Forensic mobile intelligence

Detect what antivirus can't see.

SmartScan Forensic captures your device's network traffic through an encrypted WireGuard tunnel and analyses it against 200+ threat signatures — Pegasus, Predator, Graphite, Hermit, FinSpy, Candiru and hundreds more. No account required. Zero personal data collected.

Launch campaign
973 / 1,000
100% European Zero PII iOS 16+ Android 8+ MITRE ATT&CK Court-ready PDF
Why an antivirus isn't enough

Mobile antivirus is looking in the wrong place.

Consumer antivirus apps scan the filesystem and installed packages. Nation-state spyware runs from kernel memory, leaves no artifacts on disk, and communicates through encrypted C2 channels. You cannot find it with a file scanner.

Traditional antivirus
SmartScan Forensic
Scans installed apps
Analyzes network traffic
File signature matching
Behavioral + JA3/JA3S fingerprints
Blind to kernel/RAM implants
Detects covert C2 beaconing
No forensic export
Court-ready PDF with MITRE ATT&CK
Static virus database
Live threat intelligence (VirusTotal, AlienVault OTX)
One engine
22 forensic engines in parallel
High-intent spyware checks

If you searched for any of these, start with a forensic scan.

SmartScan is built for the moments when “maybe my phone is infected” is not enough. It targets the exact questions people ask after travel, legal pressure, stalking, corporate espionage, suspicious app behaviour or high-risk reporting work.

How to know if your phone is tapped

Look beyond battery drain and strange messages. SmartScan checks network behaviour for covert C2 traffic, DNS anomalies and TLS fingerprints that a file scanner cannot see.

Detect Pegasus, Predator and Graphite

Our engines look for spyware families used in state-level surveillance, including Pegasus by NSO Group, Predator by Intellexa/Cytrox, Graphite by Paragon and related zero-click infrastructure.

No-root spyware detection

No jailbreak and no root required. The app captures traffic through platform-supported VPN APIs and sends it to the forensic engine for analysis.

Anti-stalkerware and partner surveillance

Useful when you suspect commercial stalkerware, suspicious Android permissions, abnormal data usage, app-based tracking or coercive phone monitoring.

Journalists, activists, lawyers and executives

Designed for high-risk users: investigative journalists, lawyers, NGOs, politicians, executives, BYOD programmes and teams exposed to targeted surveillance.

Second-hand phone and post-travel checks

Run a complete phone security analysis after border crossings, device seizure, buying a used phone, protest attendance, corporate travel or suspected tampering.

Common warning signs

Symptoms are not proof. Network evidence is stronger.

Battery drain, overheating or strange messages can have innocent causes. SmartScan turns suspicion into forensic network evidence by checking where the phone connects, how often, and with which TLS fingerprints.

Battery drains unusually fast
Phone heats up while idle
Abnormal mobile data usage
Strange messages or missed calls
Unknown VPN, MDM or device profile
Suspicious Android app permissions
Phone activity after travel, arrest or seizure
Fear of Pegasus, Predator, Graphite or stalkerware
What we detect

The threats your phone won't warn you about.

Commercial spyware is a global industry — sold to governments, deployed against journalists, activists, executives and their families. Our engine tracks 200+ surveillance tools using JA3/JA4+ TLS fingerprinting, DNS pattern analysis, Suricata rules and behavioral heuristics.

Pegasus

NSO Group

The most infamous mobile spyware. Zero-click infection via iMessage, WhatsApp, and SMS. Documented use against 31,000+ journalists and human-rights defenders across 45+ countries.

Citizen Lab · Amnesty International

Predator

Intellexa / Cytrox

Android and iOS exploitation platform. Documented targeting of EU politicians, US officials and investigative journalists. Persistent kernel-level access with covert data exfiltration.

Google TAG · Meta Threat Research

Graphite

Paragon Solutions

Next-generation implant, RAM-resident with kernel-level persistence. Designed to bypass every consumer security stack. Recent WhatsApp campaign targeted 90+ journalists and civil society members.

Citizen Lab · Meta

Candiru

Candiru (Saito Tech)

Israeli zero-day marketplace vendor. Custom implants for high-value targets. Windows, macOS, iOS and Android exploitation with month-long persistence campaigns.

Citizen Lab · Microsoft MSTIC
200+

And 200+ more

Hermit (RCS Lab), FinSpy (FinFisher), QuaDream, commercial stalkerware, MDM abuse, and hundreds of surveillance signatures tracked by our forensic engine — including previously unseen C2 infrastructure detected before it enters public threat feeds.

How it works

A forensic scan in three steps.

No rooting. No jailbreaking. No permanent VPN. The scan runs for 15 minutes, produces a report, and then your device goes back to normal.

Install & Open

Download from the App Store or Google Play. No account. No email. No login. A random Device ID is generated locally at first launch — your identity is never known to our servers.

Start scan

Tap Start Scan. The app activates a WireGuard tunnel and captures your device's network traffic for a configurable window of 10 to 30 minutes. Use your phone normally while the scan runs — that improves detection.

Get your report

The forensic engine analyses your capture against 200+ signatures and returns a PDF report with MITRE ATT&CK mapping, IOC tables, JA3 evidence, risk scoring and chain of custody metadata. Court-admissible.

The forensic stack

22 engines. One report.

Every scan runs the full stack. No pay-to-unlock tiers, no upgrade path — the same forensic depth for every user.

01

Network Traffic Analyzer

Zeek-based behavioral protocol parser. Extracts connections, files, TLS metadata.

02

SSL / TLS Inspector

Deep TLS handshake analysis. Cipher suites, versions, ALPN, SNI.

03

JA3 Fingerprint

Client TLS fingerprinting to identify implant tooling by hash.

04

JA3S Server Fingerprint

Server-side TLS fingerprinting to identify C2 infrastructure.

05

Intrusion Detection

Suricata rules against known IOCs and exploit signatures.

06

Behavioral Analyzer

Anomaly detection on communication patterns and volumes.

07

VirusTotal Lookup

Cross-check IPs, domains and hashes against 70+ vendors.

08

AlienVault OTX

Open Threat Exchange correlation for indicators of compromise.

09

App Correlator

Match traffic to installed apps by UID (Android) and SNI heuristics.

10

File Correlator

Extract and hash transferred files, cross-check with IOC feeds.

11

Certificate Risk

TLS certificate anomalies, short-lived certs, suspicious CAs.

12

Temporal Analysis

Detect periodic beaconing intervals typical of C2 channels.

13

DNS Failover Tracker

Suspicious DNS failover chains and covert channels.

14

DNS-Less Detector

Direct-to-IP connections that bypass name resolution.

15

QUIC Analyzer

HTTP/3 and QUIC anomalies where classic tools are blind.

16

Beacon Detection

Statistical detection of Cobalt-Strike-style C2 beaconing.

17

Protocol Anomaly

Port/protocol mismatch, tunneling over unexpected channels.

18

Mobile Threat Detection

Stalkerware and MDM-abuse signatures specific to mobile.

19

Geolocation Risk

ASN, country and hosting-provider risk scoring for endpoints.

20

Advanced Heuristic

Unsupervised anomaly detection on multi-dimensional traffic features.

21

Forensic Assessment

Senior-analyst logic layer: correlates all findings into a risk narrative.

22

Report Generation

MITRE ATT&CK mapped, evidence-linked, court-ready PDF output.

Advanced tier · triggered on demand

When your scan finds something serious.

The base scan is powerful, but any forensic engine produces false positives. If your report contains Critical or High alerts, the app offers a C-Level upgrade — a deeper Bayesian double-verification pass that separates real threats from noise. Available to every user, not just executives.

Available to every user

Automatic in-app prompt

The app proposes the C-Level upgrade right after a base scan finds Critical or High alerts. No hidden menu, no upsell email — the offer appears exactly when it matters.

Bayesian double-verification

Every finding is re-examined by a second independent detection pass with different priors. Only threats confirmed by both passes make it into the C-Level report — cutting false positives without losing real signals.

JA4+ deep correlation

Expanded TLS fingerprinting with JA4+, cross-referenced against 5,000+ additional signatures and proprietary deep-packet heuristics not present in the standard pipeline.

+4 credits, no subscription

The C-Level upgrade costs 4 additional scan credits — pay only when you actually need it. No monthly fee, no invitation-only tier, no enterprise contract required.

Launch offer

Get your first scan on us.

We're giving the first 1,000 users a free forensic scan. One per device. Paste your Device ID from the app, prove you're human, and we'll credit your account.

973 / 1,000

Launch campaign

Open the app → Settings → About → tap "Copy Device ID". Paste it exactly as shown — iOS IDs may include dashes and uppercase letters.

Compliance & trust

Built for evidence. Built for privacy.

GDPR compliant

No personal data collected by default. Traffic captures are analyzed and destroyed within 24 hours.

MITRE ATT&CK

Every alert mapped to a documented tactic and technique for defensible reporting.

Certificate pinning

Dual pinning to ISRG Root X1 and our Secure Path CA — the app refuses to talk to imposters.

Secure Path Ltd

A UK-registered private company. Full corporate identity in the footer.

Availability: Available worldwide except in: China, Russia, Iran, North Korea, Syria, Cuba, Myanmar.

Get the app

Free yourself from doubt.

Free to install. Free to explore. Free to claim your first scan. Then €49 per scan — pay only for what you need, no subscription trap.

€49 per scan No subscription. No auto-renew. Buy only what you need.
Questions

Everything you might be wondering.

No. The app generates a random Device ID at first launch. No email, no name, no phone number, no personal information of any kind. You can optionally log in later to sync scan history across devices, but the core product is fully anonymous.
All traffic is captured through an encrypted WireGuard tunnel. Your real IP address, carrier and location never appear in the captured data. PCAP files are automatically deleted 24 hours after report delivery. Reports remain accessible only through your device with dual certificate pinning.
SmartScan detects 200+ surveillance tools across iOS and Android, including Pegasus (NSO Group), Predator (Cytrox/Intellexa), Graphite (Paragon Solutions), Hermit (RCS Lab), FinSpy (FinFisher), Candiru, QuaDream, and commercial stalkerware. Our engine uses JA3/JA4+ TLS fingerprinting, DNS pattern analysis, Suricata rules, behavioral heuristics and proprietary deep-packet correlation to identify both known and previously unseen C2 infrastructure — often before it enters public threat intelligence feeds.
The network capture runs for a configurable period, typically 10 to 30 minutes. After the capture, our server-side forensic engine processes the data. You typically receive your report within a few minutes of capture completion.
Yes. During the scan a VPN tunnel is active and all your internet traffic goes through it normally. You can browse, use apps, and make calls as usual. In fact, using your device normally during the scan improves detection — it generates the network patterns our engine analyses.
Yes. Reports include MITRE ATT&CK technique mapping, timestamped IOC tables, JA3 fingerprint evidence, and chain of custody metadata. They are designed to meet the evidentiary standards required by legal proceedings.
Right after the scan the app offers you the C-Level Report — a deeper analysis that performs a Bayesian double-verification pass on your findings, cleans false positives, and cross-references JA4+ and 5,000+ extended signatures. It costs 4 additional scan credits and is available to every user — not just enterprise.
The first 1,000 users get one free scan. Install the app, open it once, then copy your Device ID from Settings → About. Paste it into the claim form above and solve the captcha — one scan credit is added to your device. One per Device ID.
Antivirus scans files on disk. Nation-state spyware runs from kernel memory and leaves no files. SmartScan looks at what your device is talking to — the one thing an implant cannot hide, because it needs a network channel to exfiltrate data. See the comparison section above for the full breakdown.
Traffic captures are stored on EU servers (Germany) for a maximum of 24 hours, encrypted at rest. Deleted after report delivery. The service is operated by Secure Path Ltd, a UK-registered private company — 100% European infrastructure, no US cloud dependency.
Yes. SmartScan does not need root or jailbreak. It uses the official VPN layer to capture network behaviour and analyses it server-side for spyware indicators.
The launch campaign gives one free forensic scan to the first 1,000 eligible devices. The scan can detect Pegasus-related indicators together with many other spyware and C2 patterns.
Yes. These are good moments to run a network forensic scan because suspicious implants often reconnect after the device returns online or is used normally again.
SmartScan can detect many stalkerware and monitoring behaviours through DNS, TLS, network destinations, beaconing and app-correlation signals, especially on Android.
Yes. It can support executive protection, BYOD risk checks, corporate espionage investigations and incident response where a phone may be targeted but cannot be rooted or seized for full lab analysis.
SmartScan is a detection and reporting tool, not a removal utility. If a high-risk report is generated, follow the remediation guidance and consider forensic assistance before wiping or replacing the device.