What problem does it solve?
Manually reviewing iOS device configuration surfaces to identify hidden persistence mechanisms, surveillance tools, and security misconfigurations is time-consuming and error-prone, especially for incident response, high-risk user security reviews, and device handover audits.
Core Features & Use Cases
- Comprehensive Surface Coverage: Ranks and reviews 10 high-prevalence iOS configuration surfaces including configuration profiles, TCC grants, provisioning profiles, sideloaded apps, root CAs, VPN/proxy settings, WebClips, jailbreak indicators, and iCloud account posture.
- Scored Risk Assessment: Provides clear scoring criteria for configuration profiles to distinguish benign enterprise MDM from malicious persistence tools, and flags high-risk artifacts like sticky profiles that survive resets, unauthorized TCC grants, and unexpected root CAs.
- Structured Reporting: Guides users to group findings by surface area, assign risk verdicts, and provide actionable remediation steps, plus a survivability table to guide cleanup efforts from partial resets to full device replacement.
Quick Start
Use the config-and-persistence-review skill to analyze the provided iOS backup and identify all high-risk configuration profiles, suspicious TCC grants, and sideloaded enterprise apps.