applekeystored
executablemacOS696.9 KBx86_64, arm64
Cryptographic key management — handles encryption keys, certificates, and hardware security token operations
Manages cryptographic keys and certificates stored in the Secure Enclave and device key bag, providing secure storage and access controls. Communicates with hardware security tokens and encryption drivers for key operations. Exposes three XPC services for system components to request key generation, signing, and verification operations. Evaluates feature flags to conditionally enable functionality and reports telemetry to Apple endpoints. Implements code signing validation and keychain integration to authenticate operations.AI
Fingerprint
- Platform
- macOS
- Type
- executable
- Arch
- x86_64, arm64
- Min OS
- 26.1.0
- SDK
- 26.1.0
- File Size
- 696.9 KB
- UUID
- 86E54FCC-EC3B-3A3A-85E7-457EF73F923D
- Analyzed
- 2026-04-09T09:41:58Z
- CDHash
- f976701335a724da0d6ff894214b5c645944dd70aaa57943dd3b33493c2b004d
Capabilities
KeychainDevice key bag (encryption keys)
/System/Library/PrivateFrameworks/MobileKeyBag.framework/Versions/A/MobileKeyBagKeychainHardware key storage (Secure Enclave)
/System/Library/PrivateFrameworks/AppleKeyStore.framework/Versions/A/AppleKeyStoreHardwareDirect hardware/driver communication
/System/Library/Frameworks/IOKit.framework/Versions/A/IOKitSecurityKeychain, certificates, code signing
/System/Library/Frameworks/Security.framework/Versions/A/SecuritySystemFeature flag evaluation
/System/Library/PrivateFrameworks/FeatureFlags.framework/Versions/A/FeatureFlagsFrameworks23
MobileActivationMacOSAPFSIOKitCoreFoundationlibodaccesstoken.dyliblibbsm.0.dylibMobileKeyBagAppleKeyStoreFoundationlibobjc.A.dyliblibSystem.B.dylibSecurityArgumentParserInternalFeatureFlagslibswiftCore.dyliblibswiftCoreFoundation.dylib(weak)libswiftDispatch.dylib(weak)libswiftIOKit.dylib(weak)libswiftOSLog.dylib(weak)libswiftObjectiveC.dylib(weak)libswiftXPC.dylib(weak)libswift_Builtin_float.dylib(weak)libswiftos.dylib
Entitlements12
Interesting Strings
Bundle IDs(43)
File Paths(87)
/AppleInternal/Library/BuildRoots/4~B_wCugD1GT6JPDmhh1RrUK5pccLqhjehz9nqD_o/Library/Caches/com.apple.xbs/Sources/AppleCredentialManager_ClientLibs/ACMLib/ACMLib.c/AppleInternal/Library/BuildRoots/4~B_wCugD1GT6JPDmhh1RrUK5pccLqhjehz9nqD_o/Library/Caches/com.apple.xbs/Sources/AppleCredentialManager_ClientLibs/common/CommonUtil.c/AppleInternal/Library/BuildRoots/4~B_wCugD1GT6JPDmhh1RrUK5pccLqhjehz9nqD_o/Library/Caches/com.apple.xbs/Sources/AppleCredentialManager_ClientLibs/common/LibCall.c/AppleInternal/Library/BuildRoots/4~B_wCugD1GT6JPDmhh1RrUK5pccLqhjehz9nqD_o/Library/Caches/com.apple.xbs/Sources/AppleCredentialManager_ClientLibs/common/LibCallBlock.c/AppleInternal/Library/BuildRoots/4~B_wCugD1GT6JPDmhh1RrUK5pccLqhjehz9nqD_o/Library/Caches/com.apple.xbs/Sources/AppleCredentialManager_ClientLibs/common/LibSerialization.c
telemetry(1)
Network Surface
Networking Frameworks
DNA Capability Vector
Location
0
Keychain
2
Network
0
Storage
0
Hardware
1
IPC
0
Analytics
0
Security
1
System
1
Behavioral Profile
URL Endpoints
4
Telemetry Strings
1
File Paths
87
Bundle IDs
43
IOKit Constants
0
Library Functions
0
Structural HashesSHA-256
Static Libraries0 / 1061 functions identified
Functions(1061)
0x100001300sub_100001300
0x10000201csub_10000201c
0x100002090sub_100002090
0x1000020b4sub_1000020b4
0x1000020d0sub_1000020d0
0x10000216csub_10000216c
0x100002178sub_100002178
0x100002184sub_100002184
0x100002190sub_100002190
0x1000021e0sub_1000021e0
0x1000021e4sub_1000021e4
0x100002258sub_100002258
0x1000022a4sub_1000022a4
0x1000022e4sub_1000022e4
0x100002338sub_100002338
0x100002368sub_100002368
0x100002378sub_100002378
0x10000239csub_10000239c
0x10000243csub_10000243c
0x100002458sub_100002458
Imports367 symbols from 16 dylibs
Exports1
_mh_execute_header0x0