Jump to content
5 posts in this topic

Recommended Posts

Hi all — Kernel Inspector just got a big update (1.1.0). It still opens a .kext bundle or any Mach-O binary and lets you dig through it (think a lightweight Hopper), but the Hackintosh side has grown a lot: it now generates SSDTs, derives OpenCore patches from your own machine, and maps USB ports — on top of the install/maintenance chores it already did.

Download: https://github.com/luminadevapps/KernelInspector/releases
Source: https://github.com/luminadevapps/KernelInspector


NEW IN 1.1.0

- SSDT Generator — pick your hardware, generate the maintenance SSDTs (AWAC, PMC, USBX, EC, PNLF, GPRW, RHUB, ALS0…), compile DSL → AML with iasl, then install the .aml straight into a mounted OpenCore EFI and register it under config.plist → ACPI → Add. It even adds the required renames (EC→EC0, _GPRW→XGPW) for you.
- USB Ports — live view of your USB controllers from IOKit. Toggle which ports to keep, set each connector type, and auto-trim to the 15-port cap.
- XCPM / CPU — the verified CPU power-management + topology patch set (AppleXcpmExtraMsrs, AppleCpuPmCfgLock, core-count fixes). Copy any entry as a config.plist patch, or verify it against your live Kernel Collection after a macOS update.
- Port-Limit Patch — derives the XHCI port-limit patch from real bytes (a loaded binary or your live Kernel Collection) instead of a hard-coded pattern that only matches one build, with an optional universal (masked) variant.
- Install Kexts now also targets a mounted OpenCore EFI and can restore AppleHDA on Tahoe via a KDK root patch; Maintenance gained per-volume config.plist access.


WHAT IT DOES

Analyze
- Info.plist — kext identifier, version, UUID, linked libs, full searchable Info.plist
- Hex Editor — byte view with hex find & replace and patch-to-file
- Symbols — full nlist_64 table with global/local/undefined/debug filters
- Disassembly — ARM64 / x86-64 of __text, colour-coded by branch/call/return
- Control Flow — per-function basic-block graph
- Pseudocode — heuristic pseudo-C (readability aid, not a decompiler)
- Port-Limit Patch — derive an XHCI port-limit OpenCore patch from real bytes

System (Hackintosh)
- Install Kexts — readiness dashboard (SIP / macOS build / target / cache tool), install a .kext to /Library/Extensions or into your OpenCore EFI (auto-adds Kernel→Add + plugins to config.plist, backs it up first), rebuild caches, restore AppleHDA (Tahoe/KDK), uninstall
- Maintenance — ESP-mounter style EFI partition mount/unmount, Kernel Debug Kit manager, per-volume config.plist viewer, APFS snapshot cleanup
- USB Ports — live IOKit port map with keep/trim and the 15-port cap check
- XCPM / CPU — verified CPU/XCPM patch set, checked against your live kernel
- SSDT Generator — generate, compile and install OpenCore SSDTs from your hardware

All privileged steps use the standard macOS admin prompt — the app never sees your password.


INSTALL

1. Download KernelInspector-1.1.0.dmg from the Releases page
2. Drag Kernel Inspector into Applications
3. First launch only: right-click → Open → Open (it's ad-hoc signed, not notarized)

Needs macOS 13+ and the Xcode Command Line Tools (xcode-select --install) — the disassembler shells out to otool/llvm-objdump. The SSDT Generator's compile step needs iasl (e.g. brew install acpica).


NOTES

Pseudocode/CFG are heuristic. Parser targets 64-bit Mach-O. The XCPM/CPU patches are verified on a specific machine (i9-13900K, macOS 26.x) — always re-verify against your own kernel after an update. The port-limit patch is a temporary aid for USB mapping; drop it once you've built a proper USBMap. It's a study/RE + Hackintosh aid for hardware you own. Feedback and bug reports welcome — cheers!
 

 

Screenshot2026-07-25at08_13_40.thumb.png.95582d384cda231a9b9a635d2a10891a.png

Screenshot2026-07-25at08_14_03.thumb.png.432498e5b40aa9e3ce3bcba9e480a382.png

Screenshot2026-07-25at08_14_29.thumb.png.ca9fb731bfe226b23cb0bcc7d65579dd.png

Screenshot2026-07-25at08_14_44.thumb.png.70797869602bca0dd6109b0b66b9002e.png

Screenshot2026-07-25at08_15_03.thumb.png.ff18b79f560d57ba3f64d40f9b4053b0.png

Screenshot2026-07-25at08_15_17.thumb.png.1c4b81715f6017a920f71c38f0c539cd.png

Screenshot2026-07-25at08_15_26.thumb.png.03a67e3114a75455d4c730818556bd0b.png

Screenshot2026-07-25at08_16_49.thumb.png.fe64fe06fc29e150b9dcf20d0fe4fb8f.png

Screenshot2026-07-25at08_17_09.thumb.png.83250b91f2bf7f606a193c4db1d8cd1e.png

Screenshot2026-07-25at08_17_22.thumb.png.6a0e1606079e4e471f4f89158861f062.png
 

 

 

 

 

Edited by Luminadevapps
  • Like 3

Great work!

Will be nice to have a column with a hex value of the instruction before disassemble.

address |  hex         | instruction

0x1234     0x0bfe     BR .-2

It was in HopperD version 3 but escaped in new versions.

  • Like 2

Hi all 👋

Started as a simple kext / Mach-O analyzer (Info.plist, hex, symbols, disassembly, control flow, pseudocode) and grew into a full toolbox:

  • Mount EFI + install kexts and auto-register them in config.plist
  • SSDT generator (compiles to .aml with iasl)
  • XHCI port-limit patch — reads your live kernel and spits out the exact Find/Replace + config.plist entry for yourbuild. Optional masked mode so it survives macOS updates.
  • USB port viewer + map exporter
  • XCPM / CPU patch verifier — one click tells you if your CPU patches still match after an update

Screenshot2026-07-23at08_33_54.thumb.png.440cdde07fc82efe2ef0a282bd10d53f.png

 

Screenshot2026-07-23at08_35_49.thumb.png.bfd797fcb2bbda7ba2ae654c526f2f52.png

 

Screenshot2026-07-23at08_36_01.thumb.png.16c0e76a3f39438cd1ca140246b24587.png

 

 

Screenshot 2026-07-23 at 08.35.27.png

 

The whole idea: stop hunting for byte patterns that break on every macOS update — derive them from your own kernel and verify them in seconds.

Running great here on Z790 + i9-13900K, macOS 26.5. Still improving it — what would you want added?

Edited by Luminadevapps
On 7/21/2026 at 2:29 AM, Slice said:

Great work!

Will be nice to have a column with a hex value of the instruction before disassemble.

address |  hex         | instruction

0x1234     0x0bfe     BR .-2

It was in HopperD version 3 but escaped in new versions.

Thanks! 🙏 Great suggestion — just added it. New Hex column in the Disassembly view (Address | Hex | Instruction), Hopper-v3 style. You can even filter by the hex bytes now to jump straight to an instruction. Screenshot below 👇

Screenshot2026-07-23at09_13_45.thumb.png.ce6df71b0db1feaf86d4b953faf090d6.png

 

Screenshot2026-07-23at09_14_05.thumb.png.1a82351779067b3b6097f0e35bf74664.png

 

 

  • Like 2
  • Thanks 1

Hi all — Kernel Inspector just got a big update (1.1.0). It still opens a .kext bundle or any Mach-O binary and lets you dig through it (think a lightweight Hopper), but the Hackintosh side has grown a lot: it now generates SSDTs, derives OpenCore patches from your own machine, and maps USB ports — on top of the install/maintenance chores it already did.

Download: https://github.com/luminadevapps/KernelInspector/releases
Source: https://github.com/luminadevapps/KernelInspector


NEW IN 1.1.0

- SSDT Generator — pick your hardware, generate the maintenance SSDTs (AWAC, PMC, USBX, EC, PNLF, GPRW, RHUB, ALS0…), compile DSL → AML with iasl, then install the .aml straight into a mounted OpenCore EFI and register it under config.plist → ACPI → Add. It even adds the required renames (EC→EC0, _GPRW→XGPW) for you.
- USB Ports — live view of your USB controllers from IOKit. Toggle which ports to keep, set each connector type, and auto-trim to the 15-port cap.
- XCPM / CPU — the verified CPU power-management + topology patch set (AppleXcpmExtraMsrs, AppleCpuPmCfgLock, core-count fixes). Copy any entry as a config.plist patch, or verify it against your live Kernel Collection after a macOS update.
- Port-Limit Patch — derives the XHCI port-limit patch from real bytes (a loaded binary or your live Kernel Collection) instead of a hard-coded pattern that only matches one build, with an optional universal (masked) variant.
- Install Kexts now also targets a mounted OpenCore EFI and can restore AppleHDA on Tahoe via a KDK root patch; Maintenance gained per-volume config.plist access.


WHAT IT DOES

Analyze
- Info.plist — kext identifier, version, UUID, linked libs, full searchable Info.plist
- Hex Editor — byte view with hex find & replace and patch-to-file
- Symbols — full nlist_64 table with global/local/undefined/debug filters
- Disassembly — ARM64 / x86-64 of __text, colour-coded by branch/call/return
- Control Flow — per-function basic-block graph
- Pseudocode — heuristic pseudo-C (readability aid, not a decompiler)
- Port-Limit Patch — derive an XHCI port-limit OpenCore patch from real bytes

System (Hackintosh)
- Install Kexts — readiness dashboard (SIP / macOS build / target / cache tool), install a .kext to /Library/Extensions or into your OpenCore EFI (auto-adds Kernel→Add + plugins to config.plist, backs it up first), rebuild caches, restore AppleHDA (Tahoe/KDK), uninstall
- Maintenance — ESP-mounter style EFI partition mount/unmount, Kernel Debug Kit manager, per-volume config.plist viewer, APFS snapshot cleanup
- USB Ports — live IOKit port map with keep/trim and the 15-port cap check
- XCPM / CPU — verified CPU/XCPM patch set, checked against your live kernel
- SSDT Generator — generate, compile and install OpenCore SSDTs from your hardware

All privileged steps use the standard macOS admin prompt — the app never sees your password.


INSTALL

1. Download KernelInspector-1.1.0.dmg from the Releases page
2. Drag Kernel Inspector into Applications
3. First launch only: right-click → Open → Open (it's ad-hoc signed, not notarized)

Needs macOS 13+ and the Xcode Command Line Tools (xcode-select --install) — the disassembler shells out to otool/llvm-objdump. The SSDT Generator's compile step needs iasl (e.g. brew install acpica).


NOTES

Pseudocode/CFG are heuristic. Parser targets 64-bit Mach-O. The XCPM/CPU patches are verified on a specific machine (i9-13900K, macOS 26.x) — always re-verify against your own kernel after an update. The port-limit patch is a temporary aid for USB mapping; drop it once you've built a proper USBMap. It's a study/RE + Hackintosh aid for hardware you own. Feedback and bug reports welcome — cheers!
Screenshot2026-07-25at08_13_40.thumb.png.32dbe29f31c8e4d42a967bf885cae7c6.png

 

Screenshot2026-07-25at08_14_03.thumb.png.023fd411123c292b626373d94e7e4291.png

 

Screenshot2026-07-25at08_14_29.thumb.png.9f6d5a4d81c63e958c7ac594b5b458b3.png

 

Screenshot2026-07-25at08_14_44.thumb.png.f83edaa64b5f81712453f8d2678e9e31.png

 

Screenshot2026-07-25at08_15_03.thumb.png.0536c7da2df197bd20ce9a20424d03a0.png

 

Screenshot2026-07-25at08_15_17.thumb.png.bc32840913f5f9a4bb828db4fe9819b7.png

 

Screenshot2026-07-25at08_15_26.thumb.png.6a16408bee02910ac63c29cf251997c1.png

 

Screenshot2026-07-25at08_17_09.thumb.png.bd3c226e27c75ca53890735a7302e598.png

 

Screenshot2026-07-25at08_17_22.thumb.png.702eecef8adaa6483028d77736d2ebaa.png

 

Screenshot 2026-07-25 at 08.16.49.png

×
×
  • Create New...