Auditor
Android app by GrapheneOS that uses hardware-backed attestation to verify the integrity and authenticity of a supported device and its operating system, confirming it has not been tampered with.
Private alternatives to Norton, McAfee, vetted against our public criteria.
Grouped by threat level
Android app by GrapheneOS that uses hardware-backed attestation to verify the integrity and authenticity of a supported device and its operating system, confirming it has not been tampered with.
Command-line forensic tool developed by Amnesty International's Security Lab to analyze iOS and Android device backups and logs for indicators of compromise by mercenary spyware such as Pegasus.
No matches for those filters.
| Tool | Checks | Cost |
|---|---|---|
| | Attestation | Free |
| Spyware | Free |
| | Spyware | Freemium |
If you worry your phone has been targeted by mercenary spyware, or you simply want to confirm your device is running the operating system it claims, these tools help you check. They range from forensic scanners that comb a backup for known traces of compromise to attestation apps that use the phone’s secure hardware to prove the system has not been tampered with. None of them cleans an infected device. Their job is to tell you, with evidence, whether something is wrong.
A compromised phone has no honest “I have been hacked” indicator, because the whole point of advanced spyware is to leave the everyday interface looking normal. The settings screen reports what the operating system believes about itself, and that is exactly the layer a serious implant can lie to. Detection has to come from outside that trust boundary. A forensic scan reads a backup on a separate, clean computer and compares it against published indicators of compromise, while attestation leans on a hardware root the running system cannot forge. That is why these tools sit apart from anything you can toggle on the device itself.
Every tool here is measured against our public listing criteria. We favour open methods and published indicators, so a result can be understood and checked rather than taken on trust, and we prefer tools backed by recognised security researchers or projects with a track record. We are explicit about each tool’s audience, because a forensic scanner and a one-tap attestation app serve very different users. We only list a tool we would reach for ourselves in the situation it is built for, and we are clear about what it cannot do.
Match the tool to the question you actually have. If your concern is targeted spyware, you want a forensic scanner like the Mobile Verification Toolkit that checks a backup against shared indicators of compromise and explains how to read the output. If your concern is a tampered or fake operating system, you want hardware-backed attestation such as Auditor, which verifies the device against its own secure element. Look for transparency about method, clear guidance on interpreting results, and an honest scope, because a tool that overpromises is worse than none.
Not on its own. Forensic results need careful reading, since one match against an indicator can be a false positive, an old artefact, or a benign coincidence, and reputable tools say so directly. The right way to treat a hit is as a prompt to look closer and, if the concern is serious, to involve someone with the expertise to interpret a full report. Acting on a lone signal, either by panicking or by trying a do-it-yourself cleanup, tends to make things worse rather than clearer. Evidence, not a single red flag, is what these tools are for.
For a forensic scan, make a fresh backup of the phone, move it to a clean computer the suspect device has never touched, and run the scanner there, then follow its guidance on reading the output rather than reacting to the first line. For attestation, install the app on a supported device and check it regularly, so you are watching for change over time instead of taking a single snapshot. If the deeper worry is the platform itself, a hardened mobile OS or a more controllable phone reduces the attack surface that makes these checks necessary in the first place.