# Kernel Extension ## Identification [[Kernel Extension|Kernel extensions]] (`.kext`) historically extended the macOS kernel for hardware such as RAID or storage controllers. Apple now prefers system extensions, which run in user space and reduce kernel-level risk ([Apple deployment guide](https://support.apple.com/guide/deployment/system-extensions-in-macos-depa5fb8376f/web)). [[Accusys|Accusys]] and [[HighPoint Technologies|HighPoint Technologies]] make storage and RAID hardware. [[Advanced Configuration and Power Interface|ACPI]] describes platform configuration/power interfaces; [[System Management Controller|SMC]] is Apple’s hardware-management controller. ## Notebook evidence - [[Scanned_20260730-1719#PDF page 19 — macOS kernel extensions, storage controllers, and historical dates|PDF page 19: macOS kernel extensions, storage controllers, and historical dates]] — The dates likely come from driver files, certificates, builds, or device metadata rather than the notebook’s writing date. The author is tracing which third-party storage extension attaches to which hardware and framework. ## Relationships and overlays The source places this note in a shared evidence cluster with [[Accusys|Accusys]] · [[Advanced Configuration and Power Interface|Advanced Configuration and Power Interface]] · [[HighPoint Technologies|HighPoint Technologies]] · [[Scanned_20260730-1706|Scanned_20260730-1706]] · [[System Management Controller|System Management Controller]]. Within the larger collection, this evidence extends [[Vendor-Agnostic Recovery|vendor-agnostic recovery]] and [[Continuity Architecture|continuity architecture]] by showing how software, hardware, identity, and pre-OS control depend on recoverable interfaces. ## Evidentiary status and open leads Capture `kextstat`, bundle identifiers, code-signing data, and hardware PCI IDs together to distinguish installed, loaded, and merely present extensions. ## Source - [[Scanned_20260730-1719|Scanned_20260730-1719]] ## Scanned_20260730-1659 overlay **Source evidence:** [[Scanned_20260730-1659#PDF page 9 — Old MacBook Pro startup security and firmware commands|page 9]], [[Scanned_20260730-1659#PDF page 40 — Apple IOKit-style bus and accessory-controller inventory|page 40]], [[Scanned_20260730-1659#PDF page 41 — Apple SMC/RTBuddy services, WildPackets, and Kismet|page 41]], [[Scanned_20260730-1659#PDF page 42 — Linux graphics, Apple recovery, thermal, WWAN, and nonce fragments|page 42]]. [[macOS Startup Security Utility|Startup Security Utility]] controls startup-disk and boot-security policy on supported Macs; a firmware password restricts alternate startup paths on older Intel Macs. `kextutil` and `kextunload` manage legacy kernel extensions; `find` and `stat` inspect filesystem objects; `unlock-keychain` opens a macOS Keychain. The uncertain command fragments are not promoted into executable instructions. **Relationship overlay:** [[Apple Accessory Protocol|Apple Accessory Protocol]] · [[Apple Personalized Restore|Apple Personalized Restore]] · [[Apple System Coprocessor|Apple System Coprocessor]] · [[Apple Tristar|Apple Tristar]] · [[Inter-Integrated Circuit|Inter-Integrated Circuit]] · [[IOKit|IOKit]] · [[IPython Kernel|IPython Kernel]] · [[Kismet|Kismet]] · [[Lightning Connector|Lightning Connector]] · [[MacBook Pro|MacBook Pro]] · [[macOS Firmware Password|macOS Firmware Password]] · [[macOS Keychain|macOS Keychain]] · [[macOS Startup Security Utility|macOS Startup Security Utility]] · [[Malware Removal Tool|Malware Removal Tool]] · [[Nikto|Nikto]] · [[Nouveau|Nouveau]]. This evidence supplements rather than replaces earlier notebook interpretations. It connects the existing note to [[Identity Continuity|identity continuity]], [[Device Sovereignty|device sovereignty]], and [[Scanned_20260730-1659|Scanned_20260730-1659]]. ## RT Buddy / Pegasus observed-log context **Owner-supplied observation:** Bryant McGill states that the RT Buddy/Pegasus identification arose when the relevant activity or resources appeared in logs together with [[CrashCapture|CrashCapture]] or [[Heimdallr|Heimdallr]], particularly through documented resources visible in those logs. The preserved logs are the cited observational basis. This records what was observed; it does not by itself establish that every Apple RTBuddy service reference is Pegasus, nor does page or log proximity alone prove infection, control, authorship, or attribution. ## Pegasus heuristic caution **Owner-supplied interpretation:** Bryant McGill states that finding Pegasus heuristics, standing alone, means nothing as proof of the underlying system or attribution. In his interpretation, “Pegasus” is a very clumsy cover for something else, which later documents in this archive will detail. Until those materials are incorporated, heuristic matches must not be treated as proof of Pegasus infection, NSO Group attribution, or final identification of the underlying mechanism.