biome stream present: Notification (a notification was posted) | | `biome_notification_usage` | `stream` = `Notification.Usage` | `notification_activity` | Biome stream present: Notification.Usage (notification usage/interaction) | | `biome_proactiveharvesting_mail` | `stream` = `ProactiveHarvesting.Mail` | `harvested_mail` | Biome stream present: ProactiveHarvesting.Mail (mail content proactively harvested for Siri suggestions) | | `biome_proactiveharvesting_messages` | `stream` = `ProactiveHarvesting.Messages` | `harvested_communication` | Biome stream present: ProactiveHarvesting.Messages (message content proactively harvested for Siri suggestions) | | `biome_safari_navigations` | `stream` = `Safari.Navigations` | `safari_activity` | Biome stream present: Safari.Navigations (Safari page navigation) | | `biome_screentime_appusage` | `stream` = `ScreenTime.AppUsage` | `app_usage_recorded` | Biome stream present: ScreenTime.AppUsage (Screen Time recorded app usage) | | `biome_screentime_messages_usage` | `stream` = `ScreenTime.AppUsage`
`bundle_id` = `com.apple.MobileSMS` | `screentime_messages_usage` | Screen Time usage of Messages was recorded | | `biome_screentime_safari_usage` | `stream` = `ScreenTime.AppUsage`
`bundle_id` = `com.apple.mobilesafari` | `screentime_safari_usage` | Screen Time usage of Safari was recorded | | `biome_siri_remembers_audiohistory` | `stream` = `Siri.Remembers.AudioHistory` | `siri_remembers_activity` | Biome stream present: Siri.Remembers.AudioHistory (Siri Remembers recorded audio history) | | `biome_siri_remembers_callhistory` | `stream` = `Siri.Remembers.CallHistory` | `siri_remembers_activity` | Biome stream present: Siri.Remembers.CallHistory (Siri Remembers recorded call history) | | `biome_siri_remembers_messagehistory` | `stream` = `Siri.Remembers.MessageHistory` | `siri_remembers_activity` | Biome stream present: Siri.Remembers.MessageHistory (Siri Remembers recorded message history) | | `biome_wallet_transaction` | `stream` = `Wallet.Transaction` | `wallet_transaction` | Biome stream present: Wallet.Transaction (an Apple Wallet transaction) | | `biome_wifi_connected_event` | `stream` = `Device.Wireless.WiFi`
`state_raw` = `1` | `wifi_connected_event` | Wi-Fi connected | | `biome_wifi_disconnected_event` | `stream` = `Device.Wireless.WiFi`
`state_raw` = `0` | `wifi_disconnected_event` | Wi-Fi disconnected |