PrivacyTools.io
Reviewed by Marcus Holmberg
Replace today: Norton McAfee

Device Integrity & Spyware Detection Tools in 2026

Private alternatives to Norton, McAfee, vetted against our public criteria.

Grouped by threat level

Hardened Some setup and real gains for the willing
#2
iMazing logo

iMazing

iOS and iPadOS device manager for Windows and macOS that includes a free built-in spyware analyzer, powered by MVT detection logic, to scan a device backup for signs of compromise.

Targeted Maximum effort for when you're a target

How they compare

Tool Checks Cost
Auditor
Attestation Free
Mobile Verification Toolkit
Spyware Free
iMazing
Spyware Freemium

If you worry your phone has been targeted by mercenary spyware, or you simply want to confirm your device is running the operating system it claims, these tools help you check. They range from forensic scanners that comb a backup for known traces of compromise to attestation apps that use the phone’s secure hardware to prove the system has not been tampered with. None of them cleans an infected device. Their job is to tell you, with evidence, whether something is wrong.

Why a setting can’t tell you the device is clean

A compromised phone has no honest “I have been hacked” indicator, because the whole point of advanced spyware is to leave the everyday interface looking normal. The settings screen reports what the operating system believes about itself, and that is exactly the layer a serious implant can lie to. Detection has to come from outside that trust boundary. A forensic scan reads a backup on a separate, clean computer and compares it against published indicators of compromise, while attestation leans on a hardware root the running system cannot forge. That is why these tools sit apart from anything you can toggle on the device itself.

How we pick

Every tool here is measured against our public listing criteria. We favour open methods and published indicators, so a result can be understood and checked rather than taken on trust, and we prefer tools backed by recognised security researchers or projects with a track record. We are explicit about each tool’s audience, because a forensic scanner and a one-tap attestation app serve very different users. We only list a tool we would reach for ourselves in the situation it is built for, and we are clear about what it cannot do.

What to look for in an integrity tool

Match the tool to the question you actually have. If your concern is targeted spyware, you want a forensic scanner like the Mobile Verification Toolkit that checks a backup against shared indicators of compromise and explains how to read the output. If your concern is a tampered or fake operating system, you want hardware-backed attestation such as Auditor, which verifies the device against its own secure element. Look for transparency about method, clear guidance on interpreting results, and an honest scope, because a tool that overpromises is worse than none.

Does a single hit mean my phone is infected?

Not on its own. Forensic results need careful reading, since one match against an indicator can be a false positive, an old artefact, or a benign coincidence, and reputable tools say so directly. The right way to treat a hit is as a prompt to look closer and, if the concern is serious, to involve someone with the expertise to interpret a full report. Acting on a lone signal, either by panicking or by trying a do-it-yourself cleanup, tends to make things worse rather than clearer. Evidence, not a single red flag, is what these tools are for.

How to use them

For a forensic scan, make a fresh backup of the phone, move it to a clean computer the suspect device has never touched, and run the scanner there, then follow its guidance on reading the output rather than reacting to the first line. For attestation, install the app on a supported device and check it regularly, so you are watching for change over time instead of taking a single snapshot. If the deeper worry is the platform itself, a hardened mobile OS or a more controllable phone reduces the attack surface that makes these checks necessary in the first place.

Frequently asked

Can these tools remove spyware from my phone?
No, and that is an important limit to understand. They detect and verify, they do not clean. If a scan turns up signs of compromise, the safe response is to stop using that device for anything sensitive and get expert help, not to attempt a removal yourself, since sophisticated spyware can survive a normal reset and reinstall.
Do I need to be technical to use these tools?
It varies by tool, which is why we say which is which. Some are command-line forensic scanners built for investigators and assume comfort with a terminal and phone backups. Others are ordinary apps you install and open like any other. Pick one that matches your comfort level, because a tool you cannot run correctly gives you false reassurance.
What does device attestation actually prove?
It proves that your phone is running a genuine, unmodified operating system rather than a tampered one, using a check anchored in the device's secure hardware. That tells you the foundation you are trusting has not been quietly altered. It does not scan for spyware or examine your apps, so it answers a narrower question than a forensic scan does.
Should I run a spyware scan if I am not a journalist or activist?
For most people it is not necessary, because mercenary spyware is expensive and aimed at specific high-value targets rather than the general public. The people who genuinely benefit are those in a high-risk position who have concrete reason to think they are targeted. Running a scan out of vague worry usually produces nothing useful and a lot of anxiety.
How is this different from antivirus apps?
Antivirus on a phone mostly checks installed apps against known malware and runs continuously in the background. These tools work differently: a forensic scanner inspects a full backup for traces of advanced spyware after the fact, and an attestation app verifies the operating system itself. They target the high-end threats and integrity checks that ordinary antivirus is not built to catch.
How often should I check my device?
Attestation is worth checking regularly rather than once, since the value is in spotting a change over time, and a quick recheck after a major update or a suspicious event makes sense. A forensic scan is more of an as-needed step, run when you have a specific reason to be concerned, on a fresh backup made for the purpose.