# macOS Recovery
## Identification
The list spans [[macOS Recovery|macOS Recovery]], boot caching and network boot, [[NVRAM|NVRAM]], System Integrity Protection (`csrutil`), disk and image administration (`diskutil`, `hdiutil`), identity (`dscl`), network configuration (`scutil`, `ipconfig`, `netstat`, `mDNSResponder`), security/keychain interfaces (`security`), and hardware profiling. Apple documents FileVault as full-volume encryption with recovery-key or account-based recovery paths ([Apple FileVault guide](https://support.apple.com/guide/mac-help/protect-data-on-your-mac-with-filevault-mh11785/mac)).
## Notebook evidence
- [[Scanned_20260730-1719#PDF page 20 — macOS recovery and command-line tool inventory|PDF page 20: macOS recovery and command-line tool inventory]] — This is a rescue-shell vocabulary sheet: the commands most useful when the graphical system is unavailable or a disk, account, boot state, or network must be diagnosed from Recovery.
## Relationships and overlays
The source places this note in a shared evidence cluster with [[NVRAM|NVRAM]] · [[Scanned_20260730-1706|Scanned_20260730-1706]].
Within the larger collection, this evidence extends [[Vendor-Agnostic Recovery|vendor-agnostic recovery]] and [[Continuity Architecture|continuity architecture]] by showing how software, hardware, identity, and pre-OS control depend on recoverable interfaces.
## Evidentiary status and open leads
Add command purpose, OS-version availability, required recovery mode, and read-only versus mutating risk. A bare command inventory is easy to misuse.
## Source
- [[Scanned_20260730-1719|Scanned_20260730-1719]]