
Service
Spyware examination
What is examined
- Installed applications, permissions and background activity
- Configuration profiles, device management entries and certificates
- Indicators of compromise from public and commercial sources
- Network connections and conspicuous data transfers
How the examination is carried out
- 1.Acquisition of the device, followed by analysis of the extraction rather than the live device
- 2.Comparison against current indicator sets from several sources
- 3.Manual review of every automatically flagged indicator
- 4.Clear statement of the residual uncertainty in the report
Technical limits
These limits are stated before the instruction, not afterwards.
- A negative result does not prove the absence of monitoring software; it means no indicator was found.
- Unknown or newly developed tools may leave no known indicator.
- Monitoring at the account or cloud level is not visible in a device examination.
- A factory reset before the examination removes most traces.
FREQUENTLY ASKED QUESTIONS
Spyware examination: frequently asked questions
No. It establishes whether known indicators are present. A result without findings reduces the likelihood of monitoring but cannot rule it out.
Analysis takes place on the secured working copy in the permanent examination rooms at the registered office in Krefeld, Germany. Devices are handed over in person or sent by insured carrier; by prior arrangement, processing in Munich is also possible. Where the technical conditions allow it, the acquisition itself can also be carried out at the client’s premises or at the location of the item; unavoidable changes to a running system are documented with reasons.
Whether an expert report is used in proceedings, and what evidential value it carries, is decided by the competent court or investigating authority. Our examinations are documented so that third parties can review them: recorded handover, cryptographic hashes, described methods and a clear separation between technical finding and assessment. A binding assurance of later admissibility cannot be given.
Equipment used
Systems used in this examination
- MEFF M3-PRO
Indicator-based examination of mobile devices for anomalies.
- Cellebrite Inseyets and UFED
Data acquisition when a suspicion requires a deeper examination.
Next step
Discuss your case
Describe the situation briefly. We will say what can realistically be established, and what cannot.
Further specialised services
AQON INTELLIGENCE covers technical and digital forensics. Adjacent requirements are handled by other providers:
- QUINTEGO investigation agency – investigative work and clarification of facts