Skip to main content
Smartphone in a holder next to a screen listing processes and network connectionsAI-generated

Service

Spyware examination

Monitoring software leaves traces in permissions, configuration profiles, running processes and network connections. An examination checks these areas systematically and states plainly what was and was not found.

What is examined

  • Installed applications, permissions and background activity
  • Configuration profiles, device management entries and certificates
  • Indicators of compromise from public and commercial sources
  • Network connections and conspicuous data transfers

How the examination is carried out

  1. 1.Acquisition of the device, followed by analysis of the extraction rather than the live device
  2. 2.Comparison against current indicator sets from several sources
  3. 3.Manual review of every automatically flagged indicator
  4. 4.Clear statement of the residual uncertainty in the report

Technical limits

These limits are stated before the instruction, not afterwards.

  • A negative result does not prove the absence of monitoring software; it means no indicator was found.
  • Unknown or newly developed tools may leave no known indicator.
  • Monitoring at the account or cloud level is not visible in a device examination.
  • A factory reset before the examination removes most traces.

FREQUENTLY ASKED QUESTIONS

Spyware examination: frequently asked questions

Equipment used

Systems used in this examination

Next step

Discuss your case

Describe the situation briefly. We will say what can realistically be established, and what cannot.

+49 221 99981 490ContactBook an appointment

Further specialised services

AQON INTELLIGENCE covers technical and digital forensics. Adjacent requirements are handled by other providers: