Glossary
TCC database (TCC.db)
The SQLite databases where macOS records privacy permissions such as Full Disk Access, camera or screen recording.
TCC (Transparency, Consent and Control) is the macOS framework that decides which apps may use protected resources: Full Disk Access, the camera, the microphone, screen recording, accessibility, contacts and more. Its decisions are stored in SQLite databases named TCC.db: a system-wide one at /Library/Application Support/com.apple.TCC/TCC.db, which holds Full Disk Access among others, and a per-user one under ~/Library/Application Support/com.apple.TCC/. System Integrity Protection guards both; reading them needs Full Disk Access.
Why it matters in investigations
Many attacks on macOS need a privacy permission first. A tool that wants to read mail, browser data or other users' files needs Full Disk Access; one that watches the screen needs screen recording. A change in TCC.db right before sensitive activity is therefore a strong lead.
FSEvents records that the database files were written, including their -wal and -shm companions, but never their content. It tells you that permissions changed, and in which order relative to other events, not which app got which service. The FSEvents Parser raises a finding for writes to either database and says whether the system or a user database changed. The database rows complete the picture: the access table lists the service, the client (app) and a last_modified time for each entry.
Example
In the synthetic sample, within the log window 10:09:55 to 10:23:18 UTC:
Users/dana.whitlock/Library/Preferences/com.apple.systempreferences.plist:Modified;FileLibrary/Application Support/com.apple.TCC/TCC.db-wal,TCC.dbandTCC.db-shm:Modified;File
This is consistent with someone granting Terminal Full Disk Access in System Settings. The kTCCServiceSystemPolicyAllFiles row for Terminal, with its own timestamp, would confirm it.
Related terms
Spot TCC writes in the FSEvents Parser, and read the full sequence in the Mac exfiltration walkthrough.