remoted
executablemacOS1.0 MBx86_64, arm64
Keychain management service — handles encryption keys and secure credential storage
Manages system keychain operations including encryption key access, Secure Enclave integration, and credential storage. Reads and writes keychain items, accesses sealed keys through the Secure Enclave, and enforces keychain access group controls. Communicates via NWConnection networking and exposes 7 XPC services for client applications to request keychain operations. Runs as a hardened runtime process with direct hardware communication capabilities and exception-based file path access.AI
Fingerprint
- Platform
- macOS
- Type
- executable
- Arch
- x86_64, arm64
- Min OS
- 26.1.0
- SDK
- 26.1.0
- File Size
- 1.0 MB
- UUID
- 611812C8-697A-3684-9BE7-E407F95EE095
- Analyzed
- 2026-04-09T10:01:22Z
- CDHash
- deac6988026f87ae362ea1833439f365e28d8aded392befeab8d4d706062470b
Capabilities
KeychainHardware key storage (Secure Enclave)
/System/Library/PrivateFrameworks/AppleKeyStore.framework/Versions/A/AppleKeyStoreNetworkModern networking framework (NWConnection)
/System/Library/Frameworks/Network.framework/Versions/A/NetworkStorageException: access additional file paths
com.apple.security.exception.files.absolute-path.read-onlyHardwareDirect hardware/driver communication
/System/Library/Frameworks/IOKit.framework/Versions/A/IOKitSecurityKeychain, certificates, code signing
/System/Library/Frameworks/Security.framework/Versions/A/SecurityFrameworks20
Entitlements13
Interesting Strings
Bundle IDs(66)
File Paths(21)
/AppleInternal/Library/BuildRoots/4~B_wuugAnEHDZhrR7WrTsUIwosBSN4MtSJCxO1mI/Library/Caches/com.apple.xbs/Sources/RemoteServiceDiscovery_executables/remoted/modules/identity.m/System/Library/CoreServices/RestoreVersion.plist/System/Library/Frameworks/CoreFoundation.framework/Versions/A/CoreFoundation/System/Library/Frameworks/Foundation.framework/Versions/C/Foundation/System/Library/Frameworks/IOKit.framework/Versions/A/IOKit
iokit_constants(2)
telemetry(1)
Network Surface
Networking Frameworks
Endpoints(10)
DNA Capability Vector
Location
0
Keychain
5
Network
1
Storage
1
Hardware
1
IPC
0
Analytics
0
Security
2
System
0
Behavioral Profile
URL Endpoints
5
Telemetry Strings
1
File Paths
21
Bundle IDs
66
IOKit Constants
2
Library Functions
0
Structural HashesSHA-256
Static Libraries0 / 1486 functions identified
Functions(1486)
0x1000014c8-[RSDEventRegistration initWithToken:name:]
0x100001534-[RSDEventRegistration startBrowsing:]
0x100001668sub_100001668
0x1000016e4sub_1000016e4
0x100001720sub_100001720
0x10000175c-[RSDEventRegistration cancelBrowsing]
0x10000180c-[RSDEventRegistration fire:]
0x100001984-[RSDEventRegistration dealloc]
0x1000019d0-[RSDEventRegistration token]
0x1000019d8-[RSDEventRegistration setToken:]
0x1000019e0-[RSDEventRegistration name]
0x1000019e8-[RSDEventRegistration setName:]
0x1000019f0-[RSDEventRegistration dontRestartBrowse]
0x1000019f8-[RSDEventRegistration setDontRestartBrowse:]
0x100001a00-[RSDEventRegistration browser]
0x100001a08-[RSDEventRegistration setBrowser:]
0x100001a14-[RSDEventRegistration .cxx_destruct]
0x100001a20sub_100001a20
0x100001b08sub_100001b08
0x100001e14sub_100001e14
Imports474 symbols from 19 dylibs
Exports26
BlockedYonkersSPKI0x665c8
CTOidAppleImg4Manifest0x4fed0
CTParseCertificateSet0x3a55c
X509CertificateParse0x3c2e0
X509CertificateParseImplicit0x3a688
X509CertificateParseWithExtension0x3c1bc
X509PolicyCheckForBlockedKeys0x3a2cc
_mh_execute_header0x0
ccder_blob_check_null0x3a4f8
ccder_blob_decode_AlgorithmIdentifierNULL0x3a364
compare_octet_string0x3a31c
compare_octet_string_raw0x3a344
sntp_calc_delay0x39f94
sntp_calc_offset0x39eec
sntp_client_process_response0x3a184
sntp_datestamp_from_timespec0x39eac
sntp_datestamp_to_nsec0x39e44
sntp_datestamp_to_timespec0x39e68
sntp_header_ntoh0x3a0a0
sntp_packet_ntoh0x3a028
sntp_server_respond0x3a0f4
sntp_shortstamp_ntoh0x39e10
sntp_timestamp_from_datestamp0x39e38
sntp_timestamp_hton0x39e18
sntp_timestamp_ntoh0x39e20
sntp_timestamp_to_datestamp0x39e28