Skip to content
This documentation is also available as markdown. For a complete index of all pages, see llms.txt at /llms.txt

Real Time Threat Analysis

Real Time Threat Analytics shows detections from a protected app as they arrive, over a rolling window described in the console as Real Time Hacking Detection for last 60 mins. Use it while reproducing an attack, or when you need to see whether something is happening right now rather than what happened last month.

Open Mobile App Security → Analytics → Real Time Threat Analytics.

FilterDescription
Operating SystemAndroid or iOS.
ApplicationThe app to watch. Type to search by name or package name.
Refresh RateHow often the page pulls new data: 1 MIN, 5 MIN, or 10 MIN.

A header card naming the selected app and package, with two counters for the window:

  • Hacking Attempts
  • Unique Devices Hacking Attempts

The single most frequent value in each dimension during the window, giving you the shape of what is happening at a glance:

InsightMeaning
Hacking TypeThe threat category seen most often.
LocationThe country producing the most detections.
DeviceThe device model producing the most detections.
EmulatorWhether emulator environments are involved.
Rooting EnabledCount of detections from rooted devices.

Detections plotted against time across the window, so you can see bursts as they happen.

Distinct devices reporting over the same window, plotted on the same time axis. Compare it with the chart above: a rising attempt count on a flat device count means a small number of devices generating a lot of traffic.

A world map of the window’s detections, with a table beneath it:

ColumnMeaning
CountryCountry the detections came from.
Hacking AttemptsDetections from that country.
Unique Devices Hacking AttemptsDistinct devices behind them.

The individual detections in the window. FILTER narrows the list and EXPORT downloads it.

Columns are grouped into Device Details, Hacking Details, and Action:

ColumnGroupMeaning
Reported OnDevice DetailsWhen the detection was reported.
AppSealing VersionDevice DetailsSealing version the app was built with.
Android IdDevice DetailsThe device’s SSAID.
Model NameDevice DetailsDevice model.
Android VersionDevice DetailsOS version.
App VersionDevice DetailsVersion of your app.
CountryDevice DetailsWhere the detection came from.
AttemptsHacking DetailsNumber of attempts in the entry.
EmulatorHacking DetailsWhether an emulator was detected.
RootingHacking DetailsWhether the device is rooted.
Hacking TypeHacking DetailsThe threat category.