securityd
executablemacOS1.3 MBx86_64, arm64
Cryptographic key management — stores and manages sensitive credentials via Secure Enclave
Manages cryptographic keys and certificates stored in the Secure Enclave and system keychain. Performs hardware-backed cryptographic operations through direct hardware communication and exposes two XPC services for other processes to request signing, encryption, or key operations. Maintains private storage for credential metadata and telemetry. Communicates with Apple endpoints for validation, certificate pinning, or revocation checks.AI
Fingerprint
- Platform
- macOS
- Type
- executable
- Arch
- x86_64, arm64
- Min OS
- 26.1.0
- SDK
- 26.1.0
- File Size
- 1.3 MB
- UUID
- 1DA58E9E-387E-3E8A-945E-0C8523233083
- Analyzed
- 2026-04-07T05:21:16Z
- CDHash
- 417395c1e8f62fb5897af754da92bbef89159690b4bb51f3ec4522673237bc50
Capabilities
KeychainHardware key storage (Secure Enclave)
/System/Library/PrivateFrameworks/AppleKeyStore.framework/Versions/A/AppleKeyStoreHardwareDirect hardware/driver communication
/System/Library/Frameworks/IOKit.framework/Versions/A/IOKitSecurityKeychain, certificates, code signing
/System/Library/Frameworks/Security.framework/Versions/A/SecurityFrameworks15
Entitlements9
Interesting Strings
Bundle IDs(31)
File Paths(18)
telemetry(5)
Network Surface
Networking Frameworks
Endpoints(22)
HostnameSecurity-61901.40.77
Ipv4100.6.1.9
Hostnamefield.1.2.840.113635.100.6.1.9
Ipv4100.6.2.1
Ipv4100.6.1.25
Hostnamefield.1.2.840.113635.100.6.2.1
Ipv4100.6.2.6
Ipv4100.6.1.13
Ipv4100.6.1.12
Ipv4100.6.1.7
Hostnamefield.1.2.840.113635.100.6.2.6
Hostnamefield.1.2.840.113635.100.6.1.13
Hostnamefield.1.2.840.113635.100.6.1.12
Hostnamefield.1.2.840.113635.100.6.1.7
Hostnamewww.apple.com
Hostnamecrl.apple.com
API Usage
DNA Capability Vector
Location
0
Keychain
1
Network
0
Storage
2
Hardware
1
IPC
0
Analytics
0
Security
1
System
0
Behavioral Profile
URL Endpoints
4
Telemetry Strings
5
File Paths
18
Bundle IDs
31
IOKit Constants
0
Library Functions
3
Structural HashesSHA-256
Static Libraries3 / 1763 functions identified
Identified Libraries
Functions(1763)
0x100001008sub_100001008
0x10000109csub_10000109c
0x100001168sub_100001168
0x100001264sub_100001264
0x1000012a0sub_1000012a0
0x1000013e0sub_1000013e0
0x100001470sub_100001470
0x1000014f0sub_1000014f0
0x10000159csub_10000159c
0x100001aa4sub_100001aa4
0x100001abcsub_100001abc
0x100001af4sub_100001af4
0x100001b54sub_100001b54
0x100001c24sub_100001c24
0x100001cb4sub_100001cb4
0x1000021ecsub_1000021ec
0x10000227csub_10000227c
0x100002324sub_100002324
0x1000023dcsub_1000023dc
0x100002410sub_100002410
Imports484 symbols from 11 dylibs
Exports1
_mh_execute_header0x0