Skip to main content
MEFF M3-PRO in forensic examination use

Technology

MEFF M3-PRO

Indicator-based examination compares a device extraction against known indicators of compromise. It is one component of a spyware examination, never the whole of it.

Where it is used

  • Comparison of extractions against current indicator sets
  • Review of configuration profiles, permissions and device management entries
  • Assessment of conspicuous network connections
  • Manual verification of every automatically flagged indicator

Limits

  • Unknown or newly developed tools may leave no known indicator.
  • A result without findings is not proof that no monitoring took place.
  • Monitoring at account or cloud level is not visible in a device examination.