MOBILE FORENSICS

Detecting spyware on smartphones

Suspicions of spyware often arise following unusual device behaviour or a suspicion of unauthorised access. A professional IT forensic investigation focuses on objectively examining technical evidence and evaluating it in a transparent manner.

Installed applications
Permissions and configurations
System and application logs
Persistence mechanisms
Network and communication artefacts
Known Indicators of Compromise (IoCs)

TECHNICAL BACKGROUND

Technical Fundamentals

Depending on the operating system and the data available, the following, amongst other things, can be examined:

  • Installed applications
  • Permissions and configurations
  • System and application logs
  • Persistence mechanisms
  • Network and communication artefacts
  • Known Indicators of Compromise (IoCs)

OUR APPROACH

This is how your examination will be carried out

A transparent process – from the initial enquiry to the handover of the report.

1
The investigation begins with a suitable forensic data backup. Relevant artefacts are then analysed using appropriate tools and through manual plausibility checks. Automated matches are not accepted without verification, but are technically verified and assessed within the overall context.
2
LanCologne produces private expert reports for private individuals, businesses and solicitors. Our reports have already been used in court proceedings; in some cases, we have been directly commissioned to produce IT forensic reports. Upon request, anonymised extracts from client references can be provided.

TYPICAL QUESTIONS

When is this analysis required?

  • Are there any signs of spyware?
  • Have any suspicious apps been installed?
  • Are there any anomalies in the system data?
  • Can any known IoCs be detected?
  • Is there any evidence of tampering?

LIMITATIONS & CONCLUSION

What you should know

Not all spyware leaves permanent, detectable traces. Modern malware can minimise traces or leave only a few clues behind after it has been uninstalled. Furthermore, operating system protection mechanisms and the available data set are crucial to the reliability of the findings.

Suspicions of spyware should not be based on mere conjecture. Only a structured IT forensic investigation can provide an objective assessment of the technical evidence available.

CUSTOMER REVIEWS

What our customers say

4.8 out of 5 stars on Trustpilot · 54 reviews

★★★★★

“The highest standards of professionalism, prompt service and excellent communication. They made the seemingly impossible a reality. This is what genuine customer service is all about – unrivalled in Germany!”

idalein

Verified review on Trustpilot

★★★★★

“Very helpful advice, excellent responsiveness and communication. My problem was completely resolved and the lost data was recovered. I’m very satisfied and, of course, relieved!”

Layla Pankratz

Verified review on Trustpilot

★★★★★

“My problem was sorted out professionally and quickly; everyone I spoke to was always friendly, and I can still get in touch if I have any questions – I’m very grateful for that!”

a woman from Cologne

Verified review on Trustpilot

Enquire now – free initial consultation

Do you suspect your smartphone might be infected with spyware? LanCologne can help you with an objective IT forensic investigation and a transparent technical assessment.

FREQUENTLY ASKED QUESTIONS

Frequently Asked Questions

Click on a question to see the answer.

Can spyware always be detected?

No. That depends on the available data and the characteristics of the malware.

Are unusual battery life figures proof of this?

No. There can be many technical causes.

Are iPhones and Android devices being investigated?

Yes, provided that this is technically feasible and forms part of the contract.

Can traces that have already been deleted be found?

Depending on the device, the backup method and the specific circumstances, this may be possible in some cases.

Will I receive a report?

Yes, provided that this is requested.