Coverage register
At the September 30, 2026 checkpoint, the audit register contains 147,253 objects across seven inventoried source/image scopes: 85 paths have bounded semantic records (43 detailed, 42 other bounded), and 147,168 remain pending semantic reconciliation. Eight embedded components have separate bounded records. Zero whole objects are closed. These are coverage labels, not vulnerability or integrity scores.
The seven trees include 105,123 regular-file paths. Repeated or hard-linked paths are not unique binary counts. Inventory enumeration and hashing are broader than instruction-level review. Stage 5A parsed 78,465 plists, and Stage 5B classified 19 launch socket groups, but these bulk passes do not make every plist or service semantically complete. The inventory page gives per-scope counts and image formats.
The 18-phase master checklist records work in progress on preservation/metadata, disk images, RAMDisk, ramrod, USB, firmware, Secure Boot, SSV, services, signatures, kernel/cryptex, network, provenance correlation, and independent validation. Bounded stage passes are documented; the whole investigation is not complete. The active continuation is Stage 6F.7, with the exact next static trace recorded there.
| Coverage class | Meaning |
|---|---|
| Inventory observed | Path, type, and collected metadata are recorded; role may be inferred from packaging |
| Bounded path review | A named function, branch, configuration, or artifact relationship was examined with a stated limit |
| Embedded bounded review | Selected code inside a larger fileset/cache was examined; the enclosing object is not closed |
| Pending | No sufficient semantic disposition has been recorded yet |
| Whole-object closure | All relevant interfaces/dependencies reviewed to a declared scope; none claimed here |
The original master register and 12-field per-path queue remain in the private audit workspace because they contain host-specific raw evidence and extensive unreviewed paths. Public results are in the finding index, tables, and evidence index.
Eighteen-phase investigation checklist
Every phase remains IN PROGRESS at this snapshot; completed bounded passes do not close a phase. Evidence filenames in the final column refer to the retained private audit workspace unless a public page or table is linked elsewhere in this repository.
| Phase | Component | Status | Established coverage | Next gap | Evidence |
|---|---|---|---|---|---|
| 01 | Preservation and complete metadata inventory | IN PROGRESS | Seven tree inventories: 105,123 regular-file paths, no recorded enumeration/hash errors; original/copy and exact-reference comparisons retained. | Reconcile ACL/birth-time/xattr-value coverage; map every path to an explicit semantic-review disposition. | coverage.json; catalog/; STAGE2_COMPARISON.md |
| 02 | Disk images and filesystems | IN PROGRESS | RAMDisk, diagnostics, two BaseSystems, Intel Preboot and cryptex reconstructed/enumerated; read-only filesystem checks retained. | Consolidate APFS roles, UUIDs, snapshots, firmlinks and seal evidence per image; inspect unnamed embedded containers. | REPORT.md; private-evidence/volume-summary.json |
| 03 | RAMDisk architecture | IN PROGRESS | Launch definitions, binaries, kernel components and sealing plugin examined. | Finish startup ordering, shells, logging, device discovery, firmware coordination and policy relationships. | REPORT.md; STAGE4_RAMROD.md |
| 04 | Ramrod and restore pipeline | IN PROGRESS | Stages 4A–4F bounded traces recorded; Stages 4G–4I bounded receiver, guards, verifier-state and saved-context/session passes recorded. | Finish caller/options/session and verification-state trace, then checkpoints, rollback and brain acceptance. | STAGE4_RAMROD.md |
| 05 | USB and device communication | IN PROGRESS | USB profiles, 19 socket groups, remoted/PAM guards and proxy absence bounded; Stages5E–5N trace selected remote-service policy, TLS, attestation, membership and backend policy/lifecycle edges. | Finish token-use restrictions, exact transport enforcement and remaining metadata mutations; resolve per-environment services and protocol relationships; distinguish host from target. | STAGE5_CONFIGURATION.md; REPORT.md; private-evidence/ramdisk-services.json |
| 06 | Secure boot and boot chain | IN PROGRESS | Image4/EFI/trust-cache/kernel evidence established for retained artifacts. | Trace platform-specific policy/root selection and personalization; device enforcement needs hardware/runtime evidence. | STAGE3_FIRMWARE.md |
| 07 | Firmware forensics | IN PROGRESS | Catalog, IMG4/IM4M, FTAB, UARP and DP855 bounded checks; PFX/PSF vendor layouts and8CRCs reproduced. | Per-component updater/dependency/rollback map, deeper firmware control flow and encryption boundaries. | STAGE3_FIRMWARE.md |
| 08 | Option ROM and Intel boot content | IN PROGRESS | 25 ROMs,34 images,nine decompressed EFI drivers;69 Apple EFI signature checks; PSFFlasher selected PCI/update/status workflow. | Complete driver behavior and platform policy context; Product.efi trailer/plaintext unresolved. | STAGE3_FIRMWARE.md |
| 09 | Executable reverse engineering | IN PROGRESS | Standalone signature/entitlement checks and selected instruction-level traces retained. | Shared-cache extraction, ARM paths, other privileged programs and per-binary semantic coverage. | STAGE4_RAMROD.md; private-evidence/binary-analysis.json |
| 10 | Plists, manifests and configuration | IN PROGRESS | Stage 5A: 78,465 selected plist candidates parsed/hash-matched; 606 protected records remain unreadable. | Trace important consumers; collect protected records and unnamed/nonselected formats. | private-evidence/plist-index.json; private-evidence/recovery-services.json |
| 11 | Certificates, trust and signatures | IN PROGRESS | Image4, EFI, code-page and trust-cache comparisons bounded; two embedded remoted roots match Apple fingerprints and pass self-signature checks; conditional attestation/OID and expiration/chassis exceptions traced. | Exact Security/AKS/AMFDR behavior, BOM and CNKL method-2 trust, remaining certificate stores/extensions and loader policy. | STAGE3_FIRMWARE.md; STAGE2_COMPARISON.md; STAGE5_CONFIGURATION.md |
| 12 | Network and Apple service dependencies | IN PROGRESS | Stages6A–6F.6 bounded traces and partial6F.7 kernel permissions/conversion/runtime/helper census, including the static hibernation consumer, no-cache GUID-list/default gate and path-property handoff. | Finish6F.7 resync/MAC reachability, no-cache/path-property producer authority and errors, caller/helper policy and MultiUpdater errors; Q32–Q35 remain open. No traffic or firmware write observed. | STAGE6_NETWORK.md; private-evidence/stage6f7/resumption.json |
| 13 | Anomaly and compromise review | IN PROGRESS | Exact-reference reconciliation resolves earlier strict-signature alarms; no observed byte differences in corresponding update files. | Systematic per-service/entitlement/script/policy review; retain unknowns and do not infer execution. | publication/FINDINGS.csv; STAGE2_COMPARISON.md |
| 14 | Version and hardware context | IN PROGRESS | 25G83, OS 26.6.2, MacPro7,1/J160AP target metadata and 136 manifest identities retained. | Complete per-image/per-firmware version and target matrix; separate host hardware from asset targets. | REPORT.md; private-evidence/manifest-component-coverage.json |
| 15 | Public research cross-reference | IN PROGRESS | Apple, pinned OpenCore/EDK2 and format references cited next to specific claims. | Add primary citations for newly analyzed subsystems; separate documented behavior from direct observations. | publication/README.md |
| 16 | Full security report | IN PROGRESS | A partial snapshot was published previously; this revised 100-finding draft remains local and uncommitted. | Continue evidence-linked findings, coverage/limitations and reproduction material as analysis advances. | publication/README.md; publication/FINDINGS.csv |
| 17 | Supporting tools | IN PROGRESS | Existing scripts/ contains inventory, comparison and stage-specific verifiers. | New reusable tools under analysis/tools; reuse existing parsers and document exact inputs/limits in docstrings. | scripts/; analysis/tools/ |
| 18 | Investigation ledger | IN PROGRESS | Master phase/question/artifact ledgers plus147253-row twelve-field object register and per-queue remaining checklist. | 33 paths have detailed bounded twelve-field records; 42 other bounded records retain prior evidence; remaining fields and full closure remain explicit. | INVESTIGATION_STATUS.md; UNRESOLVED_QUESTIONS.md; private-evidence/coverage-ledger/object-register.csv; private-evidence/coverage-ledger/remaining-checklist.csv |