Join our Newsletter — 33% off our NHI Course
Architecture & Implementation

Load Command

← Back to Glossary
By NHI Mgmt Group Updated September 30, 2026 Domain: Architecture & Implementation

A directive embedded in a Mach-O binary that tells the dynamic linker what to do before the app starts. Load commands can reference shared libraries, frameworks, and other runtime dependencies. If altered, they can change which code is loaded and executed at launch.

What a load command is in Mach-O

A load command is part of the Mach-O file format’s launch-time metadata. It tells the dynamic linker what the binary needs before execution begins, including which shared libraries, frameworks, and runtime structures should be loaded.

How load commands shape app startup

Load commands are read early in the process startup path, so they influence how the operating system resolves dependencies and prepares the image for execution. They can describe segments, entry-related metadata, code-signing references, and other directives that affect what gets mapped into memory and in what order.

That makes them more than bookkeeping. In practice, they help define the binary’s launch contract, because the app’s initial execution state depends on what the loader learns from those commands.

Why load commands matter for binary integrity

Because load commands can point to code that is loaded at launch, they sit close to a trust boundary. If an attacker or careless build process changes them, the binary may resolve different dependencies, use unexpected frameworks, or fail to start safely.

Load-command manipulation is therefore part of broader executable integrity concerns. Even when the source code is unchanged, altering launch metadata can change the runtime behavior the user actually receives.

Common change patterns and dependencies

Typical load commands describe where the system should find libraries, how the binary is laid out in memory, and which runtime features it expects. Some are structural, while others are dependency-related and directly affect launch behavior.

  • Dependency resolution, such as references to dynamic libraries or frameworks.
  • Runtime layout and segment information used by the loader.
  • Launch metadata that influences code loading, symbol resolution, and startup sequencing.

In security review, the key question is whether the command set still matches the intended build artifact. A mismatch can indicate tampering, repackaging, or an unexpected build change that deserves investigation.

Risk and Threat Considerations

Load commands can be abused because they determine what the dynamic linker trusts and loads at startup. A malicious or altered command can redirect execution toward unexpected code, interfere with dependency resolution, or support binary tampering and persistence mechanisms.

Failure mechanism: An attacker or faulty packaging step changes launch metadata so the loader resolves a different library, framework, or runtime path than the one originally intended.

Impact: The application may execute unintended code, fail integrity checks, crash on startup, or silently inherit a compromised dependency chain.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK addresses the attack and risk surface, while NIST SP 800-53 Rev 5 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST SP 800-53 Rev 5SI-7 — Software, Firmware, and Information IntegrityMach-O load commands affect executable integrity and trusted code loading.
CM-2 — Baseline ConfigurationKnown-good binary metadata needs a controlled baseline to spot tampering.
Recommendation — Verify signed binaries and investigate unexpected load-command changes before release. Maintain a trusted baseline for Mach-O metadata and flag drift in load commands.
CIS Controls v8CIS-2 — Inventory and Control of Software AssetsBinary loading depends on knowing which executable artifacts and dependencies are approved.
Recommendation — Track approved app binaries and compare launch metadata against the software inventory.
MITRE ATT&CKT1574 — Hijack Execution FlowAltering loader-directed metadata can redirect what code executes at launch.
Recommendation — Hunt for execution-flow hijacking when a Mach-O binary loads unexpected dependencies.

Practitioner Guidance

What to watch for: Treat load-command changes as a binary-integrity event, not a routine metadata edit. Unexpected differences between a signed or released artifact and its known-good baseline deserve review because they can alter runtime behavior without changing visible source files.

Practitioner takeaway: For release and incident review, compare Mach-O load commands against a trusted baseline so dependency and launch-path changes are detected before distribution.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 30, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org