corecaptured
executablemacOS101.4 KBx86_64, arm64
System driver communication daemon — facilitates direct hardware and driver interactions
Manages direct communication with DriverKit drivers and hardware subsystems through privileged kernel interfaces. Operates as a hardened runtime process with restricted execution environment. Exposes an XPC service for other system components to request hardware operations or driver communications. Handles telemetry reporting to Apple infrastructure and maintains references to multiple bundle identifiers, suggesting coordination across several system services. Includes security constraints that prevent unauthorized access to the driver communication layer.AI
Fingerprint
- Platform
- macOS
- Type
- executable
- Arch
- x86_64, arm64
- Min OS
- 26.1.0
- SDK
- 26.1.0
- File Size
- 101.4 KB
- UUID
- 4FDE4E54-9883-3972-93E9-EE7B9036218A
- Analyzed
- 2026-04-09T09:45:38Z
- CDHash
- 061211e5e9bd104867a0890829d5eaa28fcef964bc690756cdc95f4f52388fc7
Capabilities
HardwareDirect DriverKit driver communication
com.apple.private.driverkit.driver-accessHardwareDirect hardware/driver communication
/System/Library/Frameworks/IOKit.framework/Versions/A/IOKitInteresting Strings
Bundle IDs(26)
File Paths(8)
(/private/var/Managed Preferences/mobile/(/private/var/tmp/com.apple.corecaptured//System/Library/Frameworks/CoreFoundation.framework/Versions/A/CoreFoundation/System/Library/Frameworks/IOKit.framework/Versions/A/IOKit/System/Library/PrivateFrameworks/CoreCaptureDaemon.framework/Versions/A/CoreCaptureDaemon
telemetry(2)
Network Surface
Networking Frameworks
DNA Capability Vector
Location
0
Keychain
0
Network
0
Storage
0
Hardware
2
IPC
0
Analytics
0
Security
1
System
0
Behavioral Profile
URL Endpoints
4
Telemetry Strings
2
File Paths
8
Bundle IDs
26
IOKit Constants
0
Library Functions
0
Structural HashesSHA-256
Static Libraries0 / 2 functions identified
Functions(2)
0x1000006e8sub_1000006e8
0x100000778sub_100000778
Imports16 symbols from 2 dylibs
Exports1
_mh_execute_header0x0