kernelmanagerd
executablemacOS3.8 MBx86_64, arm64
Security enclave manager — handles biometric authentication and secure key storage
Manages authentication operations for Touch ID and Face ID, interfacing with the Secure Enclave to store and validate biometric templates and cryptographic keys. Handles keychain operations, certificate validation, and code signing verification. Writes system NVRAM variables and accesses private storage areas for secure credential management. Submits analytics to Apple and communicates with 23 network endpoints for service connectivity. Runs with elevated privileges and manages process lifecycle for related security operations.AI
Fingerprint
- Platform
- macOS
- Type
- executable
- Arch
- x86_64, arm64
- Min OS
- 26.1.0
- SDK
- 26.1.0
- File Size
- 3.8 MB
- UUID
- C2622C27-CC52-31EA-B8CF-BB4D9DC3D4A3
- Analyzed
- 2026-04-09T09:52:56Z
- CDHash
- 86035af46272e763de0d880d62abd9639b070a110d3d2f9aa912d32fc9f87d12
Capabilities
KeychainHardware key storage (Secure Enclave)
/System/Library/PrivateFrameworks/AppleKeyStore.framework/Versions/A/AppleKeyStoreStorageRead and write system NVRAM variables
com.apple.private.iokit.system-nvram-allow[object Object]StoragePrivate storage area access
com.apple.private.security.storage.SystemExtensionManagement[object Object]HardwareDirect hardware/driver communication
/System/Library/Frameworks/IOKit.framework/Versions/A/IOKitAnalyticsApple unified analytics submission
/System/Library/PrivateFrameworks/CoreAnalytics.framework/Versions/A/CoreAnalyticsSecurityTouch ID / Face ID / password auth
/System/Library/Frameworks/LocalAuthentication.framework/Versions/A/LocalAuthenticationSecurityKeychain, certificates, code signing
/System/Library/Frameworks/Security.framework/Versions/A/SecuritySystemProcess lifecycle management
/System/Library/PrivateFrameworks/RunningBoardServices.framework/Versions/A/RunningBoardServicesFrameworks41
libswiftIOKit.dylib(weak)LocalAuthentication(weak)RunningBoardServices(weak)DiskImages2(weak)libxcselect.dylib(weak)AppServerSupportAppleKeyStore(weak)libcompression.dyliblibamsupport.dylibCoreServices(weak)DiskManagement(weak)libbootpolicy.dylib(weak)SystemExtensions(weak)libKernelCollectionBuilder.dylib(weak)SystemPolicy(weak)Securitylibauthinstall.dyliblibimage4.dylib(weak)KernelManagementapfs_boot_mount(weak)libSystem.B.dylibIOKitFoundationlibobjc.A.dylibCoreFoundation(weak)DiskArbitrationAPFSCollectionsInternalCoreAnalyticsLoggingSupportlibswiftCompression.dylib(weak)libswiftCore.dyliblibswiftCoreFoundation.dyliblibswiftDarwin.dyliblibswiftDispatch.dyliblibswiftObjectiveC.dyliblibswiftXPC.dylib(weak)libswift_Builtin_float.dylib(weak)libswift_DarwinFoundation1.dyliblibswift_DarwinFoundation2.dyliblibswiftos.dylib
Entitlements23
Interesting Strings
Bundle IDs(116)
File Paths(52)
/AppleInternal/Library/BuildRoots/4~B_wCugD1GT6JPDmhh1RrUK5pccLqhjehz9nqD_o/Library/Caches/com.apple.xbs/Sources/AppleCredentialManager_ClientLibs/ACMLib/ACMLib.c/AppleInternal/Library/BuildRoots/4~B_wCugD1GT6JPDmhh1RrUK5pccLqhjehz9nqD_o/Library/Caches/com.apple.xbs/Sources/AppleCredentialManager_ClientLibs/common/LibCall.c/AppleInternal/Library/BuildRoots/4~B_wtugAtpEAVzPW8qOi3wBsSB2lFPgbNBILLkvg/Library/Caches/com.apple.xbs/Sources/KernelManagement_executables/core/Errors.swift/AppleInternal/Library/BuildRoots/4~B_wtugAtpEAVzPW8qOi3wBsSB2lFPgbNBILLkvg/Library/Caches/com.apple.xbs/Sources/KernelManagement_executables/kernelmanagerd/KernelManagerDaemon.swift/Library/Apple/System/Library/Extensions/AppleKextExcludeList.kext
telemetry(15)
Network Surface
Networking Frameworks
Endpoints(23)
Ipv4100.6.2.6
Ipv4100.6.1.13
Ipv4100.6.1.18
Hostnamefield.1.2.840.113635.100.6.2.6
Hostnamefield.1.2.840.113635.100.6.1.13
Hostnamefield.1.2.840.113635.100.6.1.18
Ipv4100.6.1.9
Ipv4100.6.1.12
Ipv4100.6.2.1
Ipv4100.6.1.25
Hostnamefield.1.2.840.113635.100.6.1.9
Hostnamefield.1.2.840.113635.100.6.1.9.1
Hostnamefield.1.2.840.113635.100.6.1.12
Hostnamefield.1.2.840.113635.100.6.2.1
Ipv60:8:16
Hostnamewww.apple.com
Hostnamecrl.apple.com
DNA Capability Vector
Location
0
Keychain
1
Network
0
Storage
2
Hardware
1
IPC
0
Analytics
1
Security
2
System
1
Behavioral Profile
URL Endpoints
4
Telemetry Strings
15
File Paths
52
Bundle IDs
116
IOKit Constants
0
Library Functions
0
Structural HashesSHA-256
Static Libraries0 / 8928 functions identified
Functions(8928)
0x100001de0sub_100001de0
0x100001e38sub_100001e38
0x100001e54sub_100001e54
0x100001e70sub_100001e70
0x100001eb0sub_100001eb0
0x100001efcsub_100001efc
0x100001f0csub_100001f0c
0x100001f1csub_100001f1c
0x100001f8csub_100001f8c
0x100001fd4sub_100001fd4
0x100002018sub_100002018
0x10000202csub_10000202c
0x100002078sub_100002078
0x1000020f8sub_1000020f8
0x100002120sub_100002120
0x100002164sub_100002164
0x100002178sub_100002178
0x100002180sub_100002180
0x100002184sub_100002184
0x100002188sub_100002188
Imports1191 symbols from 35 dylibs
Exports1
_mh_execute_header0x0