siriknowledged
executablemacOS395.7 KBx86_64, arm64
System diagnostic collector — gathers and submits device health and usage telemetry
Collects diagnostic data including symptoms, analytics, and device state information, then submits reports to Apple endpoints. Accesses location data as a system bundle without user prompts and syncs diagnostic information through iCloud. Maintains private storage areas for collected data and manages communication through 7 XPC services for inter-process coordination. Makes outgoing network connections to transmit telemetry and accesses additional file paths beyond standard sandboxed locations. Runs as an Apple-signed system component with no direct user interface.AI
Fingerprint
- Platform
- macOS
- Type
- executable
- Arch
- x86_64, arm64
- Min OS
- 26.1.0
- SDK
- 26.1.0
- File Size
- 395.7 KB
- UUID
- CAEE22E1-DCA7-370C-AF89-8E9A54F8814B
- Analyzed
- 2026-04-09T10:04:26Z
- CDHash
- 911e21cceec57b0223d1732f27018756ddbdd80db66b4532382733e3dcd05db9
Capabilities
LocationAccess location as a system bundle (no user prompt)
com.apple.locationd.effective_bundle[object Object]StoragePrivate storage area access
com.apple.private.security.storage.MobileAssetGenerativeModels[object Object]StorageException: access additional file paths
com.apple.security.exception.files.absolute-path.read-onlyStorageException: access additional file paths
com.apple.security.exception.files.home-relative-path.read-writeIpcRestricted application group access
com.apple.private.security.restricted-application-groupsIpcShared application group container access
com.apple.security.application-groupsIpcException: access additional Mach services
com.apple.security.exception.mach-lookup.global-namecom.apple.siri.orchestration.capabilitiescom.apple.routined.registrationcom.apple.SystemConfiguration.configdcom.apple.triald.namespace-managementcom.apple.mobileasset.autoassetcom.apple.mobileassetd.v2com.apple.assistant.analyticscom.apple.siri.analytics.assistantcom.apple.icloud.searchparty.locationfetch.itemscom.apple.icloud.searchpartyd.ownersessioncom.apple.siri.uaf.servicecom.apple.siri.uaf.subscription.servicecom.apple.medialibraryd.xpccom.apple.calaccessdcom.apple.feedbackloggercom.apple.biome.access.usercom.apple.findmy.findmylocate.friendshipservicecom.apple.findmy.findmylocate.settingscom.apple.findmy.findmylocate.locationservicecom.apple.icloud.searchpartyd.beaconmanagercom.apple.icloud.searchpartyd.beaconsharingservice
Frameworks10
Entitlements110
com.apple.private.assets.accessible-asset-types
com.apple.MobileAsset.Trial.Siri.SiriDialogAssetscom.apple.MobileAsset.Trial.Siri.SiriExperienceCamcom.apple.MobileAsset.Trial.Siri.SiriTextToSpeechcom.apple.MobileAsset.Trial.Siri.SiriFindMyConfigurationFilescom.apple.MobileAsset.Trial.Siri.SiriUnderstandingAsrAssistantcom.apple.MobileAsset.Trial.Siri.SiriUnderstandingAsrHammercom.apple.MobileAsset.Trial.Siri.SiriUnderstandingAttentionAssetscom.apple.MobileAsset.Trial.Siri.SiriUnderstandingMorphuncom.apple.MobileAsset.Trial.Siri.SiriUnderstandingNLcom.apple.MobileAsset.Trial.Siri.SiriUnderstandingNLOverridescom.apple.MobileAsset.UAF.Siri.TextToSpeech
com.apple.security.exception.mach-lookup.global-name
com.apple.siri.orchestration.capabilitiescom.apple.routined.registrationcom.apple.SystemConfiguration.configdcom.apple.triald.namespace-managementcom.apple.mobileasset.autoassetcom.apple.mobileassetd.v2com.apple.assistant.analyticscom.apple.siri.analytics.assistantcom.apple.icloud.searchparty.locationfetch.itemscom.apple.icloud.searchpartyd.ownersessioncom.apple.siri.uaf.servicecom.apple.siri.uaf.subscription.servicecom.apple.medialibraryd.xpccom.apple.calaccessdcom.apple.feedbackloggercom.apple.biome.access.usercom.apple.findmy.findmylocate.friendshipservicecom.apple.findmy.findmylocate.settingscom.apple.findmy.findmylocate.locationservicecom.apple.icloud.searchpartyd.beaconmanagercom.apple.icloud.searchpartyd.beaconsharingservice
Interesting Strings
Bundle IDs(221)
File Paths(20)
telemetry(8)
Network Surfaceentitled
Networking Frameworks
Endpoints(13)
DNA Capability Vector
Location
1
Keychain
0
Network
2
Storage
6
Hardware
0
IPC
3
Analytics
1
Security
0
System
0
Behavioral Profile
URL Endpoints
5
Telemetry Strings
8
File Paths
20
Bundle IDs
221
IOKit Constants
0
Library Functions
0
Structural HashesSHA-256
Static Libraries0 / 236 functions identified
Functions(236)
0x100001080-[CKSiriSettingsMonitor .cxx_destruct]
0x1000010c4-[CKSiriSettingsMonitor siriSettingsDidChange]
0x1000011ecsub_1000011ec
0x1000012b8sub_1000012b8
0x1000012c0sub_1000012c0
0x1000012ccsub_1000012cc
0x100001418sub_100001418
0x1000016d8sub_1000016d8
0x1000017f0sub_1000017f0
0x1000017f8sub_1000017f8
0x100001800-[CKSiriSettingsMonitor init]
0x10000189c+[CKSiriSettingsMonitor sharedInstance]
0x10000193csub_10000193c
0x100001978sub_100001978
0x100001a58sub_100001a58
0x100001bf8sub_100001bf8
0x100001ea0sub_100001ea0
0x100001ef4sub_100001ef4
0x100002010-[CKNCloudKitDataStore mergeRecordsWithDictionary:deletedRecordKeys:containsAllChanges:]
0x100002218sub_100002218
Imports153 symbols from 10 dylibs
Exports1
_mh_execute_header0x0