# macOS Recovery ## Identification The list spans [[macOS Recovery|macOS Recovery]], boot caching and network boot, [[NVRAM|NVRAM]], System Integrity Protection (`csrutil`), disk and image administration (`diskutil`, `hdiutil`), identity (`dscl`), network configuration (`scutil`, `ipconfig`, `netstat`, `mDNSResponder`), security/keychain interfaces (`security`), and hardware profiling. Apple documents FileVault as full-volume encryption with recovery-key or account-based recovery paths ([Apple FileVault guide](https://support.apple.com/guide/mac-help/protect-data-on-your-mac-with-filevault-mh11785/mac)). ## Notebook evidence - [[Scanned_20260730-1719#PDF page 20 — macOS recovery and command-line tool inventory|PDF page 20: macOS recovery and command-line tool inventory]] — This is a rescue-shell vocabulary sheet: the commands most useful when the graphical system is unavailable or a disk, account, boot state, or network must be diagnosed from Recovery. ## Relationships and overlays The source places this note in a shared evidence cluster with [[NVRAM|NVRAM]] · [[Scanned_20260730-1706|Scanned_20260730-1706]]. Within the larger collection, this evidence extends [[Vendor-Agnostic Recovery|vendor-agnostic recovery]] and [[Continuity Architecture|continuity architecture]] by showing how software, hardware, identity, and pre-OS control depend on recoverable interfaces. ## Evidentiary status and open leads Add command purpose, OS-version availability, required recovery mode, and read-only versus mutating risk. A bare command inventory is easy to misuse. ## Source - [[Scanned_20260730-1719|Scanned_20260730-1719]]