smd
executablemacOS357.3 KBx86_64, arm64
Code signing and certificate validation — verifies binary integrity and manages cryptographic credentials
Validates code signatures on macOS binaries and manages access to Keychain certificates and signing credentials. Communicates with Apple's code signing infrastructure through 11 network endpoints to perform online validation and revocation checks. Exposes 12 XPC services that allow other system components to verify signatures, retrieve certificates, and validate code identity. Collects telemetry on signing operations and validation failures. Enforces security policies around which applications can access Keychain items and signing keys.AI
Fingerprint
- Platform
- macOS
- Type
- executable
- Arch
- x86_64, arm64
- Min OS
- 26.1.0
- SDK
- 26.1.0
- File Size
- 357.3 KB
- UUID
- 87D51432-06EC-3A70-9E30-A62C6722B29B
- Analyzed
- 2026-04-09T10:05:06Z
- CDHash
- be4f9bdb1507bccdcdc2d7c0bdf1c4d15bcfb8a023d17284dc23b7159e6c950d
Capabilities
SecurityKeychain, certificates, code signing
/System/Library/Frameworks/Security.framework/Versions/A/SecurityFrameworks7
Entitlements7
Interesting Strings
Bundle IDs(36)
#com.apple.private.xpc.aux-bootstrap%com.apple.rootless.xpc.effective-root(com.apple.private.xpc.protected-services)com.apple.private.xpc.launchd.job-manager/AppleInternal/Library/BuildRoots/4~B_wmugDgJ2N2f5ZSwF8D1OxuTMzN48riXDKBxbA/Library/Caches/com.apple.xbs/Binaries/libxpc_executables/install/Symbols/smd
File Paths(20)
telemetry(6)
URLs & Endpoints(6)
$http://crl.apple.com/codesigning.crl0%http://www.apple.com/appleca/root.crl0<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd"><?xml version="1.0" encoding="UTF-8"?><!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd"><plist version="1.0"><dict><string>com.apple.compilers.llvm.clang.1_0</string>
Network Surface
Networking Frameworks
Endpoints(11)
Hostnamelibxpc-3089.41.2
Ipv60:8:16
Ipv601:13:24
Hostnamewww.apple.com
Hostnamemacosx26.1.internal
Hostnamecrl.apple.com
API Usage
DNA Capability Vector
Location
0
Keychain
0
Network
0
Storage
0
Hardware
0
IPC
0
Analytics
0
Security
1
System
0
Behavioral Profile
URL Endpoints
6
Telemetry Strings
6
File Paths
20
Bundle IDs
36
IOKit Constants
0
Library Functions
0
Structural HashesSHA-256
Static Libraries0 / 397 functions identified
Functions(397)
0x100000e88+[SMAppServiceLegacyLoginItemFactory instanceWithFileSystem:]
0x100000ee8-[SMAppServiceLegacyLoginItemFactory legacyLoginItemFromPath:container:uid:]
0x10000108c+[RealFileSystem instance]
0x1000010e4-[RealFileSystem loadPlistFromBundle:subpath:errorOut:]
0x1000010f4-[RealFileSystem copyRealPath:]
0x1000010fc-[RealFileSystem createBundle:flags:]
0x10000112c-[RealFileSystem copyRequestorBundle:errorOut:]
0x10000115c-[RealFileSystem copyPlist:]
0x100001164-[RealFileSystem copyLoginItemBundle:identifier:]
0x100001170-[RealFileSystem getRelationship:ofDirectoryAtURL:toItemAtURL:error:]
0x100001210+[SMAppServiceManaged setDefaultPlistProperties:type:]
0x10000127c-[SMAppServiceManaged initWithType:path:container:plist:uid:domain:btm:launchd:]
0x1000013d4-[SMAppServiceManaged createJob:]
0x100001694-[SMAppServiceManaged bootstrapImpl:]
0x100001800-[SMAppServiceManaged shouldBootstrapAndReturnLWCR:]
0x10000198c-[SMAppServiceManaged bootstrapWithCompletionHandler:onQueue:]
0x100001b2csub_100001b2c
0x100001cd8sub_100001cd8
0x100001d30sub_100001d30
0x100001d7c-[SMAppServiceManaged bootstrapServicesImpl]
Imports239 symbols from 7 dylibs
Exports1
_mh_execute_header0x0