IOMFB_FDR_Loader

JSON
executablemacOS254.9 KBarm64

Secure Enclave key manager — handles cryptographic operations and sealed key access

Manages cryptographic keys stored in the Secure Enclave and performs hardware-accelerated operations through direct driver communication. Accesses Secure Enclave sealed keys via the Keychain framework to sign, encrypt, or attest data without exposing raw key material to the main OS. Communicates with multiple network endpoints and interacts with 15 different bundle identifiers, suggesting integration across system services. Includes telemetry collection and operates with elevated entitlements required for Secure Enclave access.AI

Fingerprint

Platform
macOS
Type
executable
Arch
arm64
Min OS
26.1.0
SDK
26.1.0
File Size
254.9 KB
UUID
58579874-4DE7-34C6-92B2-DD30EAFB5649
Analyzed
2026-04-07T05:21:11Z
CDHash
5216bf9acabf07823c57ff0a8e905e89b5bff48ca9ac466eeb6262f95ecfa912

Capabilities

Interesting Strings

Network Surface

Networking Frameworks

DNA Capability Vector

Location
0
Keychain
1
Network
0
Storage
0
Hardware
1
IPC
0
Analytics
0
Security
0
System
0

Behavioral Profile

URL Endpoints
4
Telemetry Strings
1
File Paths
5
Bundle IDs
15
IOKit Constants
0
Library Functions
0

Structural HashesSHA-256

Static Libraries0 / 311 functions identified

Functions(311)

0x1000008f8sub_1000008f8
0x100000960sub_100000960
0x1000009b8sub_1000009b8
0x100000a30sub_100000a30
0x100000aa4sub_100000aa4
0x100000b08sub_100000b08
0x100000b74sub_100000b74
0x100000bb0sub_100000bb0
0x100000bbcsub_100000bbc
0x100000bc8sub_100000bc8
0x100000be4sub_100000be4
0x100000bf0sub_100000bf0
0x100000c0csub_100000c0c
0x100000c18sub_100000c18
0x100000c24sub_100000c24
0x100000c44sub_100000c44
0x100000c64sub_100000c64
0x100000ed0sub_100000ed0
0x100001188sub_100001188
0x100001384sub_100001384

Imports127 symbols from 8 dylibs

Exports1

_mh_execute_header0x0