secd
executablemacOS8.3 MBx86_64, arm64
Apple authentication and security manager — handles identity verification and encrypted credential access
Manages Apple ID authentication, biometric verification (Touch ID/Face ID), and keychain-based credential storage across local and cloud environments. Accesses encryption keys from the Secure Enclave and device key bag to protect sensitive data. Performs certificate validation and code signing operations through the Security framework. Submits diagnostic telemetry to Apple and synchronizes encrypted data with iCloud. Exposes 31 XPC services to enable other system processes to request authentication, keychain access, and security operations without direct access to credentials.AI
Fingerprint
- Platform
- macOS
- Type
- executable
- Arch
- x86_64, arm64
- Min OS
- 26.1.0
- SDK
- 26.1.0
- File Size
- 8.3 MB
- UUID
- DD41A725-52FE-376C-BCD2-401F1CC35113
- Analyzed
- 2026-04-09T10:03:04Z
- CDHash
- daa75de84a2926e7b74c315c16839214446a86da8abceda344d5b487ff3d74b2
Capabilities
KeychainHardware key storage (Secure Enclave)
/System/Library/PrivateFrameworks/AppleKeyStore.framework/Versions/A/AppleKeyStoreKeychainDevice key bag (encryption keys)
/System/Library/PrivateFrameworks/MobileKeyBag.framework/Versions/A/MobileKeyBagNetworkModern networking framework (NWConnection)
/System/Library/Frameworks/Network.framework/Versions/A/NetworkNetworkNetwork configuration and reachability
/System/Library/Frameworks/SystemConfiguration.framework/Versions/A/SystemConfigurationHardwareDirect hardware/driver communication
/System/Library/Frameworks/IOKit.framework/Versions/A/IOKitIpcException: access additional Mach services
com.apple.security.exception.mach-lookup.global-nameIpcProtocol buffer serialization
/System/Library/PrivateFrameworks/ProtocolBuffer.framework/Versions/A/ProtocolBufferAnalyticsWireless diagnostic reporting
/System/Library/PrivateFrameworks/WirelessDiagnostics.framework/Versions/A/WirelessDiagnosticsSecurityTouch ID / Face ID / password auth
/System/Library/Frameworks/LocalAuthentication.framework/Versions/A/LocalAuthenticationSecurityApple ID authentication
/System/Library/PrivateFrameworks/AuthKit.framework/Versions/A/AuthKitSecuritySecurity framework extensions
/System/Library/Frameworks/SecurityFoundation.framework/Versions/A/SecurityFoundationSecurityKeychain, certificates, code signing
/System/Library/Frameworks/Security.framework/Versions/A/SecurityFrameworks54
AppleKeyStoreMobileKeyBagCoreCDP(weak)AppleAccount(weak)TrustedPeersOctagonTrustCoreFollowUp(weak)NetworkUserManagementlibicucore.A.dylibCBORLibrary(weak)IMFoundation(weak)TapToRadarKit(weak)MobileSoftwareUpdate(weak)RTCReporting(weak)LocalAuthenticationCrashReporterSupportKeychainCircleCloudServiceslibz.1.dylibAuthKit(weak)Accounts(weak)libprequelite.dylib(weak)libDiagnosticMessagesClient.dylibSecurityFoundationWirelessDiagnostics(weak)Foundationloginlibsqlite3.dylibCloudCoreInternal(weak)CoreFoundationIOKitCoreData(weak)ApplePushService(weak)CloudKit(weak)SystemConfigurationSecurityProtocolBuffer(weak)AppleSystemInfoSoftLinkinglibobjc.A.dyliblibSystem.B.dyliblibswiftCore.dyliblibswiftCoreFoundation.dylib(weak)libswiftCoreLocation.dylib(weak)libswiftDispatch.dylib(weak)libswiftIOKit.dylib(weak)libswiftObjectiveC.dyliblibswiftSynchronization.dyliblibswiftUniformTypeIdentifiers.dylib(weak)libswiftXPC.dylib(weak)libswift_Builtin_float.dylib(weak)libswift_Concurrency.dyliblibswiftos.dylib
Entitlements69
Interesting Strings
Bundle IDs(318)
File Paths(53)
*com.apple.private.sqlite.sqlite-encryption/AppleInternal/Library/BuildRoots/4~B_wCugD1GT6JPDmhh1RrUK5pccLqhjehz9nqD_o/Library/Caches/com.apple.xbs/Sources/AppleCredentialManager_ClientLibs/ACMLib/ACMLib.c/AppleInternal/Library/BuildRoots/4~B_wCugD1GT6JPDmhh1RrUK5pccLqhjehz9nqD_o/Library/Caches/com.apple.xbs/Sources/AppleCredentialManager_ClientLibs/common/LibCall.c/AppleInternal/Library/Frameworks/TapToRadarKit.framework/Versions/A/TapToRadarKit/Library/Keychains/TrustStore.sqlite3
telemetry(280)
OctagonSignpostNamePairingChannelAcceptorEpoch=%{public,signpost.telemetry:number1,name=OctagonSignpostNamePairingChannelAcceptorEpoch}d OctagonSignpostNamePairingChannelAcceptorVoucher=%{public,signpost.telemetry:number1,name=OctagonSignpostNamePairingChannelAcceptorVoucher}d OctagonSignpostNamePairingChannelInitiatorJoinOctagon=%{public,signpost.telemetry:number1,name=OctagonSignpostNamePairingChannelInitiatorJoinOctagon}d OctagonSignpostNamePairingChannelInitiatorPrepare=%{public,signpost.telemetry:number1,name=OctagonSignpostNamePairingChannelInitiatorPrepare}d SOSSignpostNameAssertUserCredentialsAndOptionalDSID=%{public,signpost.telemetry:number1,name=SOSSignpostNameAssertUserCredentialsAndOptionalDSID}d
URLs & Endpoints(8)
$http://crl.apple.com/codesigning.crl0%http://www.apple.com/appleca/root.crl0<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd"><?xml version="1.0" encoding="UTF-8"?> <!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd"> <plist version="1.0"> <dict> <key>general</key> <dict> <key>maxStateSize</key> <integer>250</integer> <key>maxItemAge</key> <integer>3600</integer> <key>overloadDuration</key> <integer>1800</integer> <key>name</key> <string>SOS</string> <key>MAType</key> <string></string> </dict> <key>groups</key> <array> <dict> <key>property</key> <string>global</string> <key>capacity</key> <integer>1000</integer> <key>rate</key> <integer>10</integer> <key>badness</key> <integer>1</integer> </dict> <dict> <key>property</key> <string>accessGroup</string> <key>capacity</key> <integer>50</integer> <key>rate</key> <integer>900</integer> <key>badness</key> <integer>3</integer> </dict> </array> </dict> </plist> <string>com.apple.compilers.llvm.clang.1_0</string>
Network Surfaceentitled
Networking Frameworks
Endpoints(10)
API Usage
Methods
DNA Capability Vector
Location
0
Keychain
3
Network
4
Storage
2
Hardware
1
IPC
2
Analytics
2
Security
4
System
0
Behavioral Profile
URL Endpoints
8
Telemetry Strings
280
File Paths
53
Bundle IDs
318
IOKit Constants
0
Library Functions
0
Structural HashesSHA-256
Static Libraries0 / 9749 functions identified
Functions(9749)
0x100002648sub_100002648
0x100002654sub_100002654
0x100002660sub_100002660
0x10000266csub_10000266c
0x100002678sub_100002678
0x1000026c8sub_1000026c8
0x100002738sub_100002738
0x1000027bcsub_1000027bc
0x100002910sub_100002910
0x10000294csub_10000294c
0x1000029a8sub_1000029a8
0x1000029dcsub_1000029dc
0x100002a30sub_100002a30
0x100002a54sub_100002a54
0x100002a9csub_100002a9c
0x100002ab0sub_100002ab0
0x100002b1csub_100002b1c
0x100002b88sub_100002b88
0x100002b8csub_100002b8c
0x100002bf8sub_100002bf8
Imports1709 symbols from 40 dylibs
Exports1
_mh_execute_header0x0