devmodectl

JSON
executablemacOS158.2 KBx86_64, arm64

System utility — performs unsigned code detection and security policy enforcement

Validates executable signatures and enforces macOS code signing requirements across the system. Communicates with security policy services via network endpoints to check authorization status for unsigned or modified binaries. Manages bundle identifiers and file paths to track application provenance and enforce gatekeeper policies. Uses private Apple frameworks to interact with the security subsystem and policy databases, preventing execution of untrusted code.AI

Fingerprint

Platform
macOS
Type
executable
Arch
x86_64, arm64
Min OS
26.1.0
SDK
26.1.0
File Size
158.2 KB
UUID
876F8C27-AE9B-3503-BCF1-99AF2A55F654
Analyzed
2026-04-07T05:21:14Z
CDHash
fdbfca28ff914575a7a4bea80b07d788cde3ae19d3ccf4fe2d3ea4530fe3e016

Interesting Strings

Bundle IDs(11)

File Paths(13)

Network Surface

Networking Frameworks

DNA Capability Vector

Location
0
Keychain
0
Network
0
Storage
0
Hardware
0
IPC
0
Analytics
0
Security
0
System
0

Behavioral Profile

URL Endpoints
4
Telemetry Strings
0
File Paths
13
Bundle IDs
11
IOKit Constants
0
Library Functions
0

Structural HashesSHA-256

Static Libraries0 / 24 functions identified

Functions(24)

0x100000d90dev_mode_state_to_string
0x100000dbcdev_mode_state_for_device
0x100000ffcgetAMDErrorString
0x100001024getDictionaryFromConnection
0x100001078-[DeviceRef amd]
0x100001080+[DeviceRef fromMobileDevice:]
0x1000010f0-[DeviceRef dealloc]
0x100001154-[DeviceRef connect]
0x10000117c-[DeviceRef startSession]
0x1000011a4-[DeviceRef startService:options:]
0x100001244-[DeviceRef getService:]
0x10000127c-[DeviceRef udid]
0x1000012a8-[DeviceRef .cxx_destruct]
0x1000012ecinfo_invoke
0x1000015f4single_invoke
0x100001974device_callback
0x100001d70list_invoke
0x100001f88device_callback
0x1000023c0streaming_invoke
0x1000025a0main

Imports48 symbols from 6 dylibs

Exports1

_mh_execute_header0x0