🚀 Maximize your product's SEO. Submit to 240+ directories in 1-click with DirSubmit. Launch Now
mvt logo

mvt

A forensic toolkit to detect signs of compromise on mobile devices.

2026-09-21

Product Introduction

  1. Definition: MVT (Mobile Verification Toolkit) is an open-source, command-line digital forensics and incident response (DFIR) tool specifically engineered for the consensual forensic analysis of Android and iOS mobile devices. It falls under the technical categories of mobile security analysis, spyware detection, and forensic triage software.
  2. Core Value Proposition: MVT exists to provide investigators, researchers, and security professionals with a reliable, transparent, and automated methodology for detecting sophisticated mobile threats, particularly commercial-grade spyware like Pegasus (NSO Group). Its core value is democratizing high-level mobile forensic capabilities to aid in human rights investigations, incident response, and targeted threat hunting.

Main Features

  1. iOS Forensic Analysis Suite (mvt-ios): This module provides a comprehensive toolkit for examining iOS data. It works by parsing full filesystem dumps, iTunes backups, and sysdiagnose archives. It uses specific parsers for iOS system databases (e.g., DataUsage.sqlite, knowledgeC.db) and log files to extract artifacts like application install history, network connections, Safari browsing history, and system events. The technology relies on Python libraries for parsing SQLite databases and Plist files.
  2. Android Forensic Analysis Suite (mvt-android): This module focuses on Android device forensics. It works by analyzing Android Backup files (ADB backups) to extract SMS messages, call logs, and package lists. A key feature is its ability to check for signs of compromise in Android's bugreports and intrusion detection logs, looking for indicators of root exploits, shell privilege escalation, and suspicious package installations.
  3. Indicators of Compromise (IOC) Matching Engine: The core detection mechanism of MVT is its automated IOC matching system. It works by allowing users to provide STIX2-formatted threat intelligence feeds containing malicious domains, IP addresses, file hashes, and other forensic indicators. MVT cross-references the extracted device artifacts against these IOCs, flagging matches that suggest compromise. This automates the tedious process of manual log and database review.
  4. Modular Plugin Architecture: MVT is built with extensibility in mind. Security researchers can develop custom plugins to parse new artifact types or log files. Plugin configuration is managed via YAML files, allowing for easy customization of checks and integration of new forensic data sources without modifying the core tool.

Problems Solved

  1. Pain Point: The extreme difficulty and resource intensity of manually detecting advanced persistent threats (APTs) and commercial spyware on mobile devices. Traditional methods involve manually sifting through gigabytes of unstructured system data, which is error-prone and impractical under time constraints.
  2. Target Audience: Digital Forensic Analysts, Incident Responders (CSIRT teams), Human Rights Researchers and Investigators, Security Consultants conducting consensual device audits, and Technologists supporting high-risk individuals like journalists and activists.
  3. Use Cases: Triaging a device suspected of being infected with Pegasus or similar spyware; conducting a post-incident forensic analysis of a compromised mobile device; performing a proactive security check for an individual at high risk of targeted surveillance; verifying the integrity of a device as part of a human rights investigation.

Unique Advantages

  1. Differentiation: Unlike commercial forensic suites that are often costly and closed-source, MVT is free and open-source, allowing for peer review and trust verification. Compared to manual ad-hoc scripting, MVT provides a standardized, repeatable forensic methodology. It is specifically tuned for threat hunting and IOC matching, whereas general mobile forensic tools are broader and less focused on compromise detection.
  2. Key Innovation: MVT's primary innovation is the publication and codification of a complete, reproducible forensic methodology for mobile spyware detection. It packages expert knowledge of iOS and Android forensic artifact locations and their relevance to compromise into an automated tool. Its development and release in direct conjunction with real-world Pegasus investigation data (The Pegasus Project) ensures its checks are grounded in actual threat actor tactics.

Frequently Asked Questions (FAQ)

  1. Is MVT a hacking tool? No, MVT is strictly a forensic analysis tool designed for consensual security investigations. It requires physical access to the device and a backup or dump created with the user's knowledge and consent. It does not exploit devices or extract data without permission.
  2. What is the difference between MVT and commercial mobile forensic tools like Cellebrite or Oxygen Forensics? Commercial tools are designed for broad law enforcement and corporate forensics, focusing on data extraction and recovery. MVT is a specialized, open-source tool focused specifically on detecting indicators of compromise and advanced spyware, making it a complementary tool for deep-dive threat hunting.
  3. Can MVT detect all types of mobile malware? MVT is specifically optimized to detect sophisticated, targeted spyware that leaves forensic traces in system logs and databases. It is less effective against widespread, generic malware from app stores that does not attempt sophisticated persistence or privilege escalation.
  4. Do I need programming skills to use MVT? Basic proficiency with the command-line interface (CLI) is required to install and run MVT. Interpreting its output effectively requires foundational knowledge of mobile operating systems and digital forensics concepts.
  5. Where can I find Indicators of Compromise (IOCs) to use with MVT? IOCs are often published by security research firms and organizations like Amnesty International's Security Lab. Users must source relevant, high-quality STIX2-formatted threat intelligence feeds related to the specific threats they are hunting for.

Submit to 240+ Directories with 1-Click

Maximize your product's SEO and drive massive traffic by automatically submitting it to over 240 curated startup directories using DirSubmit.

Related Products

Subscribe to Our Newsletter

Get weekly curated tool recommendations and stay updated with the latest product news