xpcroleaccountd

JSON
executablemacOS171.4 KBx86_64, arm64

Security certificate tool — manages keychain access and code signing operations

Performs cryptographic operations involving keychain access, certificate management, and code signing validation. Communicates with multiple network endpoints and accesses extended file paths beyond standard application sandboxing. Exposes three XPC services for inter-process communication with other system components. Handles security-sensitive operations involving certificates and signing credentials stored in the system keychain.AI

Fingerprint

Platform
macOS
Type
executable
Arch
x86_64, arm64
Min OS
26.1.0
SDK
26.1.0
File Size
171.4 KB
UUID
952FC3B1-CEF2-31F9-BD1E-ED4E90944799
Analyzed
2026-04-09T10:12:41Z
CDHash
2cbc38a13fae5ce87ef1765ff9aa2b1c0836300b2e08a532ec1ab8aa9429b500

Interesting Strings

Network Surface

Networking Frameworks

DNA Capability Vector

Location
0
Keychain
0
Network
0
Storage
2
Hardware
0
IPC
0
Analytics
0
Security
1
System
0

Behavioral Profile

URL Endpoints
6
Telemetry Strings
0
File Paths
15
Bundle IDs
24
IOKit Constants
0
Library Functions
0

Structural HashesSHA-256

Static Libraries0 / 79 functions identified

Functions(79)

0x100000a18sub_100000a18
0x100000b64sub_100000b64
0x100000cacsub_100000cac
0x100000db4sub_100000db4
0x100000dfcsub_100000dfc
0x100000ed0sub_100000ed0
0x100000ee4sub_100000ee4
0x100000f1csub_100000f1c
0x100000f94sub_100000f94
0x100001004sub_100001004
0x100001134sub_100001134
0x100001190sub_100001190
0x1000011d4sub_1000011d4
0x100001218sub_100001218
0x100001314sub_100001314
0x10000135csub_10000135c
0x1000013d8sub_1000013d8
0x100001630sub_100001630
0x100001e5csub_100001e5c
0x100001e64sub_100001e64

Imports111 symbols from 5 dylibs

Exports1

_mh_execute_header0x0