Security Console Mobile Hexii
Mobile threat detection

See what your mobile devices are really doing.

Mobile Hexii ships signed scanner modules to enrolled devices, captures DNS and VPN flow telemetry, inventories every installed app and permission, and scores the result with an explainable risk engine — so a finding always arrives with the evidence behind it.

Evidence retained
DNS packets & flow metadata
Payloads captured
None — metadata only
Module delivery
Signed & version pinned

Signed delivery

Every scanner module is Ed25519-signed and its signature verified on the device before it runs.

Metadata only

Queries, flows, and counters — never payload, request bodies, or decrypted traffic.

Explainable scores

Each score decomposes into the signals that produced it, largest contribution first.

Auditable by design

Every dashboard and API write lands in a filterable, sortable audit trail.

Step 01

Deliver a signed scanner

Upload a Python module once. Mobile Hexii signs it, hashes it, and pins it to a platform, release channel, and app version range. Roll it out to a slice of your fleet, or revoke it instantly if it misbehaves.

  • Ed25519 signature verified on-device before execution
  • Staged rollout by percentage, platform, and channel
  • Emergency kill switch per module version
Step 02

Capture the traffic

Assign DNS-only or full VPN flow capture to any enrolled device. Queries, answer records, and flow metadata stream back with the raw packet bytes preserved — payloads are never touched. Search the whole capture by domain, resolved IP, port, or response code.

  • Parsed DNS answers with TTLs and CNAME chains
  • Per-flow byte and packet counters, never payload
  • Raw packet SHA-256 kept for chain of custody
Step 03

Inventory every app and permission

The scanner reads the device's package manager directly: every installed app, its signing certificate, and the full permission table with what was actually granted. Ask which package holds CAMERA and get an answer, not a spreadsheet.

  • Granted vs declared permissions, per package
  • System, user, and debuggable builds separated
  • Searchable by package, installer, or permission
Step 04

Score it, and show your work

Every risk score decomposes into the signals that produced it, largest contribution first. Open a finding to see the evidence, the provider verdict, and exactly how many points it added — no opaque numbers.

  • Per-signal contribution breakdown
  • Reputation verdicts from threat intel providers
  • Full report exportable as JSON

Signed module delivery

Every version is signed, hashed, and revocable from one screen.

DNS & VPN introspection

Raw packet bytes are preserved so a finding traces back to what was observed.

App & permission audit

The full package inventory, searchable down to a single permission.

Explainable risk scores

Each score breaks down into the signals that produced it.

The console publishes its own uptime.

Component checks are recorded on every poll and kept for seven days — the same evidence standard we hold your scans to.