managedeventsd
executablemacOS261.8 KBx86_64, arm64
Endpoint Security monitor — tracks process, file, and network activity
Monitors system activity through the Endpoint Security framework, observing process execution, file operations, and network connections. Maintains private storage for collected data and exposes three XPC services for querying monitoring state and activity logs. Communicates with eight network endpoints, likely for telemetry or policy synchronization. Instruments 20 bundle identifiers across the system to classify activity by application.AI
Fingerprint
- Platform
- macOS
- Type
- executable
- Arch
- x86_64, arm64
- Min OS
- 26.1.0
- SDK
- 26.1.0
- File Size
- 261.8 KB
- UUID
- 60F47A16-E0FD-3B5A-A05C-CC4D81FF5FFA
- Analyzed
- 2026-04-09T09:54:49Z
- CDHash
- 0d4b7aacee64389efa9b58fa0e3cb46ce1fa311fa789c6ee2b521048461c57e7
Capabilities
StoragePrivate storage area access
com.apple.private.security.storage.ManagedConfigurationFiles[object Object]SecurityEndpoint Security (process/file/network monitoring)
/usr/lib/libEndpointSecurity.dylibFrameworks16
DMCUtilitieslibbsm.0.dyliblibEndpointSecurity.dylibFoundationlibobjc.A.dyliblibc++.1.dyliblibSystem.B.dylibCoreFoundationlibswiftCore.dyliblibswiftCoreFoundation.dylib(weak)libswiftDispatch.dyliblibswiftIOKit.dylib(weak)libswiftObjectiveC.dylib(weak)libswiftXPC.dyliblibswift_Builtin_float.dylib(weak)libswiftos.dylib
Entitlements5
Interesting Strings
Bundle IDs(20)
File Paths(3)
Network Surface
Networking Frameworks
Endpoints(8)
DNA Capability Vector
Location
0
Keychain
0
Network
0
Storage
1
Hardware
0
IPC
0
Analytics
0
Security
1
System
0
Behavioral Profile
URL Endpoints
5
Telemetry Strings
0
File Paths
3
Bundle IDs
20
IOKit Constants
0
Library Functions
0
Structural HashesSHA-256
Static Libraries0 / 177 functions identified
Functions(177)
0x100001428-[DMCEndpointSecurityMessage initWithClient:message:]
0x1000015d8-[DMCEndpointSecurityMessage dealloc]
0x100001628-[DMCEndpointSecurityMessage description]
0x1000016d4-[DMCEndpointSecurityMessage msToDeadline]
0x100001718-[DMCEndpointSecurityMessage eventTypeName]
0x100001768-[DMCEndpointSecurityMessage dispositionName]
0x1000017a0-[DMCEndpointSecurityMessage _machTimeToMS:]
0x100001808-[DMCEndpointSecurityMessage _translateDisposition:]
0x100001828-[DMCEndpointSecurityMessage uuid]
0x100001830-[DMCEndpointSecurityMessage client]
0x100001838-[DMCEndpointSecurityMessage message]
0x100001840-[DMCEndpointSecurityMessage deadline]
0x100001848-[DMCEndpointSecurityMessage eventType]
0x100001850-[DMCEndpointSecurityMessage isMountMessage]
0x100001858-[DMCEndpointSecurityMessage mountToName]
0x100001860-[DMCEndpointSecurityMessage disposition]
0x100001868-[DMCEndpointSecurityMessage mountFlags]
0x100001870-[DMCEndpointSecurityMessage readOnlyMount]
0x100001878-[DMCEndpointSecurityMessage isSignalMessage]
0x100001880-[DMCEndpointSecurityMessage sourceSigner]
Imports206 symbols from 13 dylibs
Exports1
_mh_execute_header0x0