XDR Mobile · Endpoint module

Your phones too
are a target.

An iOS and Android app protecting company smartphones and tablets. Detects stalkerware (Pegasus, Predator, Hermit), malicious apps and credential leaks — without reading your data.

iOS 15+Android 10+Stalkerware / MVTFleet Management
0-clic
spyware detection
150 000+
apps monitored
< 2 %
de batterie par jour

Mobile is the weak link in most SOCs. Pegasus, Predator and Hermit install in seconds, sometimes without a single click. Mobile XDR applies the same detection to the phone as to the workstation: stalkerware indicators (Citizen Lab) + MVT (Amnesty) + multi-source CTI matching. The user keeps control, the SOC sees the risk — never the content.

How it works

From threat to evidence, in real time.

The module captures the signal, SYLink AI correlates it and decides — you keep control.

Corporate mobile
iOS & Android
Mobile XDR
Intrusion signals
SYLink AI
Cross-correlates with the desktop
Alert RSSI
Without reading your data
Capabilities

The technology, in detail.

What the module actually does — functions, not promises.

Stalkerware and spyware detection

  • stalkerware-indicators (Citizen Lab)
  • mvt-indicators STIX2 (Amnesty MVT)
  • Pegasus, Predator, Hermit, Reign, Quadrant
  • Apps abusing accessibility or admin permissions
  • Suspicious MDM profiles (iOS)

Multi-source threat intel

  • MalwareBazaar (Android / iOS / macOS / state tags)
  • URLhaus abuse.ch (malicious URLs)
  • AlienVault OTX (multiple keys)
  • mobile_apk_hashes → unified_iocs propagation
  • MITRE ATT&CK Mobile mapping (T1437, T1517…)

Inventory & compliance

  • Installed apps, permissions and signatures
  • Detection of unmanaged apps (BYOD)
  • Root / jailbreak + unlocked bootloader
  • OS patch level + applicable CVEs
  • Intune / Jamf / Workspace ONE compatible report

Mobile network

  • IMSI-catcher and fake base station detection
  • C2 over mobile data and Wi-Fi
  • VPN enforced on public hotspots (automatically)
  • Suspicious captive portals blocked
  • Audit of the DNS resolver in use

SYLink AI driven

  • Automatic triage of mobile alerts
  • Contextual recommendations (delete / reset / wipe)
  • Mobile kill chain reconstruction
  • Cross-correlation with the desktop EDR
  • Built into the tenant's SOC dashboard

User privacy

  • No message or photo is ever read
  • Only hashes and signatures are reported
  • Pro / personal mode (BYOD-friendly)
  • The SOC sees the risk, never private life
  • GDPR compliant article 9
Use cases

What is it actually for?

Detect Pegasus on an executive's device

The CEO's phone shows an MVT pattern (WebKit process plus a connection to an NSO Group IP). Critical alert to the CISO, factory reset recommended, forensic audit.

Block a malicious app

An employee installs WhatsApp+Mod from APKMirror: the hash matches an android_stealer tag. The SOC is alerted and the app removed through MDM within five minutes.

Check the fleet before a NIS2 audit

The auditor wants the list of unpatched devices. Report in 30 seconds: OS version, prohibited apps, root detected, questionable MDM profiles.

Cross-correlate mobile and desktop

Bob's phone is compromised (stalkerware) AND his workstation beacons to the same infrastructure. The AI correlates the two and escalates a multi-vector incident.

The method, in four steps
From raw signal to defensible evidence.
Detect
Understand
Decide
Prove
01The module captures the raw signal — traffic, behaviour or indicator.signal captured
Specifications
PlatformsiOS 15+ (App Store / MDM), Android 10+
Battery footprint< 2% per day
Local storage30 MB
Heartbeat15 min (configurable)
Stalkerware sourcesstalkerware-indicators + mvt-indicators STIX2
Mobile CTIMalwareBazaar, URLhaus, AlienVault OTX
Catalogue of monitored apps150,000+ Android · 80,000+ iOS
DeploymentLocal app · on the devices
Natively integrated with
SYLink AI — triage and cross-correlation
EDR agent — same user, desktop
Your existing MDM (Intune, Jamf), read-only
Compliance module — NIS2 for the mobile fleet
HoneyPot — lateral movement from mobile to server
Sovereign

Driven by SYLink AI, hosted 100% in France (HDS v2), with no Cloud Act exposure. Every decision is logged and defensible under NIS2 and DORA.

Live in under 48 hours

Ready to see what is really
happening on your network?

First trial free, no credit card, no commitment. On your existing infrastructure.

Cookie settings

We use cookies to improve your experience on our site. By continuing to browse, you accept our privacy policy and our use of cookies under the GDPR.