sysdiagnose_helper
executablemacOS1.2 MBx86_64, arm64
MDM client daemon — enforces mobile device management policies and device compliance
Implements mobile device management on macOS by reading MDM configuration profiles and enforcing device policies. Monitors process lifecycle, network configuration, and file system events through Endpoint Security framework to detect policy violations. Manages hardware-level access controls and communicates with MDM servers via network APIs. Exposes three XPC services for system components to query device compliance status and policy settings. Transmits telemetry and diagnostic data about device state and policy enforcement.AI
Fingerprint
- Platform
- macOS
- Type
- executable
- Arch
- x86_64, arm64
- Min OS
- 26.1.0
- SDK
- 26.1.0
- File Size
- 1.2 MB
- UUID
- 1277884A-21A9-32E9-9DC2-83A7E84EBD8D
- Analyzed
- 2026-04-09T10:07:29Z
- CDHash
- d1656817f3b6c81181f81f5ddf819e4fe17f25c3352c76908455fbc5900b0a8f
Capabilities
NetworkNetwork configuration and reachability
/System/Library/Frameworks/SystemConfiguration.framework/Versions/A/SystemConfigurationHardwareDirect hardware/driver communication
/System/Library/Frameworks/IOKit.framework/Versions/A/IOKitIpcShared application group container access
com.apple.security.application-groupsIpcException: access additional Mach services
com.apple.security.exception.mach-lookup.global-namecom.apple.intelligenceplatform.SysdiagnoseSecurityEndpoint Security (process/file/network monitoring)
/usr/lib/libEndpointSecurity.dylibSystemAccess MDM configuration profiles
com.apple.private.managedclient.configurationprofiles[object Object]SystemProcess lifecycle management
/System/Library/PrivateFrameworks/RunningBoardServices.framework/Versions/A/RunningBoardServicesSystemMDM configuration profiles
/System/Library/PrivateFrameworks/ConfigurationProfiles.framework/Versions/A/ConfigurationProfilesFrameworks35
libdscsym.dyliblibtailspin.dylib(weak)AppleDeviceQuerySupport(weak)libMobileGestalt.dylibCoreDiagnostics(weak)IntelligencePlatform(weak)UnifiedAssetFramework(weak)Trial(weak)RunningBoardServices(weak)libMemoryResourceException.dylib(weak)WiFiVelocity(weak)PowerLog(weak)libtzupdate.dylib(weak)libmis.dylib(weak)RapidResourceDelivery(weak)AppKit(weak)Seeding(weak)libsystemstats.dyliblibsysmon.dylibSystemConfigurationPersonalizationPortrait(weak)Carbon(weak)libEndpointSecurity.dylib(weak)ProactiveInputPredictions(weak)NearField(weak)HID(weak)CoreRepairCore(weak)ConfigurationProfiles(weak)Foundationlibobjc.A.dyliblibSystem.B.dylibCoreFoundation(weak)CoreGraphics(weak)CoreServices(weak)IOKit
Interesting Strings
Bundle IDs(130)
File Paths(28)
/Library/Preferences/com.apple.security.coderequirements/System/Library/Frameworks/AppKit.framework/Versions/C/AppKit/System/Library/Frameworks/Carbon.framework/Versions/A/Carbon/System/Library/Frameworks/CoreFoundation.framework/Versions/A/CoreFoundation/System/Library/Frameworks/CoreGraphics.framework/Versions/A/CoreGraphics
telemetry(14)
Network Surface
Networking Frameworks
Endpoints(9)
API Usage
DNA Capability Vector
Location
0
Keychain
0
Network
1
Storage
0
Hardware
1
IPC
2
Analytics
0
Security
1
System
3
Behavioral Profile
URL Endpoints
4
Telemetry Strings
14
File Paths
28
Bundle IDs
130
IOKit Constants
0
Library Functions
0
Structural HashesSHA-256
Static Libraries0 / 368 functions identified
Functions(368)
0x1000019b8-[SystemDiagnosticPromptOSX promptIfNeeded:withBundleID:]
0x1000029f0sub_1000029f0
0x100002a34-[SystemDiagnosticPromptOSX userNotificationCenter:shouldPresentNotification:]
0x100002a3c-[SystemDiagnosticPromptOSX userNotificationCenter:didDismissAlert:]
0x100002ac4-[SystemDiagnosticPromptOSX userNotificationCenter:didActivateNotification:]
0x100002ca0sub_100002ca0
0x100002ce8sub_100002ce8
0x100003470sub_100003470
0x10000357csub_10000357c
0x1000036c0sub_1000036c0
0x100003844sub_100003844
0x100003900sub_100003900
0x100003a10sub_100003a10
0x100003a54sub_100003a54
0x100003a9csub_100003a9c
0x100003ab8sub_100003ab8
0x100003b2csub_100003b2c
0x100003b7c-[SystemdiagnosticLogAgentOSX _prompt]
0x100003bc0sub_100003bc0
0x100003c00-[SystemdiagnosticLogAgentOSX evaluateGlob:]
Imports299 symbols from 33 dylibs
Exports1
_mh_execute_header0x0