uarpd

JSON
executablemacOS1.9 MBx86_64, arm64

Network packet analyzer — captures and processes raw network traffic for diagnosis

Captures raw network packets at the link layer using packet capture libraries, enabling traffic inspection and network diagnostics. Communicates with hardware and kernel drivers to access network interfaces directly. Submits analytics and diagnostic data to Apple endpoints via the unified analytics framework. Exposes six XPC services for inter-process communication and maintains access to multiple file paths and Mach services for low-level system interaction. Contains telemetry reporting and connects to multiple network endpoints for data submission.AI

Fingerprint

Platform
macOS
Type
executable
Arch
x86_64, arm64
Min OS
26.1.0
SDK
26.1.0
File Size
1.9 MB
UUID
203982F2-2258-3C20-B16B-4475E610CCC9
Analyzed
2026-04-09T10:10:33Z
CDHash
7d25ba2f9a5c9c12e6c9cd0863779f06fd8b0614b78116660929181a48b5834d

Interesting Strings

Network Surface

Networking Frameworks

DNA Capability Vector

Location
0
Keychain
0
Network
1
Storage
1
Hardware
1
IPC
1
Analytics
1
Security
0
System
0

Behavioral Profile

URL Endpoints
6
Telemetry Strings
46
File Paths
17
Bundle IDs
56
IOKit Constants
0
Library Functions
0

Structural HashesSHA-256

Static Libraries0 / 3134 functions identified

Functions(3134)

0x100001128-[BloodhoundPacketDumper initWithFileName:]
0x100001208-[BloodhoundPacketDumper initWithDumper:]
0x10000125c-[BloodhoundPacketDumper dealloc]
0x1000012c0-[BloodhoundPacketDumper dumpPacket:type:metadata:metadataLength:]
0x100001420-[BloodhoundPacketDumper .cxx_destruct]
0x10000142c-[UARPAssetMTIC init]
0x1000014b8-[UARPAssetMTIC processAsset:tmapSnapshot:]
0x100001910-[UARPAssetMTIC postToCoreAnalytics]
0x100001af0sub_100001af0
0x100001af8sub_100001af8
0x100001b00sub_100001b00
0x100001b08-[UARPAssetMTIC prepareForSysdiagnose:]
0x100001c20-[UARPAssetMTIC prepareEventForSysdiagnose:sysdiagnoseFolder:]
0x100001eb8-[UARPAssetMTIC setupEventFolder:sysdiagnoseFolder:]
0x1000021bc-[UARPAssetMTIC contributeSysdiagnoseMetrics:eventFileURL:]
0x100002474-[UARPAssetMTIC writeSysdiagnoseMetrics:fileHandle:error:]
0x100002540-[UARPAssetMTIC .cxx_destruct]
0x100002584sub_100002584
0x10000259csub_10000259c
0x1000025acsub_1000025ac

Imports182 symbols from 13 dylibs

Exports1

_mh_execute_header0x0