Skip to main content
Jamf Mobile Forensics, India

Jamf Mobile Forensics: for the few people whose phone is genuinely a target.

Formerly Jamf Executive Threat Protection. Mercenary spyware such as Pegasus, Predator and Graphite does not need the target to tap anything. It can arrive with no interaction at all, leave almost nothing visible, and sit on a phone that looks entirely normal. This product detects that class of compromise and produces documented evidence of it. Most organisations do not need it, and we will say so. Delivered discreetly, remote-first from Gachibowli, Hyderabad.

Advanced mobile threat detection and forensics in India
  • iOS and AndroidBoth mobile platforms covered
  • Zero-clickDetects no-interaction compromise
  • Remote DFIRThe phone stays with its owner
  • Honest gateWe say no more often than yes
What the product does

Eight capabilities, all pointed at one hard problem.

Ordinary mobile security assumes an attacker who needs a user mistake, and most Indian organisations need nothing more than that. We will tell you plainly if you are one of them. The hard problem this product addresses is that a sophisticated mobile compromise leaves very little for a user or an administrator to see. Detecting it needs deep artefacts collected off the device and somebody qualified to read them, and both halves are what this covers.

Detection of zero-click compromise

The threats this addresses do not require a user mistake. A zero-click attack reaches the device through a message or call the target never opens, which makes every awareness training session you have run irrelevant to it. Detection happens through device artefacts, not through anything the user could notice.

Automated artefact collection and analysis

The product collects the diagnostic and forensic data a mobile device retains and analyses it for indicators associated with known spyware families and attack techniques. Doing this manually is slow specialist work per device; automating collection makes routine checking of a small named group viable.

Remote DFIR, so the phone stays in use

Digital forensics and incident response performed remotely rather than by taking custody of the handset. The people most likely to need this check are the least able to hand a phone over for a week, and a control that requires them to is a control that will not be used.

AI-assisted analysis as triage

Jamf has added AI analysis to prioritise what an analyst should look at first. Treat it as triage rather than a verdict: it narrows a very large volume of artefacts to what deserves human attention, and it is not a substitute for the human judgement that follows.

Incident management for a real process

Detections arrive as managed incidents with a rules engine behind them rather than as isolated alerts. If you have no security operations function, read that as a signal: the product assumes somebody will act on what it finds, and buying detection with nobody to respond is a familiar mistake.

Coverage across iOS, iPadOS and Android

High-risk individuals rarely all carry the same platform, and many carry two devices. Coverage of both major platforms means the assessment is of the person rather than of one handset, which is the only way it is meaningful. Analyst work is done from macOS or Windows.

Evidence you can act on and hand over

The output is a documented forensic finding rather than a pop-up, which is what lets a legal team, a board or an external investigator do something with it. A suspicion that a phone is compromised is nearly useless. A documented artefact-level finding is defensible.

A baseline, even when nothing is found

A clean result is itself useful: it converts an open question into a documented position at a point in time, with the limits of the analysis stated. That is what makes any later change meaningful, and it is what a board asking "are we compromised" actually needs.

Read this before enquiring

Most organisations do not need this, and the basics beat it every time.

This is a specialist product for a narrow problem, and it is easy to sell badly by frightening people. We would rather lose the enquiry than sell advanced mobile forensics to an organisation whose actual exposure is an unpatched laptop and shared passwords.

  • The realistic threat for almost every Indian business is not mercenary spyware. It is business email compromise, an invoice redirected because somebody read a mailbox, ransomware through an exposed remote access service, and credentials reused from a public breach. If those are open, spend there first. The return per rupee is not close.
  • Apple Lockdown Mode is built into iOS, costs nothing, and for a genuinely high-risk individual it is a far bigger reduction in attack surface than any product you can buy. It restricts the message and web features this class of attack tends to use. It is inconvenient, which is exactly why people avoid enabling it, and that inconvenience is the trade being made.
  • Detection is not prevention. This product finds and evidences a compromise; it does not stop one. If the objective is to reduce the chance of compromise, the work is device hardening, disciplined patching, restricting who can reach the individual by message, and reducing what is on the device at all.
  • Buying detection without a plan for the answer is the common failure. Decide in advance who is told if a device is found compromised, who decides to isolate or replace it, what happens about the data that may already have gone, and whether a legal or regulatory notification follows. That plan is harder than the purchase and more valuable.
Ask us to review your actual exposure first
How we approach it

Four commitments on a subject that is easy to sell dishonestly.

Advanced mobile threats are the easiest thing in security to sell with fear and the hardest to sell honestly. These are the rules we hold ourselves to on this topic.

We will tell you if you do not need it

The first output of any conversation is an assessment of whether anyone in your organisation is plausibly a target for this class of attack. For most Indian businesses the answer is no, and we say so directly and point you at the work that would actually reduce your risk. We would rather have that reputation than the revenue.

Built-in hardening before paid detection

Lockdown Mode, current operating system versions, removing unused message-receiving apps and restricting who can reach an individual all cost nothing but attention, and all reduce the chance of compromise more than detection does. We implement those first and quantify what is left.

The response is planned before deployment

Before anything is switched on we agree who is notified, who decides, how quickly a device can be replaced, when counsel is engaged, and what a DPDP Act or CERT-In notification would look like. Detection without a decided response produces a crisis at the worst possible moment.

Discretion, and a named contact

Work of this kind involves individuals rather than systems, and it is handled by named people on our side with the confidentiality that implies. Findings go to whoever you nominate and to nobody else, and you always speak to somebody who already knows the context. Managed clients hold a 30 minutes response SLA.

Who this is actually for

Six situations where the conversation is warranted.

These are the profiles where we would consider this proportionate. If your organisation does not resemble one of them, the honest answer is that your money goes further elsewhere, and we will say so.

A family office or promoter group

Small teams, very high value information, and principals whose movements and intentions are commercially valuable to others. The attack surface is a handful of phones belonging to people who travel constantly and cannot be told to stop using their devices normally.

A board of a listed or regulated entity

Advance knowledge of a transaction, a result or a regulatory outcome has direct financial value, and board members are often the least managed devices in the organisation because nobody wants to impose policy on them. This is one of the few controls that applies to a small named group without a wider policy fight.

A law firm on contested matters

Privileged material, adversarial parties with resources, and a professional duty of confidentiality a compromise would breach directly. The professional consequences of an undetected compromise are not only commercial, which changes how proportionate a specialist control looks.

Media and civil society organisations

People who publish on contested subjects are a documented target group for mercenary spyware globally. The individuals concerned frequently have no IT support at all, so the practical work is often as much about basic hardening and sensible habits as any product, and we approach it that way.

Executives travelling to higher-risk jurisdictions

Exposure attaches to the person and where they go. The pattern we usually recommend is a hardened travel device carrying the minimum necessary, checked before and after travel, rather than continuous monitoring of the everyday phone. Cheaper, less intrusive, and aimed at the actual window of risk.

Organisations that already suspect something

Sometimes the enquiry follows an incident: an unexplained leak, a negotiation where the other side clearly knew too much, a device behaving oddly. The requirement is investigative, usually urgent, and needs handling in a way that preserves evidence. Do not factory reset the device before speaking to somebody.

Three positions organisations take

What high-risk mobile exposure looks like in practice.

The middle column is where most organisations that have thought about this at all end up: risk identified, nothing structural done, reliance on the individual noticing something. That reliance is misplaced, because this class of compromise is specifically designed to be unnoticeable.
Feature
Assessed and monitored
Aware but unaddressed
Not considered
High-risk individuals formally identified
Informally
Lockdown Mode enabled where warranted
Rarely
Devices patched without exception
MostlyUnknown
Device artefacts ever examined
RoutinelyNeverNever
Compromise would be detected
LikelyOnly by chance
Evidence available if it were
Response plan agreed in advance
Legal counsel briefed
Replacement device available same day
Sometimes
Typical position in the Indian market
UncommonCommonThe default
Where each control fits

Mobile management, mobile security and mobile forensics do different jobs.

These are frequently confused, and the confusion leads organisations to believe they are covered when they are not. Management controls the device. Security defends against ordinary threats. Forensics investigates the extraordinary ones. Owning one does not give you the others.
Mobile device managementMobile threat defenceMobile forensics
Enforces passcode, encryption, updatesYesNoNo
Blocks phishing and malicious sitesLimitedYesNo
Detects ordinary mobile malwareNoYesNot its purpose
Detects zero-click and mercenary spywareNoRarelyYes, this is the point
Collects deep on-device artefactsNoNoYes
Produces documented forensic evidenceNoNoYes
Needed by most organisationsYesUsually yesRarely
Applies to the whole workforceYesYesA named few
Requires somebody to respond to findingsSomeYesAbsolutely
Where to spend firstFirstSecondOnly when justified
How an engagement runs

Five stages, and the first two involve no product at all.

We do not start with a deployment. We start by establishing whether a target exists, because that determines whether anything after it is justified.
  1. 1

    Establish whether a genuine target exists

    A short structured conversation about roles, travel, public profile, the value of what individuals know and who might want it. The output is a written position on whether anyone plausibly falls into this risk category. For most organisations this stage ends the engagement, which is the correct outcome.

  2. 2

    Harden what is built in

    For the individuals identified: Lockdown Mode where they will accept it, operating system currency enforced without exception, removal of unused message-receiving applications, tightening of who can reach them directly, and a review of what data is on the device at all. This reduces exposure measurably and costs nothing but attention.

  3. 3

    Agree the response before the detection

    Who is told, who decides, how fast a device can be replaced, when counsel is engaged, what DPDP Act or CERT-In notification obligations may follow, and how findings are recorded. Written down and agreed by the people who would actually be involved, not drafted by IT and filed.

  4. 4

    Deploy and baseline

    The product is deployed to the named individuals, artefacts are collected and analysed, and a baseline position is established per device. A clean baseline is itself a useful result: it converts an open question into a documented finding at a point in time, which is what makes any later change meaningful.

  5. 5

    Run it, review it, stop it when no longer warranted

    Periodic collection and analysis, with findings reported to your nominated contact. We review annually whether the risk profile still justifies the control, because roles change, and recommending that you stop paying for something is part of the job.

Direct answers

The questions people actually ask about this.

Is anyone here actually high risk

Twelve questions that decide whether this conversation is worth having.

The first group establishes whether a genuine target exists. The second is the hardening that should happen regardless and usually has not. The third is what you need in place before detection is worth buying.

Is there a real target

  • Does anyone hold a government, diplomatic or public office role?
    The clearest indicator, and the one this product was built around.
  • Does anyone negotiate transactions where advance knowledge is worth a great deal?
    Deal teams, boards, promoters and family offices are commercially attractive targets.
  • Does anyone work in or travel regularly to a higher-risk jurisdiction?
    Exposure follows the person, not the office.
  • Does anyone publish, report or campaign publicly on contested subjects?
    Journalists and civil society are a documented target group for this class of tooling globally.

Has the built-in hardening been done

  • Is Lockdown Mode enabled on the devices of the people identified above?
    Built in, and the largest single reduction available.
  • Are those devices on the current OS version, without exception?
    This class of attack chases unpatched flaws. Patch latency is the exposure.
  • Have unused messaging apps been removed from those devices?
    Every message-receiving app is an inbound surface.
  • Can strangers reach those individuals directly by message or call?
    Restricting who can reach someone is an underrated control.

Could you act on a finding

  • Is there a named person who would be told first?
    Findings of this kind cannot go through a general helpdesk queue.
  • Is legal counsel briefed in advance?
    The response is a legal question as much as a technical one.
  • Could you replace a compromised device the same day?
    A finding you cannot act on for a week is a finding of limited value.
  • Do you know which notification obligations would apply?
    DPDP Act breach reporting and CERT-In timelines may follow depending on what was exposed.
Next step

Start with whether anyone here is actually a target.

That question decides everything after it, and answering it carries no obligation. If the answer is no, we will tell you plainly and point you at the work that would genuinely reduce your risk. If it is yes, we start with the hardening that is already built into the platform before recommending anything you have to buy. Enquiries answered within 4 business hours.