bputil
executablemacOS192.5 KBx86_64, arm64
System boot configuration utility — manages firmware settings and authentication
Modifies system NVRAM variables that control macOS boot behavior, firmware options, and hardware configuration. Authenticates operations through Touch ID or Face ID to gate privileged changes. Communicates with 7 network endpoints, likely for firmware validation or telemetry. Interfaces with 28 bundle identifiers across the system, indicating coordination with multiple system services and applications that depend on boot-level settings.AI
Fingerprint
- Platform
- macOS
- Type
- executable
- Arch
- x86_64, arm64
- Min OS
- 26.1.0
- SDK
- 26.1.0
- File Size
- 192.5 KB
- UUID
- 02146AF4-FB4C-30B3-9AC4-18823DF98BB7
- Analyzed
- 2026-04-07T05:21:12Z
- CDHash
- 33562a3bcaf8d0ad399b938ac9a430555f31e1214ee7eb2d9a1def82db0fabaf
Capabilities
StorageRead and write system NVRAM variables
com.apple.private.iokit.system-nvram-allow[object Object]HardwareDirect hardware/driver communication
/System/Library/Frameworks/IOKit.framework/Versions/A/IOKitSecurityTouch ID / Face ID / password auth
/System/Library/Frameworks/LocalAuthentication.framework/Versions/A/LocalAuthenticationFrameworks9
Entitlements11
Interesting Strings
Bundle IDs(28)
File Paths(11)
%@/var/db/AdminUserRecoveryInfo.plist/AppleInternal/Library/BuildRoots/4~B_5OugDsqWgwqJFU9f0MpruJG7Hd0j3Fa82inzY/Library/Caches/com.apple.xbs/Sources/BootPolicy_executables/bputil/bputil.m/AppleInternal/Library/BuildRoots/4~B_5OugDsqWgwqJFU9f0MpruJG7Hd0j3Fa82inzY/Library/Caches/com.apple.xbs/Sources/BootPolicy_executables/shared/image4.c/AppleInternal/Library/BuildRoots/4~B_wCugD1GT6JPDmhh1RrUK5pccLqhjehz9nqD_o/Library/Caches/com.apple.xbs/Sources/AppleCredentialManager_ClientLibs/ACMLib/ACMLib.c/AppleInternal/Library/BuildRoots/4~B_wCugD1GT6JPDmhh1RrUK5pccLqhjehz9nqD_o/Library/Caches/com.apple.xbs/Sources/AppleCredentialManager_ClientLibs/common/LibCall.c
Network Surface
Networking Frameworks
DNA Capability Vector
Location
0
Keychain
0
Network
0
Storage
1
Hardware
1
IPC
0
Analytics
0
Security
1
System
0
Behavioral Profile
URL Endpoints
4
Telemetry Strings
0
File Paths
11
Bundle IDs
28
IOKit Constants
0
Library Functions
0
Structural HashesSHA-256
Static Libraries0 / 194 functions identified
Functions(194)
0x100000be8sub_100000be8
0x100000c38sub_100000c38
0x100000c40sub_100000c40
0x100000ca4sub_100000ca4
0x100000d80sub_100000d80
0x100000fc4sub_100000fc4
0x100000fd8sub_100000fd8
0x100000ff4sub_100000ff4
0x100001000sub_100001000
0x100001020sub_100001020
0x100001030sub_100001030
0x100001060sub_100001060
0x100001070sub_100001070
0x10000107csub_10000107c
0x100001094sub_100001094
0x1000010b0sub_1000010b0
0x1000010c8sub_1000010c8
0x1000010e8sub_1000010e8
0x100001110sub_100001110
0x100001384sub_100001384
Imports142 symbols from 9 dylibs
Exports1
_mh_execute_header0x0