What problem does it solve?
This Skill solves the challenge of detecting stealthy mercenary iOS spyware such as Pegasus, Predator, and QuaDream that leaves minimal on-device artifacts, by correlating STIX indicators of compromise with high-signal iOS system logs and backup artifacts that are often the only durable evidence of infection.
Core Features & Use Cases
- STIX IoC Sweeping: Scan iOS backups or full filesystem dumps against curated STIX2 indicators from authoritative security research organizations to identify known spyware signatures.
- Multi-Artefact Correlation: Cross-reference shutdown logs, DataUsage records, Safari/WebKit history, SMS messages, and Manifest.db entries to surface hidden spyware activity.
- Timeline & Reporting: Build a chronological timeline of suspicious events to confirm infection patterns even without direct STIX matches, and generate structured forensic reports with confidence levels and evidence chain details.
- Use Case: For a human rights defender who received an Apple Threat Notification, use this skill to scan their iOS device backup for STIX matches, identify unknown short-lived processes in DataUsage records, and compile a forensic report of likely compromise to share with security researchers.
Quick Start
Use the spyware-hunt skill to scan an iOS backup or filesystem dump for mercenary spyware indicators, cross-reference shutdown logs and data usage records for suspicious activity, and generate a forensic report of confirmed or suspected infections.