frauddefensed
executablemacOS1.6 MBx86_64, arm64
System service — manages background tasks, keychain access, and cloud synchronization
Runs as a background system daemon with access to keychain credentials, code signing certificates, and iCloud synchronization. Schedules and executes background tasks while maintaining persistent network connections to nine endpoints for data sync and analytics. Exposes five XPC services for inter-process communication with other system components. Accesses multiple private file storage areas and leverages 39 frameworks including eight private Apple frameworks. Submits telemetry events to Apple's unified analytics system and maintains exception entitlements for extended file path and Mach service access.AI
Fingerprint
- Platform
- macOS
- Type
- executable
- Arch
- x86_64, arm64
- Min OS
- 26.1.0
- SDK
- 26.1.0
- File Size
- 1.6 MB
- UUID
- 0720775E-BF7A-3890-8B21-88157E115482
- Analyzed
- 2026-04-09T09:49:50Z
- CDHash
- 50627e54767a95032a7f108f19e8b46416cb1e17432118fed12589551a0b90cb
Capabilities
StoragePrivate storage area access
com.apple.private.security.storage.AppDataContainers[object Object]StorageException: access additional file paths
com.apple.security.exception.files.absolute-path.read-onlyStorageException: access additional file paths
com.apple.security.exception.files.home-relative-path.read-onlyIpcException: access additional Mach services
com.apple.security.exception.mach-lookup.global-nameAnalyticsApple unified analytics submission
/System/Library/PrivateFrameworks/CoreAnalytics.framework/Versions/A/CoreAnalyticsSecurityKeychain, certificates, code signing
/System/Library/Frameworks/Security.framework/Versions/A/SecuritySystemBackground task scheduling
/System/Library/PrivateFrameworks/BackgroundSystemTasks.framework/Versions/A/BackgroundSystemTasksFrameworks39
Foundationlibobjc.A.dyliblibSystem.B.dylibCloudKitCoreFoundationCoreMLJavaScriptCoreNaturalLanguageSecurityBackgroundSystemTasksCipherMLCoreAnalyticsDeviceIdentityIntelligencePlatformLibraryRulesStorageContainersPrivateUnifiedAssetFrameworklibMobileGestalt.dyliblibsqlite3.dyliblibswiftCore.dyliblibswiftCoreFoundation.dylib(weak)libswiftCoreLocation.dylib(weak)libswiftDispatch.dyliblibswiftIOKit.dylib(weak)libswiftMLCompute.dylib(weak)libswiftMetal.dylib(weak)libswiftNaturalLanguage.dylib(weak)libswiftOSLog.dylib(weak)libswiftObjectiveC.dyliblibswiftQuartzCore.dylib(weak)libswiftSystem.dyliblibswiftUniformTypeIdentifiers.dylib(weak)libswiftXPC.dylib(weak)libswift_Builtin_float.dylib(weak)libswift_Concurrency.dyliblibswift_DarwinFoundation2.dyliblibswift_DarwinFoundation3.dyliblibswiftos.dyliblibswiftsimd.dylib(weak)
Entitlements22
Interesting Strings
Bundle IDs(112)
File Paths(53)
/AppleInternal/Library/BuildRoots/4~B_wuugCnQpVXPyKlH-x-rlJ5x80ACwink0wYTDI/Library/Caches/com.apple.xbs/Sources/TrustKit/TrustKit/Source/AdHocSignaturesBackgroundActivity.swift/AppleInternal/Library/BuildRoots/4~B_wuugCnQpVXPyKlH-x-rlJ5x80ACwink0wYTDI/Library/Caches/com.apple.xbs/Sources/TrustKit/TrustKit/Source/AttestationManager.swift/AppleInternal/Library/BuildRoots/4~B_wuugCnQpVXPyKlH-x-rlJ5x80ACwink0wYTDI/Library/Caches/com.apple.xbs/Sources/TrustKit/TrustKit/Source/BackgroundActivityManager.swift/AppleInternal/Library/BuildRoots/4~B_wuugCnQpVXPyKlH-x-rlJ5x80ACwink0wYTDI/Library/Caches/com.apple.xbs/Sources/TrustKit/TrustKit/Source/CloudKitManager.swift/AppleInternal/Library/BuildRoots/4~B_wuugCnQpVXPyKlH-x-rlJ5x80ACwink0wYTDI/Library/Caches/com.apple.xbs/Sources/TrustKit/TrustKit/Source/CloudKitRecord.swift
telemetry(23)
$s13frauddefensed16AnalyticsManagerP/AppleInternal/Library/BuildRoots/4~B_wuugCnQpVXPyKlH-x-rlJ5x80ACwink0wYTDI/Library/Caches/com.apple.xbs/Sources/TrustKit/TrustKit/Source/DaemonAnalyticsManager.swift/System/Library/PrivateFrameworks/CoreAnalytics.framework/Versions/A/CoreAnalyticsActivity is already submitted. { activity=AnalyticsManager
Network Surfaceentitled
Networking Frameworks
Endpoints(9)
API Usage
DNA Capability Vector
Location
0
Keychain
1
Network
2
Storage
3
Hardware
0
IPC
1
Analytics
1
Security
1
System
1
Behavioral Profile
URL Endpoints
5
Telemetry Strings
23
File Paths
53
Bundle IDs
112
IOKit Constants
0
Library Functions
1
Structural HashesSHA-256
Static Libraries0 / 2067 functions identified
Function Matches(1)
PEM_read_bioopenssl 3.2High
Functions(2067)
0x100001c58sub_100001c58
0x100001e9csub_100001e9c
0x100001eb8sub_100001eb8
0x100001ec4sub_100001ec4
0x100002294sub_100002294
0x1000022dcsub_1000022dc
0x1000022f8sub_1000022f8
0x1000024d0sub_1000024d0
0x1000025ecsub_1000025ec
0x100002658sub_100002658
0x1000026ccsub_1000026cc
0x100002938sub_100002938
0x100002a9csub_100002a9c
0x100002ae0sub_100002ae0
0x100002b98sub_100002b98
0x100002bd0sub_100002bd0
0x100002c7csub_100002c7c
0x100002d70sub_100002d70
0x100002dbcsub_100002dbc
0x100002dccsub_100002dcc
Imports751 symbols from 27 dylibs
Exports1
_mh_execute_header0x0