Skip to the content.

Research documentation

Home · Findings · Evidence · Status

The pages below preserve the detailed analysis from the September 27, 2026 audit snapshot. They report measured bytes, selected static paths, and unresolved boundaries separately. Addresses refer to the exact named build and binary, not arbitrary macOS releases.

Read in this order Page
1. Scope and results Audit overview, methodology, coverage, limitations
2. Objects and workflow Provenance, inventory and images, architecture, RAMDisk/ramrod, installer workflow
3. Trust and boot Code signing/KCs, Image4/trust/Secure Boot, sealed system volume, OpenCore assessment
4. Device communication USB/services/TLS, mobile-device components, restore networking/FDR
5. Firmware Catalog/Option ROMs, PFX, PSF and updater handoff
6. Kernel and policy Stage 6F.7 NVRAM/EFI, sandbox, AMFI, APFS/Device Tree, reverse-engineering map
7. Reproduce and continue Findings index, source narrative coverage, reproduction, corrections, open questions, audit status, references

The finding groups preserve all 100 original IDs across reference, RAMDisk, USB, signatures, firmware, configuration, remote services, and network categories. The source crosswalk, public tables, and evidence index help reviewers trace the published claims without distributing copyrighted binaries or private raw logs.

The diagrams have rendered SVGs and editable Mermaid sources, with text explanations on their subject pages. The local Pages instructions cover the site build and navigation check. The CI workflow validates but does not deploy this draft.