uarpd
executablemacOS1.9 MBx86_64, arm64
Network packet analyzer — captures and processes raw network traffic for diagnosis
Captures raw network packets at the link layer using packet capture libraries, enabling traffic inspection and network diagnostics. Communicates with hardware and kernel drivers to access network interfaces directly. Submits analytics and diagnostic data to Apple endpoints via the unified analytics framework. Exposes six XPC services for inter-process communication and maintains access to multiple file paths and Mach services for low-level system interaction. Contains telemetry reporting and connects to multiple network endpoints for data submission.AI
Fingerprint
- Platform
- macOS
- Type
- executable
- Arch
- x86_64, arm64
- Min OS
- 26.1.0
- SDK
- 26.1.0
- File Size
- 1.9 MB
- UUID
- 203982F2-2258-3C20-B16B-4475E610CCC9
- Analyzed
- 2026-04-09T10:10:33Z
- CDHash
- 7d25ba2f9a5c9c12e6c9cd0863779f06fd8b0614b78116660929181a48b5834d
Capabilities
NetworkRaw packet capture library
/usr/lib/libpcap.A.dylibStorageException: access additional file paths
com.apple.security.exception.files.absolute-path.read-writeHardwareDirect hardware/driver communication
/System/Library/Frameworks/IOKit.framework/Versions/A/IOKitIpcException: access additional Mach services
com.apple.security.exception.mach-lookup.global-nameAnalyticsApple unified analytics submission
/System/Library/PrivateFrameworks/CoreAnalytics.framework/Versions/A/CoreAnalyticsFrameworks13
Entitlements11
Interesting Strings
Bundle IDs(56)
File Paths(17)
!/private/var/db/accessoryupdater/0/System/Library/Frameworks/CoreFoundation.framework/Versions/A/CoreFoundation/System/Library/Frameworks/Foundation.framework/Versions/C/Foundation/System/Library/Frameworks/IOKit.framework/Versions/A/IOKit/System/Library/PrivateFrameworks/CoreAnalytics.framework/Versions/A/CoreAnalytics
telemetry(46)
Network Surface
Networking Frameworks
Endpoints(11)
Ipv60:8:16
Ipv40.0.0.0
Hostnamegs.apple.com
Hostnamewww.apple.com
Hostnamemacosx26.1.internal
Hostnamecrl.apple.com
API Usage
Methods
-[UARPEndpointConfiguration initWithURL:]-[UARPEndpointControllerInternal endpointControllerExportDynamicAsset:endpointUUID:dynamicAssetURL:reply:]-[UARPEndpointControllerInternal endpointControllerExportPersonalizedAsset:endpointUUID:personalizedAssetURL:reply:]-[UARPEndpointControllerInternal endpointControllerSolicitAsset:assetTag:assetURL:assetUUID:]-[UARPHostManager solicitAssetByAssetTag:hostEndpoint:assetURL:assetUUID:]-[UARPRTKitFTAB initWithURL:]-[UARPRTKitFTABSubfile initWithURL:offset:length:subFileTag:]-[UARPSuperBinaryLayer3 initWithURL:assetUUID:assetTag:tmpFolderPath:]-[UARPSuperBinaryLayer3 initWithURL:assetUUID:tmpFolderPath:]
DNA Capability Vector
Location
0
Keychain
0
Network
1
Storage
1
Hardware
1
IPC
1
Analytics
1
Security
0
System
0
Behavioral Profile
URL Endpoints
6
Telemetry Strings
46
File Paths
17
Bundle IDs
56
IOKit Constants
0
Library Functions
0
Structural HashesSHA-256
Static Libraries0 / 3134 functions identified
Functions(3134)
0x100001128-[BloodhoundPacketDumper initWithFileName:]
0x100001208-[BloodhoundPacketDumper initWithDumper:]
0x10000125c-[BloodhoundPacketDumper dealloc]
0x1000012c0-[BloodhoundPacketDumper dumpPacket:type:metadata:metadataLength:]
0x100001420-[BloodhoundPacketDumper .cxx_destruct]
0x10000142c-[UARPAssetMTIC init]
0x1000014b8-[UARPAssetMTIC processAsset:tmapSnapshot:]
0x100001910-[UARPAssetMTIC postToCoreAnalytics]
0x100001af0sub_100001af0
0x100001af8sub_100001af8
0x100001b00sub_100001b00
0x100001b08-[UARPAssetMTIC prepareForSysdiagnose:]
0x100001c20-[UARPAssetMTIC prepareEventForSysdiagnose:sysdiagnoseFolder:]
0x100001eb8-[UARPAssetMTIC setupEventFolder:sysdiagnoseFolder:]
0x1000021bc-[UARPAssetMTIC contributeSysdiagnoseMetrics:eventFileURL:]
0x100002474-[UARPAssetMTIC writeSysdiagnoseMetrics:fileHandle:error:]
0x100002540-[UARPAssetMTIC .cxx_destruct]
0x100002584sub_100002584
0x10000259csub_10000259c
0x1000025acsub_1000025ac
Imports182 symbols from 13 dylibs
Exports1
_mh_execute_header0x0