devicerecoverytool

JSON
executablemacOS157.7 KBx86_64, arm64

System firmware utility — reads and writes NVRAM variables with direct hardware access

Manages low-level system firmware variables stored in NVRAM, enabling read and write operations to persistent hardware settings. Communicates directly with hardware and drivers to access firmware state. Exposes network endpoints for remote operations and includes references to multiple bundle identifiers, suggesting integration with system management or hardware monitoring frameworks. Operates with elevated privileges to modify firmware-level configuration.AI

Fingerprint

Platform
macOS
Type
executable
Arch
x86_64, arm64
Min OS
26.1.0
SDK
26.1.0
File Size
157.7 KB
UUID
37EC457F-95E8-3E85-8764-764D8595A335
Analyzed
2026-04-09T09:46:57Z
CDHash
d0ba32c413561388b41ca318d21f1c08be4ae1455a6e07c4f138ad1ac898ea27

Interesting Strings

Network Surface

DNA Capability Vector

Location
0
Keychain
0
Network
0
Storage
1
Hardware
1
IPC
0
Analytics
0
Security
0
System
0

Behavioral Profile

URL Endpoints
4
Telemetry Strings
0
File Paths
3
Bundle IDs
3
IOKit Constants
0
Library Functions
0

Structural HashesSHA-256

Static Libraries0 / 62 functions identified

Functions(62)

0x100000ca8sub_100000ca8
0x100000ce4sub_100000ce4
0x100000d2csub_100000d2c
0x100000d6csub_100000d6c
0x100000df8sub_100000df8
0x100000e44sub_100000e44
0x1000010b0sub_1000010b0
0x1000010c4sub_1000010c4
0x100001118sub_100001118
0x100001240sub_100001240
0x100001294sub_100001294
0x1000012e0sub_1000012e0
0x1000012e8sub_1000012e8
0x10000132csub_10000132c
0x100001354sub_100001354
0x100001394sub_100001394
0x1000013b8sub_1000013b8
0x100001448sub_100001448
0x100001454sub_100001454
0x100001460sub_100001460

Imports95 symbols from 6 dylibs

Exports1

_mh_execute_header0x0