
CROSSBOW
Real-Time Mobile Threat Detection
Agent-free mobile threat intelligence for Android and iOS. CROSSBOW remotely profiles devices to expose spyware, malicious implants, risky links, forced app installs, and other infection vectors while preserving device integrity. It gives government, police, and high-risk teams a fast, reliable way to tell normal use from compromise.
PLATFORM DETAILS
Threat Detection
Proprietary DATAENFORCE technology. No third-party security components.
CAPABILITIES
Key Features
Agent-Free Architecture
Analyses Android and iOS devices without installing any client software, preserving device integrity and preventing forensic contamination.
Spyware & Malware Detection
Identifies executable code designed to alter, corrupt, deny access, or covertly transmit user data to remote systems.
Infection Vector Analysis
Detects infection vectors including malicious SMS messages, web links, unauthorised wireless connections, and forced application installs.
Candidate Application Profiling
Flags and ranks applications for further individual and deep-dive analysis based on behavioural signatures and anomaly scoring.
Real-Time Results
Delivers actionable intelligence in minutes, enabling rapid response by security teams without device downtime.
Cross-Platform Support
Full support for Google Android and Apple iOS across a wide range of device models and operating system versions.
HOW IT WORKS
Threat Detection
Further reading: Indicators of Compromise - types, detection and operationalization
DEPLOYMENT
Use Cases
- Investigation of suspected device compromise in government and defence
- Security screening of devices before access to classified environments
- Corporate BYOD fleet auditing for APT and stalkerware
- Judicial and law enforcement digital forensics intake
- Executive device protection programmes
FAQ
Frequently Asked Questions
How do you detect mercenary spyware like Pegasus on a mobile device?
Mercenary spyware - the class of commercial surveillance tools that includes Pegasus, Predator, Graphite and others - rarely leaves an app icon or an obvious file to scan for. CROSSBOW detects it by analysing device behaviour rather than chasing a named signature: anomalous process activity, covert data exfiltration, zero-click exploitation artefacts, and unexpected configuration changes. Because the detection targets the behaviour of the whole class, it does not depend on knowing which vendor or brand built the implant.
Is Pegasus still active, or did it shut down and change its name?
Pegasus and its developer NSO Group still exist, but the more important point for defenders is that mobile surveillance is no longer a one-vendor problem. The mercenary-spyware market has diversified: Intellexa/Cytrox Predator, Paragon Graphite, QuaDream Reign, and Hermit-class tooling deliver comparable zero-click capabilities, and new brands appear as old ones are sanctioned or rebranded. Treating "Pegasus" as the only threat is exactly the blind spot attackers rely on. CROSSBOW detects the surveillance behaviour these tools share, so coverage does not lapse each time a brand changes its name.
Can you detect spyware without installing an app on the device?
Yes. CROSSBOW uses an agent-free architecture: it performs a passive analysis of the device and its signals without installing client software, rooting, or jailbreaking. This matters for high-risk users - executives, officials, journalists - who cannot have a visible security agent on their phone, and for forensic examinations where installing software would alter the evidence.
What are the signs that a phone is infected with spyware or stalkerware?
Common indicators include rapid battery drain, a device that runs warm while idle, unexplained data usage, unfamiliar configuration profiles, and unusual outbound network connections. Sophisticated mercenary spyware is engineered to suppress these signs, which is why CROSSBOW correlates multiple weak signals and scores anomalies rather than relying on any single symptom a user might notice.
What is the difference between commercial spyware, stalkerware, and APT implants?
Commercial (mercenary) spyware such as Pegasus or Predator is sold by private vendors to state and agency clients and typically uses zero-click exploits. Stalkerware is consumer-grade monitoring software installed by someone with physical access - an abusive partner or employer - and is more common but less stealthy. APT implants are bespoke tools built by state intelligence services for specific operations. CROSSBOW is built to surface all three, because each leaves behavioural traces an agent-free analysis can detect even when the specific tool is unknown.
Does CROSSBOW work on both Android and iOS?
Yes. CROSSBOW supports both Android and iOS devices and is designed to detect cross-platform threats, including zero-click exploits delivered through messaging apps. Detection is based on device and signal anomalies rather than platform-specific antivirus signatures, so the same behavioural approach applies across operating systems.
Interested in CROSSBOW?
Contact our team for a confidential briefing or technical demonstration.