Safari’s History database contains a lesser-known tagging artifact that can help investigators infer a user’s browsing themes.
While this feature is not definitive evidence of intent, when correlated with URLs, visit times, cache data, downloads, and network telemetry, it can provide useful context for macOS forensic timelines.
Safari History Tags and Browsing Themes
Safari’s History.db database may contain automatically generated topic labels for webpages a user has visited, offering an additional investigative lead for digital forensic and incident response teams.
Located at ~/Library/Safari/History.db, this database is primarily known for storing browsing URLs, page titles, visit timestamps, redirects, and visit counts.
However, researchers have noted that Safari can also associate some history entries with descriptive tags that appear to represent an inferred subject or theme.
Two SQLite tables are central to this functionality: history_tags and history_items_to_tags. The history_tags table stores metadata for each tag, including its human-readable title, identifier, modification timestamp, and item count.
The history_items_to_tags table serves as the relationship mapping between a tag and the corresponding record in history_items, which contains the visited URL. This lets examiners link Safari’s inferred thematic classifications to specific browsing records, rather than reviewing isolated tag values.
In the history_tags table, the title field contains the tag label, while the identifier typically begins with “Q.” These identifiers correspond to Wikidata entities, suggesting that Safari associates a webpage with a broader structured concept rather than simply extracting a keyword from its title.
The specific mechanism that Safari uses to determine whether a webpage should receive a tag, and which label it should receive, is not publicly clear. Not every visited page is tagged, and available observations indicate that this feature has existed in Safari history databases since at least 2021.
Forensic analysts must account for Apple’s Cocoa timestamp format. Safari stores relevant timestamps as Mac absolute time, which is measured from the epoch beginning on January 1, 2001.
Analysts can convert those values to Unix time by adding 978307200 seconds before using SQLite’s datetime() function. A joined query can extract the visit title, URL, converted visit time, tag title, tag identifier, and the tag’s modification time. This produces a richer browsing timeline than standard URL history alone.

Tags can reveal patterns that may otherwise be difficult to discern across thousands of URLs. For instance, an investigation involving suspicious software-download activity might uncover a tag such as “APT.”
However, that label should not immediately be interpreted as an advanced persistent threat; the Wikidata entity Q230724 refers to the Advanced Package Tool, a Linux package-management utility.
In one observed case, a phishing site impersonating Homebrew received the “APT” tag, while the legitimate Homebrew site did not. This example underscores the importance of correlating tag interpretations with the URL, webpage content, certificate data, DNS logs, and other endpoint evidence.
Investigators may also encounter residual tags with an item count of zero. While Safari history deletion appears capable of removing associated records, testing has revealed that older entries can remain in history_tags without active links to history_items.
Though these orphaned entries are not a standalone recovery mechanism, they may provide limited insight into historic browsing themes after related records were deleted. Database triggers increment and decrement the item count as tag relationships are added or removed, making this field relevant when assessing tag persistence.
The open-source macOS and iOS forensic framework mac_apt has added support for parsing Safari tags, presenting tags without item counts as TAGGED. This enhancement makes the artifact easier to include in routine endpoint triage and full-disk-image analyses.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC

