trustdFileHelper
executablemacOS168.1 KBx86_64, arm64
Security credential manager — accesses and manages keychain, certificates, and code signatures
Manages cryptographic credentials and code signing artifacts stored in the macOS Keychain. Retrieves, stores, and validates certificates and signing keys for authentication and code integrity verification. Communicates with 8 network endpoints and includes telemetry reporting. Operates through an XPC service interface for inter-process access to credential operations. Maintains private storage for credential-related data and enforces keychain access controls.AI
Fingerprint
- Platform
- macOS
- Type
- executable
- Arch
- x86_64, arm64
- Min OS
- 26.1.0
- SDK
- 26.1.0
- File Size
- 168.1 KB
- UUID
- 31F1D6F4-8F40-3719-B13F-E8BA0E210662
- Analyzed
- 2026-04-09T10:10:01Z
- CDHash
- aaa44b9722b7778a5e38a1cf40b9e0108039b7826da0b3c5e2be82e6d637157c
Capabilities
SecurityKeychain, certificates, code signing
/System/Library/Frameworks/Security.framework/Versions/A/SecurityEntitlements2
Interesting Strings
Bundle IDs(8)
File Paths(20)
telemetry(5)
Network Surface
Networking Frameworks
Endpoints(8)
DNA Capability Vector
Location
0
Keychain
0
Network
0
Storage
2
Hardware
0
IPC
0
Analytics
0
Security
1
System
0
Behavioral Profile
URL Endpoints
4
Telemetry Strings
5
File Paths
20
Bundle IDs
8
IOKit Constants
0
Library Functions
0
Structural HashesSHA-256
Static Libraries0 / 62 functions identified
Functions(62)
0x100000ce8sub_100000ce8
0x100000e70sub_100000e70
0x100000e80sub_100000e80
0x100000e8csub_100000e8c
0x100000fb0sub_100000fb0
0x100001030sub_100001030
0x10000109csub_10000109c
0x1000010acsub_1000010ac
0x1000010bcsub_1000010bc
0x1000010c8sub_1000010c8
0x1000011a0sub_1000011a0
0x1000011b4sub_1000011b4
0x1000012c0sub_1000012c0
0x1000012d4sub_1000012d4
0x100001378sub_100001378
0x1000013b0sub_1000013b0
0x1000013f8sub_1000013f8
0x100001650sub_100001650
0x100001718sub_100001718
0x10000175csub_10000175c
Imports77 symbols from 5 dylibs
Exports1
_mh_execute_header0x0