A compromise assessment can find suspicious artifacts. It cannot prove that a device has never been compromised.

That distinction matters because visibility is bounded by the device, operating system, acquisition method, available account data, retention and the behaviour of the suspected threat.

Define the hypothesis

“Check for malware” is too broad. Start with the reported symptoms and timeline:

  • unusual account alerts or password changes;
  • new configuration profiles, applications or permissions;
  • unexpected battery, network or location behaviour;
  • physical access by another person;
  • messages, links or files that preceded the concern;
  • earlier resets, security tools or remediation.

The hypothesis determines which device, application, account and network artifacts matter.

Preserve before changing

Factory resets, ad-hoc cleaner applications and repeated configuration changes can remove context. If the risk is not immediate, preserve the current state and agree the collection plan first. If there is an active safety or enterprise incident, follow the appropriate response process rather than waiting for a forensic examination.

Report both findings and blind spots

A responsible result states:

  • which indicators and behaviors were assessed;
  • what data was available;
  • the method and date of examination;
  • relevant observations;
  • alternate explanations;
  • unavailable sources and known limitations.

“No defined indicators were observed in the available dataset” is materially different from “the phone is clean.”

That wording is not defensive. It is accurate. It gives the recipient enough context to decide whether further account, network, endpoint or provider evidence is needed.

See the phone compromise assessment and the intended examination sequence.