ASPCarryLog
executablemacOS2.1 MBx86_64, arm64
System diagnostics collector — gathers hardware metrics and submits telemetry
Collects system diagnostic data including hardware metrics, exception reports, and performance statistics. Communicates with Apple's analytics infrastructure through multiple network endpoints to submit aggregated diagnostic information. Accesses IOKit user clients for direct hardware and driver communication, additional Mach services, and restricted file paths to gather comprehensive system state. Maintains multiple XPC services for inter-process communication with other system components that request diagnostic data.AI
Fingerprint
- Platform
- macOS
- Type
- executable
- Arch
- x86_64, arm64
- Min OS
- 26.1.0
- SDK
- 26.1.0
- File Size
- 2.1 MB
- UUID
- ABD97A1E-E0DF-38E1-B981-383F1E95E7E7
- Analyzed
- 2026-04-09T09:37:29Z
- CDHash
- 5546a997379ac683eb6feda0b8d1319547c458b9f82721f86d3a8970fe90b2ff
Capabilities
StorageException: access additional file paths
com.apple.security.exception.files.absolute-path.read-writeHardwareException: access additional IOKit user clients
com.apple.security.exception.iokit-user-client-classHardwareDirect hardware/driver communication
/System/Library/Frameworks/IOKit.framework/Versions/A/IOKitIpcException: access additional Mach services
com.apple.security.exception.mach-lookup.global-nameAnalyticsApple unified analytics submission
/System/Library/PrivateFrameworks/CoreAnalytics.framework/Versions/A/CoreAnalyticsFrameworks20
TapToRadarKit(weak)AppleAccount(weak)Accounts(weak)StorageManagementService(weak)StorageManagement(weak)MobileSoftwareUpdate(weak)libNVMeCTL.dylib(weak)APFSlibarchive.2.dylibFoundationCrashReporterSupportIOKitCacheDelete(weak)CoreAnalyticslibMobileGestalt.dylibDiagnosticRequest(weak)libobjc.A.dyliblibc++.1.dyliblibSystem.B.dylibCoreFoundation
Entitlements16
Interesting Strings
Bundle IDs(80)
File Paths(24)
&/private/var/db/NANDTelemetryServices/0j.plist/AppleInternal/Library/BuildRoots/4~B_wCugA-0Zx3Aj7V8-QsepQi1zFPSiYP-PuUGP4/Library/Caches/com.apple.xbs/Sources/EmbeddedStorageReporting_libs_macos/NANDInfo/NANDInfo_osx.m/AppleInternal/Library/Frameworks/TapToRadarKit.framework/Versions/A/TapToRadarKit/System/Library/Frameworks/Accounts.framework/Versions/A/Accounts
telemetry(41)
Network Surface
Networking Frameworks
Endpoints(8)
DNA Capability Vector
Location
0
Keychain
0
Network
0
Storage
1
Hardware
2
IPC
1
Analytics
2
Security
0
System
0
Behavioral Profile
URL Endpoints
5
Telemetry Strings
41
File Paths
24
Bundle IDs
80
IOKit Constants
0
Library Functions
0
Structural HashesSHA-256
Static Libraries0 / 637 functions identified
Functions(637)
0x1000014f8sub_1000014f8
0x100001534sub_100001534
0x10000155csub_10000155c
0x100001758sub_100001758
0x1000017ac-[ASPCarryMainState registerIOLoggingXPCforInternalBuild:]
0x1000017b8sub_1000017b8
0x100001874-[ASPCarryMainState unregisterIOLoggingXPC]
0x100001880sub_100001880
0x100001cd0sub_100001cd0
0x100001d98sub_100001d98
0x1000020e4sub_1000020e4
0x1000021fcsub_1000021fc
0x100002274sub_100002274
0x1000023f0sub_1000023f0
0x100002578sub_100002578
0x1000025b8-[ASPCarryLog_ExtractUpload initWithNandDriver:UploadDriver:StateManager:workDirectory:internalBuild:]
0x100002a54-[ASPCarryLog_ExtractUpload _iologLba_current]
0x100002af4-[ASPCarryLog_ExtractUpload _iologLba_prevSubmission]
0x100002b68-[ASPCarryLog_ExtractUpload _isLastExtractionTooLongAgo]
0x100002c6c-[ASPCarryLog_ExtractUpload _updateLastExtractTime]
Imports261 symbols from 18 dylibs
Exports1
_mh_execute_header0x0