Digital Forensics · iOS & Android

MobileSentry

Detect and attribute the world's most advanced mobile spyware — Pegasus, Predator, Graphite and more — on iPhone and Android. Court-grade forensic triage that runs on-premises, air-gapped, and fully under your control.

On-prem & air-gapped Data stays in-country iOS & Android Court-grade evidence
5+
spyware families detected
7
detection layers
iOS+Android
device coverage
Air-gapped
sovereign deployment
Multi-layer forensic analysis
Overview

Find the spyware. Name the operator.

MobileSentry ingests a consented iOS or Android acquisition and runs a seven-layer detection stack — signatures, behavioural heuristics, protocol-agnostic network analysis, spectral beaconing, kill-chain correlation, machine learning, and a behavioural-invariant engine that catches novel and re-tooled variants. It attributes the spyware family with confidence, links the device to any wider targeting campaign, and produces a court-grade report with a tamper-evident chain of custody. It runs entirely on-premises or air-gapped — the device data never leaves your control.

Core Capabilities

What MobileSentry delivers

Spyware attribution

Detects and names Pegasus, Predator, Graphite, NoviSpy and Hermit — with confidence scoring and reported-operator context.

Novel-variant detection

A behavioural-invariant engine catches spyware by function — exfiltration, covert C2, persistence, sensor capture — defeating renamed and re-tooled variants.

Seven-layer engine

Signatures, heuristics, protocol-agnostic flow, spectral beaconing, kill-chain correlation and ML — corroborated into one clear verdict.

Campaign correlation

Links devices that share C2, indicators or a spyware family into a single targeting campaign — intelligence, not isolated cases.

AI investigation agent

Run the whole investigation in natural language and get answers, charts and reports — with repeatable IR playbooks.

Court-grade evidence

SHA-256 acquisition manifests, a tamper-evident audit chain, signed evidence bundles, MITRE ATT&CK mapping and STIX 2.1 export.

How it works

From a device to a defensible report

01

Acquire

Consented iOS/Android acquisition; a SHA-256 manifest locks the evidence.

02

Analyze

Seven detection layers run in parallel and corroborate.

03

Attribute

Identify the spyware family and reported operator.

04

Correlate

Link the device to any fleet-wide campaign.

05

Report

Court-grade report with full chain of custody.

Threats covered

Families MobileSentry detects

Pegasus · NSO Group

  • BridgeHead / late-stage process traces
  • CrashReporter anti-forensic tampering
  • Network-injection C2 topology

Predator · Intellexa

  • ALIEN loader / process spoofing
  • Keybag & Shortcuts persistence
  • Single-click delivery vectors

Graphite, NoviSpy & Hermit

  • Raw-IP C2 (Graphite / Paragon)
  • Fake-updater persistence (NoviSpy)
  • Modular RCS Lab components (Hermit)

Behavioural-invariant and machine-learning layers extend coverage to novel and re-tooled variants beyond documented families.

Sovereign by design

Runs in-country — on-premises and air-gapped

MobileSentry deploys inside a national security network or a sealed, air-gapped environment. Acquisition and analysis stay on your infrastructure; device data never leaves the country. Offline license verification means no dependency on any foreign cloud.

Air-gapped / offline

Sealed networks — no outbound connection required.

On-premises

Runs in your own datacentre, under your control.

Data sovereignty

All acquisition & analysis data stays in-region.

Zero-retention scanning

Devices analysed without the raw backup leaving the operator.

National CERT integration

STIX 2.1 export into MISP, TheHive and CERT workflows.

Chain of custody

Hash-chained audit + signed evidence bundles for court.

CoverageiOS & iPadOSAndroidMITRE ATT&CK MobileSTIX 2.1
Standards & engineering alignment

Fits your compliance environment

Built to fit inside the engineering, safety and compliance frameworks your organization already operates under.

ISO/IEC 27001

Information security management

Deployable inside an ISMS — data stays in your boundary, with access control and audit trails.

ISO 55000

Asset management

Supports condition- and risk-based asset decisions with defensible evidence.

Data protection

GDPR / regional privacy

Read-only, on-prem or private-cloud options keep sensitive data under your control.

Designed to support and align with the frameworks above. Alignment describes how the platform fits your program; it is not a claim of independent certification unless separately stated.

Built for your scale

From a single team to the whole enterprise

MobileSentry is designed to deliver value on day one for a small team, and to scale to a governed, multi-site enterprise deployment on the same platform.

For growing & mid-size businesses

Triage a suspected device in minutes — a clear verdict, not a raw log dump
Runs on a single on-prem box or an air-gapped laptop; no cloud account needed
Names the spyware family and the reported operator, with a court-ready report
One analyst can run it from natural language — no scripting required

For large organizations

National-scale triage across many devices, with fleet-wide campaign correlation
Fully on-premises or air-gapped — device data never leaves your jurisdiction
Tamper-evident chain of custody, signed evidence bundles and STIX 2.1 for CERT & court
Behavioural-invariant and ML layers extend coverage to novel and re-tooled variants
In practice

Deployment scenarios

Illustrative walkthroughs of how MobileSentry is used and the value it creates. Your figures are set on your own data during a proof-of-value engagement.

Targeted-official triage

A minister's phone is acquired on-site; MobileSentry attributes the implant, names the reported operator and produces a signed report — all inside the secure facility.

Coordinated campaign

Several flagged devices are found to share the same C2 and family, revealing a single targeting campaign rather than isolated incidents.

Sovereign deployment

The platform runs air-gapped for a national CERT; all acquisition and analysis data stays in-country, with STIX export into existing MISP workflows.

Proof of value

See it on your own data

A scoped engagement shows the results measured on your own operation before any wide rollout — then scale across the organization on the same platform.

Book a proof of value