keybagd

JSON
executablemacOS377.2 KBx86_64, arm64

Cryptographic key management — stores, manages, and signs with hardware-backed keys

Manages cryptographic keys stored in the Secure Enclave and system keychain, enabling secure signing and encryption operations. Handles certificate storage, code signing workflows, and key lifecycle management. Submits analytics about key operations and system state to Apple via unified analytics endpoints. Communicates with other system components through 7 XPC services to provide keychain and signing capabilities across the platform.AI

Fingerprint

Platform
macOS
Type
executable
Arch
x86_64, arm64
Min OS
26.1.0
SDK
26.1.0
File Size
377.2 KB
UUID
46D2AD52-EFF3-3715-81C4-7B304164D357
Analyzed
2026-04-09T09:53:03Z
CDHash
ec33bcdaa814de1ff8c1867ea6f95eece7c4f63a74c7f550b69c47b886ac2589

Interesting Strings

telemetry(39)

Network Surface

Networking Frameworks

API Usage

DNA Capability Vector

Location
0
Keychain
1
Network
0
Storage
0
Hardware
1
IPC
0
Analytics
1
Security
1
System
0

Behavioral Profile

URL Endpoints
4
Telemetry Strings
39
File Paths
28
Bundle IDs
85
IOKit Constants
0
Library Functions
0

Structural HashesSHA-256

Static Libraries0 / 324 functions identified

Functions(324)

0x100001158sub_100001158
0x100001254sub_100001254
0x100001360sub_100001360
0x1000014c8sub_1000014c8
0x1000015a8sub_1000015a8
0x1000016d4sub_1000016d4
0x1000018a8sub_1000018a8
0x1000019b8sub_1000019b8
0x1000019c8sub_1000019c8
0x1000019e4sub_1000019e4
0x1000019f0sub_1000019f0
0x100001a40sub_100001a40
0x100001a84sub_100001a84
0x100001b3csub_100001b3c
0x100001be8sub_100001be8
0x100001cfcsub_100001cfc
0x100002074sub_100002074
0x100002084sub_100002084
0x100002090sub_100002090
0x1000020c4sub_1000020c4

Imports270 symbols from 12 dylibs

Exports1

_mh_execute_header0x0