NRDUpdated
executablemacOS435.4 KBx86_64, arm64
Cryptographic key management service — handles encryption keys and certificate operations
Manages device encryption keys and cryptographic operations through direct keychain access and the device key bag. Exposes four XPC services for clients to request key operations, certificate validation, and code signing verification. Communicates with Apple endpoints for certificate validation and potential key escrow operations. Enforces security policies through entitlements and maintains audit logs of cryptographic operations.AI
Fingerprint
- Platform
- macOS
- Type
- executable
- Arch
- x86_64, arm64
- Min OS
- 26.1.0
- SDK
- 26.1.0
- File Size
- 435.4 KB
- UUID
- 5572664A-5677-35C9-9D82-F0BB4F75B8D1
- Analyzed
- 2026-04-09T09:39:43Z
- CDHash
- 11f0da1607e91514acd8abb721a19debb4a25551ab31e98239d39c223016fc5e
Capabilities
KeychainDevice key bag (encryption keys)
/System/Library/PrivateFrameworks/MobileKeyBag.framework/Versions/A/MobileKeyBagHardwareDirect hardware/driver communication
/System/Library/Frameworks/IOKit.framework/Versions/A/IOKitIpcException: access additional Mach services
com.apple.security.exception.mach-lookup.global-nameSecurityKeychain, certificates, code signing
/System/Library/Frameworks/Security.framework/Versions/A/SecurityFrameworks11
Entitlements10
Interesting Strings
Bundle IDs(55)
File Paths(25)
/AppleInternal/Library/BuildRoots/4~CAQjugC95RuAYsCkk-vYbfYDskBz9MtTgLug7-s/Library/Caches/com.apple.xbs/Binaries/MobileSoftwareUpdate/install/TempContent/Objects/MobileSoftwareUpdate.build/NRDUpdated.build/Objects-normal/arm64e/MSUShims.o/AppleInternal/Library/BuildRoots/4~CAQjugC95RuAYsCkk-vYbfYDskBz9MtTgLug7-s/Library/Caches/com.apple.xbs/Binaries/MobileSoftwareUpdate/install/TempContent/Objects/MobileSoftwareUpdate.build/NRDUpdated.build/Objects-normal/arm64e/NRDBackgroundActivitySchedulerServerImpl.o/AppleInternal/Library/BuildRoots/4~CAQjugC95RuAYsCkk-vYbfYDskBz9MtTgLug7-s/Library/Caches/com.apple.xbs/Binaries/MobileSoftwareUpdate/install/TempContent/Objects/MobileSoftwareUpdate.build/NRDUpdated.build/Objects-normal/arm64e/NRDRemoteableBlock.o/AppleInternal/Library/BuildRoots/4~CAQjugC95RuAYsCkk-vYbfYDskBz9MtTgLug7-s/Library/Caches/com.apple.xbs/Binaries/MobileSoftwareUpdate/install/TempContent/Objects/MobileSoftwareUpdate.build/NRDUpdated.build/Objects-normal/arm64e/NRDUpdateBrainClientImpl.o/AppleInternal/Library/BuildRoots/4~CAQjugC95RuAYsCkk-vYbfYDskBz9MtTgLug7-s/Library/Caches/com.apple.xbs/Binaries/MobileSoftwareUpdate/install/TempContent/Objects/MobileSoftwareUpdate.build/NRDUpdated.build/Objects-normal/arm64e/NRDUpdateBrainLoader.o
Network Surface
Networking Frameworks
Endpoints(13)
Ipv620:50:41
Ipv60:8:16
Hostnamewww.apple.com
Hostnamemacosx26.1.internal
Hostname144.cold.1
Hostname328.cold.1
Hostname438.cold.1
Hostname447.cold.1
Hostnamecrl.apple.com
DNA Capability Vector
Location
0
Keychain
1
Network
0
Storage
0
Hardware
1
IPC
1
Analytics
0
Security
1
System
0
Behavioral Profile
URL Endpoints
5
Telemetry Strings
1
File Paths
25
Bundle IDs
55
IOKit Constants
0
Library Functions
0
Structural HashesSHA-256
Static Libraries0 / 291 functions identified
Functions(291)
0x1000010a8sub_1000010a8
0x1000010b8sub_1000010b8
0x1000010c4sub_1000010c4
0x1000010d4sub_1000010d4
0x1000010e0logfunction
0x100001144nrdSharedLogger
0x100001188sub_100001188
0x1000011d0load_trust_cache_at_path
0x1000017ac-[NRDUpdateBrainClientImpl init]
0x1000017fc-[NRDUpdateBrainClientImpl initWithDelegate:]
0x100001828-[NRDUpdateBrainClientImpl initWithEndpoint:]
0x10000186c-[NRDUpdateBrainClientImpl dealloc]
0x1000018c0-[NRDUpdateBrainClientImpl _remoteInterfaceWithErrorHandler:]
0x1000019d4-[NRDUpdateBrainClientImpl _invalidateConnection_nolock]
0x100001a28-[NRDUpdateBrainClientImpl _invalidateConnection]
0x100001a7c-[NRDUpdateBrainClientImpl _connectToServerIfNecessary_nolock]
0x100001da8sub_100001da8
0x100001db8sub_100001db8
0x100001dc4sub_100001dc4
0x100001ea8sub_100001ea8
Imports128 symbols from 9 dylibs
Exports1
_mh_execute_header0x0