Threat Detection
Threat Detection is where you go once the Dashboard has told you something is off and you want to know what kind of attack it is and which devices are behind it. The console describes it as Hacking analytics and devices information.
Open Mobile App Security → Analytics → Threat Detection.
Filters
Section titled “Filters”Same as the Dashboard: Sealing Mode, Operating System, Application, and Period.
Widgets
Section titled “Widgets”Threats Detected
Section titled “Threats Detected”The period’s total, with a toggle that switches every figure below between HACKING ATTEMPTS and UNIQUE DEVICES HACKING ATTEMPTS, then a breakdown across the threat categories:
| Category | Detected when |
|---|---|
| Code Hooking | A hooking framework manipulates the app at runtime. |
| Malware & Cheat Tool | A cheat tool or known malicious package is present. |
| App Cloning Environment | The app runs in a virtual space, dual-app, or cloned environment. |
| Application Debugging | A debugger is attached to the app. |
| Rooted Device | The device is rooted. |
| Application Repackaging | The app has been repackaged or resigned. |
| Security Config Manipulation | Security settings have been tampered with or disabled. |
| Source Code Modification | App code or binary has been modified. |
| Emulator | The app runs in an emulator. |
| USB Debugging | ADB/USB debugging is enabled. |
| Speed Modification | A speedhack is altering system time or speed. |
| Other | Detections not covered above. |
Threats Types
Section titled “Threats Types”A donut chart of the same breakdown, showing each category’s share of the period’s detections.
Hacking Attempts By Device Information
Section titled “Hacking Attempts By Device Information”Device-level detail for the riskiest detections. The console notes that this table excludes cheat tool and app cloning environment entries, because they occur more often than their severity warrants — so the list stays focused on devices worth investigating.
FILTER narrows the list, EXPORT downloads it, and Fetch limit controls how many records are retrieved.
| Column | Group | Meaning |
|---|---|---|
| Reported On | Device Details | When the detection was reported. |
| Android Id | Device Details | The device’s SSAID. |
| Model Name | Device Details | Device model. |
| Android Version | Device Details | OS version. |
| Country | Device Details | Where the detection came from. |
| Attempts | Hacking Details | Number of attempts recorded. |
| Rooting | Hacking Details | Whether the device is rooted. |
| Hacking Type | Hacking Details | The threat category. |
Hacking Type
Section titled “Hacking Type”A daily stacked chart across the period with one series per category, so you can see when a particular attack type started or stopped.
OS Version and Rooting
Section titled “OS Version and Rooting”Three percentage cards summarising how the period’s detections distribute across OS Version - Major, OS Version - Minor, and Rooting.
Hacking Attempts By Map Overlay
Section titled “Hacking Attempts By Map Overlay”A world map of the period’s detections, paired with Hacking Attempts By Country List:
| Column | Meaning |
|---|---|
| Country | Country the detections came from. |
| Hacking Attempts | Detections from that country. |
| Unique Devices Hacking Attempts | Distinct devices behind them. |