Safari History Database Tags Can Reveal Users’ Browsing Themes in Forensic Investigations
Safari History.db stores Wikidata-linked topic tags that can reveal browsing themes in macOS investigations.
Safari’s History.db, at ~/Library/Safari/History.db, can attach automatically generated topic tags to visited pages through the history_tags and history_items_to_tags tables. Tag identifiers typically start with “Q” and map to Wikidata concepts; not every page is tagged, and the behavior has been observed since at least 2021. Investigators must convert Cocoa timestamps by adding 978307200 seconds, and labels can mislead—for example “APT” may mean the Advanced Package Tool (Q230724) rather than an intrusion. Residual tags can remain after related history records are deleted, and mac_apt now parses them.
- History.db maps history_tags to visited URLs through history_items_to_tags.
- Tag identifiers beginning with Q correspond to Wikidata entities, not keywords.
- Timestamps use the Mac epoch and need 978307200 added for Unix time.
- Orphaned tags with a zero item count can survive history deletion.
- The mac_apt framework now parses Safari tags for triage and disk images.
Full article637 words · extracted from gbhackers.com · click to collapse
Safari’s History database contains a lesser-known tagging artifact that can help investigators infer a user’s browsing themes.
While this feature is not definitive evidence of intent, when correlated with URLs, visit times, cache data, downloads, and network telemetry, it can provide useful context for macOS forensic timelines.
Safari History Tags and Browsing Themes
Safari’s History.db database may contain automatically generated topic labels for webpages a user has visited, offering an additional investigative lead for digital forensic and incident response teams.
Located at ~/Library/Safari/History.db, this database is primarily known for storing browsing URLs, page titles, visit timestamps, redirects, and visit counts.
However, researchers have noted that Safari can also associate some history entries with descriptive tags that appear to represent an inferred subject or theme.

Two SQLite tables are central to this functionality: history_tags and history_items_to_tags. The history_tags table stores metadata for each tag, including its human-readable title, identifier, modification timestamp, and item count.
The history_items_to_tags table serves as the relationship mapping between a tag and the corresponding record in history_items, which contains the visited URL. This lets examiners link Safari’s inferred thematic classifications to specific browsing records, rather than reviewing isolated tag values.
In the history_tags table, the title field contains the tag label, while the identifier typically begins with “Q.” These identifiers correspond to Wikidata entities, suggesting that Safari associates a webpage with a broader structured concept rather than simply extracting a keyword from its title.
The specific mechanism that Safari uses to determine whether a webpage should receive a tag, and which label it should receive, is not publicly clear. Not every visited page is tagged, and available observations indicate that this feature has existed in Safari history databases since at least 2021.
Forensic analysts must account for Apple’s Cocoa timestamp format. Safari stores relevant timestamps as Mac absolute time, which is measured from the epoch beginning on January 1, 2001.
Analysts can convert those values to Unix time by adding 978307200 seconds before using SQLite’s datetime() function. A joined query can extract the visit title, URL, converted visit time, tag title, tag identifier, and the tag’s modification time. This produces a richer browsing timeline than standard URL history alone.

Tags can reveal patterns that may otherwise be difficult to discern across thousands of URLs. For instance, an investigation involving suspicious software-download activity might uncover a tag such as “APT.”
However, that label should not immediately be interpreted as an advanced persistent threat; the Wikidata entity Q230724 refers to the Advanced Package Tool, a Linux package-management utility.
In one observed case, a phishing site impersonating Homebrew received the “APT” tag, while the legitimate Homebrew site did not. This example underscores the importance of correlating tag interpretations with the URL, webpage content, certificate data, DNS logs, and other endpoint evidence.
Investigators may also encounter residual tags with an item count of zero. While Safari history deletion appears capable of removing associated records, testing has revealed that older entries can remain in history_tags without active links to history_items.
Though these orphaned entries are not a standalone recovery mechanism, they may provide limited insight into historic browsing themes after related records were deleted. Database triggers increment and decrement the item count as tag relationships are added or removed, making this field relevant when assessing tag persistence.
The open-source macOS and iOS forensic framework mac_apt has added support for parsing Safari tags, presenting tags without item counts as TAGGED. This enhancement makes the artifact easier to include in routine endpoint triage and full-disk-image analyses.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.