Mobile Sensor

Observation from the device itself

The Mobile Sensor runs on the device under investigation and records what the operating system makes available to it, then hands that record to the Lab Station as evidence.

Two platforms

Android and iOS are not the same sensor

Apple and Google expose very different amounts of information to an installed application. Rather than describe a capability that only holds on one platform, here is the honest shape of each.

Android

A full device-side forensic sensor

Inventories applications and their permissions, records name resolution including the answers, assesses device security posture, and matches indicators on the handset itself.

  • Application inventory, permissions and install provenance
  • Device security posture
  • Name resolution, questions and answers
  • On-device indicator matching

iOS

A network-observation recorder

Records the connections a device makes and the names it asks for, and signs that record using the device's hardware secure element. It does not inventory applications, read permissions, assess posture, or match indicators on the device.

  • Network flows, with directional byte and packet counts
  • Name-resolution questions
  • Evidence signed by the device's secure element
  • Collection is started and stopped by hand

Why this makes the Guardian matter more on iOS

Where the handset cannot see something, an independent network observation often can. For an iOS investigation we would generally treat Guardian observation as necessary rather than complementary — and we would rather say that than imply the two platforms deliver the same picture.

Detailed capability comparison

Some of these differences are Apple platform constraints that no engineering on our side would change. Others are gaps in our own iOS sensor, which is at an earlier stage than the Android one. The distinction matters when you are reasoning about what an absence of findings means, so it is stated per row.

Observation Android iOS
Installed application inventory Full inventory, with install source, signing details and usage timeline Not available — iOS provides no mechanism for it
Permissions held by applications Recorded, including which are granted and which are sensitive Not available
Device security posture Lock-screen state, VPN and proxy configuration, indications of rooting Not available
Name resolution — queries Recorded Recorded
Name resolution — answers Recorded Not currently recorded — a gap in our iOS sensor, not a platform restriction
Network flows Recorded, with directional byte counts Recorded, with directional byte counts and per-flow packet counts
Encrypted-session fingerprinting Recorded in the fuller collection mode Not available
Per-application attribution Partial Not available — an Apple platform constraint
Indicator matching on the device Supported, against signed indicator packages Not available — matching happens at the Lab Station
Export integrity Export carries a per-file hash manifest Export is signed on the device using its hardware secure element
Unattended collection Continues automatically once a session is started Not supported — every session is started and stopped on the device

Workflow

How a Mobile Sensor fits a case

The sensor works offline on the handset and hands its findings to the Lab Station as a discrete, checkable export.

  1. Install under authorisation

    On the device under investigation, within the authorisation covering it.

  2. Observe on the device

    Recorded locally. No network connection is required.

  3. Export

    A record of what was observed and the conditions it was observed under, carrying the integrity material appropriate to its platform.

  4. Ingest and correlate

    The Lab Station checks the export, records the result against the evidence, and correlates it against Guardian observations covering the same period.

The limits

What the Mobile Sensor is not

It is not covert software
It is an application installed with authorisation, visible on the device. It is not designed to hide from the device holder, and it is not sold as something that does.
It does not extract the device's contents
It observes activity. Full acquisition and examination remain the job of established forensic acquisition tooling.
It does not exploit the device
It works within what the operating system permits an installed application to do. That is why the iOS platform limits above exist and cannot be engineered away.
An absence of findings is not a clean bill of health
It means nothing was observed within what the platform permits the sensor to see. On iOS in particular, that is a substantially narrower statement.

Evaluate it on your own devices

A pilot includes Mobile Sensors alongside a Guardian and a Lab Station, so you can see how device-side and network observation correlate on real hardware.