Skip to content
This documentation is also available as markdown. For a complete index of all pages, see llms.txt at /llms.txt

Threat Detection

Threat Detection is where you go once the Dashboard has told you something is off and you want to know what kind of attack it is and which devices are behind it. The console describes it as Hacking analytics and devices information.

Open Mobile App Security → Analytics → Threat Detection.

Same as the Dashboard: Sealing Mode, Operating System, Application, and Period.

The period’s total, with a toggle that switches every figure below between HACKING ATTEMPTS and UNIQUE DEVICES HACKING ATTEMPTS, then a breakdown across the threat categories:

CategoryDetected when
Code HookingA hooking framework manipulates the app at runtime.
Malware & Cheat ToolA cheat tool or known malicious package is present.
App Cloning EnvironmentThe app runs in a virtual space, dual-app, or cloned environment.
Application DebuggingA debugger is attached to the app.
Rooted DeviceThe device is rooted.
Application RepackagingThe app has been repackaged or resigned.
Security Config ManipulationSecurity settings have been tampered with or disabled.
Source Code ModificationApp code or binary has been modified.
EmulatorThe app runs in an emulator.
USB DebuggingADB/USB debugging is enabled.
Speed ModificationA speedhack is altering system time or speed.
OtherDetections not covered above.

A donut chart of the same breakdown, showing each category’s share of the period’s detections.

Device-level detail for the riskiest detections. The console notes that this table excludes cheat tool and app cloning environment entries, because they occur more often than their severity warrants — so the list stays focused on devices worth investigating.

FILTER narrows the list, EXPORT downloads it, and Fetch limit controls how many records are retrieved.

ColumnGroupMeaning
Reported OnDevice DetailsWhen the detection was reported.
Android IdDevice DetailsThe device’s SSAID.
Model NameDevice DetailsDevice model.
Android VersionDevice DetailsOS version.
CountryDevice DetailsWhere the detection came from.
AttemptsHacking DetailsNumber of attempts recorded.
RootingHacking DetailsWhether the device is rooted.
Hacking TypeHacking DetailsThe threat category.

A daily stacked chart across the period with one series per category, so you can see when a particular attack type started or stopped.

Three percentage cards summarising how the period’s detections distribute across OS Version - Major, OS Version - Minor, and Rooting.

A world map of the period’s detections, paired with Hacking Attempts By Country List:

ColumnMeaning
CountryCountry the detections came from.
Hacking AttemptsDetections from that country.
Unique Devices Hacking AttemptsDistinct devices behind them.