config-and-persistence-review

Review iOS backup artifacts for persistence mechanisms and security misconfigurations.

11|1|Updated May 4, 2026
One-click install
npx skills add https://github.com/dreadnode/capabilities --skill config-and-persistence-review
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: config-and-persistence-review
Source: https://github.com/dreadnode/capabilities/tree/main/capabilities/ios-forensics/skills/config-and-persistence-review
Command: npx skills add https://github.com/dreadnode/capabilities --skill config-and-persistence-review

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Manually reviewing iOS device configuration surfaces to identify hidden persistence mechanisms, surveillance tools, and security misconfigurations is time-consuming and error-prone, especially for incident response, high-risk user security reviews, and device handover audits.

Core Features & Use Cases

  • Comprehensive Surface Coverage: Ranks and reviews 10 high-prevalence iOS configuration surfaces including configuration profiles, TCC grants, provisioning profiles, sideloaded apps, root CAs, VPN/proxy settings, WebClips, jailbreak indicators, and iCloud account posture.
  • Scored Risk Assessment: Provides clear scoring criteria for configuration profiles to distinguish benign enterprise MDM from malicious persistence tools, and flags high-risk artifacts like sticky profiles that survive resets, unauthorized TCC grants, and unexpected root CAs.
  • Structured Reporting: Guides users to group findings by surface area, assign risk verdicts, and provide actionable remediation steps, plus a survivability table to guide cleanup efforts from partial resets to full device replacement.

Quick Start

Use the config-and-persistence-review skill to analyze the provided iOS backup and identify all high-risk configuration profiles, suspicious TCC grants, and sideloaded enterprise apps.

Frequently Asked Questions about config-and-persistence-review

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I audit an iOS backup for hidden persistence mechanisms and surveillance configurations?

Audit iOS backups by enumerating and scoring configuration profiles, TCC grants, provisioning profiles, sideloaded apps, root CAs, VPN settings, WebClips, jailbreak indicators, and iCloud posture to identify hidden persistence mechanisms and surveillance risks. Findings are grouped by surface area with assigned risk verdicts and remediation steps.

What iOS configuration surfaces should I check during a mobile incident response?

During mobile incident response, check 10 high-prevalence iOS configuration surfaces: configuration profiles, TCC grants, provisioning profiles, sideloaded apps, root CAs, VPN/proxy settings, WebClips, jailbreak indicators, and iCloud account posture. The review flags high-risk artifacts like sticky profiles that survive resets and unauthorized TCC grants.

Can I use a configuration audit to validate iOS device handover hygiene?

Yes, a configuration audit validates device handover and handback hygiene by detecting unauthorized root CAs, unexpected VPN/proxy settings, sideloaded enterprise apps, and sticky configuration profiles. It provides a survivability table to guide cleanup efforts ranging from partial resets to full device replacement.

How does scoring distinguish malicious persistence tools from benign enterprise MDM profiles?

Scoring distinguishes malicious persistence from benign MDM by applying clear risk criteria to configuration profiles, flagging sticky profiles that survive device resets, unauthorized TCC grants, and unexpected root certificates as high-risk artifacts requiring immediate remediation.

When do I need a pre-travel security review for my iOS device?

A pre-travel or post-travel security review is needed for high-risk users to detect surveillance tools and security misconfigurations on iOS devices. The review scopes incident response by analyzing device artifacts and backups for hidden persistence mechanisms, unauthorized monitoring profiles, and compromised iCloud account posture.

Why do some iOS configuration profiles survive a factory reset?

Sticky configuration profiles survive factory resets due to specific iOS persistence mechanisms designed for enterprise management, but they can also be exploited for surveillance. A configuration audit identifies these sticky profiles, scores their risk level, and includes them in a survivability table to guide appropriate cleanup or device replacement.