MOBILE FORENSICS

Malware Indicators (IoCs), MVT and YARA

Various technical methods are used when examining a smartphone for malware. Indicators of Compromise (IoCs), YARA rules and – depending on the specific issue – tools such as the Mobile Verification Toolkit (MVT) are particularly important. They help to identify known anomalies, but are no substitute for a full forensic assessment.

Forensic analysis
Documentation admissible in court
GDPR-compliant processing
Experienced experts

TECHNICAL BACKGROUND

Technical Fundamentals

Indicators of Compromise (IoCs) are known technical characteristics that may indicate a potential compromise, such as files, processes, domains or other artefacts.

MVT is used to analyse specific mobile artefacts and compare them with known IoCs.

YARA rules enable the detection of specific patterns in files or memory images and are frequently used for malware classification.

OUR APPROACH

This is how your examination will be carried out

A transparent process – from the initial enquiry to the handover of the report.

1
Appropriate tools are used depending on the specific issue and the available data. Matches identified through IoC comparisons, MVT or YARA are always checked manually and correlated with other artefacts. Automated results alone are not considered sufficient evidence of a compromise.
2
LanCologne produces private expert reports for private individuals, companies and solicitors. Our reports have already been used in court proceedings. In some cases, we have been directly commissioned to produce IT forensic reports. Upon request, anonymised extracts from our client references can be provided.

TYPICAL QUESTIONS

When is this analysis required?

  • Are there any known IoCs?
  • Is it possible to identify suspicious files?
  • How reliable are MVT hits?
  • Can YARA rules detect relevant artefacts?
  • How are automated matches assessed?

LIMITATIONS & CONCLUSION

What you should know

IoCs describe known attack patterns. New or previously unknown malware may therefore go undetected. Similarly, automated detections may contain misinterpretations. It is therefore always necessary to carry out a technical plausibility check.

IoCs, MVT and YARA are valuable tools in modern IT forensic malware investigations. However, their findings only become truly meaningful when combined with a comprehensive technical analysis.

CUSTOMER REVIEWS

What our customers say

4.8 out of 5 stars on Trustpilot · 54 reviews

★★★★★

“The highest standards of professionalism, prompt service and excellent communication. They made the seemingly impossible a reality. This is what genuine customer service is all about – unrivalled in Germany!”

idalein

Verified review on Trustpilot

★★★★★

“Very helpful advice, excellent responsiveness and communication. My problem was completely resolved and the lost data was recovered. I’m very satisfied and, of course, relieved!”

Layla Pankratz

Verified review on Trustpilot

★★★★★

“My problem was sorted out professionally and quickly; everyone I spoke to was always friendly, and I can still get in touch if I have any questions – I’m very grateful for that!”

a woman from Cologne

Verified review on Trustpilot

Enquire now – free initial consultation

Do you need a thorough malware analysis incorporating known IoCs and forensic tools? LanCologne can assist you with an objective technical investigation.

FREQUENTLY ASKED QUESTIONS

Frequently Asked Questions

Click on a question to see the answer.

What are IoCs?
Technical characteristics that may indicate a possible compromise.
Can MVT detect all spyware?
No. The tool uses well-known indicators and has technical limitations.
What are YARA rules used for?
For identifying characteristic patterns in files or datasets.
Are automated matches sufficient?
No. They must always be subject to expert review.
Can an expert report be drawn up on this?
Yes, provided that this forms part of the contract.