Apple Firmware Inspector
SkillSecurityApple firmware: inspect and reverse-engineer IPSWs, kernelcaches, dyld shared caches, private headers, entitlements, Mach-O binaries, KEXTs, and security internals with `ipsw`.
Use Apple Firmware Inspector in Claude, ChatGPT or Ahel Desktop
Free. Sign in, add Apple Firmware Inspector and connect your AI. About a minute.
Also: Claude Code · Cursor · Codex
Then ask your AI: use the Apple Firmware Inspector skill
Details
Instructions available. Your AI can read the instructions. Execution depends on the setup they require.
Account requirements not reviewed. Check the skill instructions before use; ahel provides instructions and does not run this skill.
No other account needed.
Add ahel to your AI once: Claude, ChatGPT, Cursor, Claude Code or Codex. Then ask it to use this.
What this skill tells your AI
The instructions your AI receives, as published by xopoko/build-swift-apps in skills/apple-firmware-inspector/SKILL.md and read by ahel’s review.
Install: brew install blacktop/tap/ipsw.
When a device target is needed, resolve current identifiers with ipsw device-list or live data. Do not copy stale iPhone identifiers.
Workflows
Firmware:
ipsw download ipsw --device "$DEVICE" --latest
ipsw download ipsw --device "$DEVICE" --latest --kernel --dyld
ipsw extract --kernel "$LATEST_IPSW"
ipsw extract --dyld --dyld-arch arm64e "$LATEST_IPSW"
ipsw extract --kernel --remote <IPSW_URL>
Userspace / dyld shared cache:
DSC=/System/Volumes/Preboot/Cryptexes/OS/System/Library/dyld/dyld_shared_cache_arm64e
ipsw dyld a2s "$DSC" 0xADDR
ipsw dyld symaddr "$DSC" "_symbol" --image Some.framework/Some
ipsw dyld disass "$DSC" --vaddr 0xADDR
ipsw dyld disass "$DSC" --symbol "_symbol" --image Some.framework/Some
ipsw dyld xref "$DSC" 0xADDR --all
ipsw dyld dump "$DSC" 0xADDR --size 256
ipsw dyld str "$DSC" "pattern" --image Some.framework/Some
ipsw dyld objc --class "$DSC" --image Some.framework/Some
ipsw dyld extract "$DSC" Some.framework/Some -o ./out/
Kernel/KEXT:
ipsw kernel kexts kernelcache.release.$DEVICE
ipsw kernel extract kernelcache sandbox --output ./kexts/
ipsw kernel syscall kernelcache
ipsw kernel kexts --diff "kernelcache_old" "kernelcache_new"
Entitlements:
ipsw macho info --ent /path/to/binary
ipsw ent --sqlite ent.db --ipsw "$LATEST_IPSW"
ipsw ent --sqlite ent.db --key "com.apple.private.security.no-sandbox"
Class dump:
ipsw class-dump "$DSC" SpringBoardServices --headers -o ./headers/
ipsw class-dump "$DSC" Security --class SecKey
ipsw class-dump "$DSC" UIKit --class 'UIApplication.*' --headers -o ./headers/
ipsw class-dump "$DSC" Security --re
Mach-O:
ipsw macho info /path/to/binary
ipsw macho disass /path/to/binary --symbol _main
ipsw macho info --sig /path/to/binary
Tips
- First
a2s/symaddrcreates cache; later lookups are faster. - Use
--image <DYLIB>for DSC operations; it is much faster. - Most commands support
--jsonfor scripting.
References
references/download.mdreferences/dyld.mdreferences/kernel.mdreferences/entitlements.mdreferences/class-dump.mdreferences/macho.md
Signals
- GitHub stars
- 45
- Forks
- 4
- Last commit
- Aug 2026
ahel review
K1binfo
installs-packages
Automated review, not a security audit. Ruleset v1+k2.
Advanced
- Item type
- skill
- Key
apple-firmware-inspector- Source
- github.com/xopoko/build-swift-apps
github.com/xopoko/build-swift-apps