About Services Products Team Insights
SHODHAN
Mobile application forensics · by Dunime

Every app, taken apart before it reaches your people.

Shodhan is AI-driven forensic analysis for Android and iOS applications. It tells you whether an app threatens your data, your infrastructure or your staff, and gives you the evidence to prove it.

EXFILTRATION ENDPOINTFLAGGED · IOC MATCHEDsample.apkEXTRACTING PACKAGE

Your data leaves through apps you approved.

Vendor tools, partner apps and even your own brand apps ask for permissions, talk to servers and ship code nobody on your side has read. One malicious package on a work phone can intercept OTPs, overlay banking screens or quietly send contacts abroad.

Shodhan reads every package in depth, checks what it finds against live threat intelligence, and returns a verdict with the reasoning attached.

What it detects

SMS and OTP interceptionBanking credential harvestingDroppers and staged payloadsAccessibility-service abuseFake UI overlaysSpyware across contacts, camera, microphone and locationRansomware modulesCommand-and-control infrastructureData-exfiltration endpointsPackers, obfuscation and anti-analysis tricks

From upload to verdict, with the working shown.

Each analysis produces a structured forensic report, machine-readable indicator exports and a chain-of-custody log, formatted for security operations, regulators and legal proceedings alike.

SHODHANCase SHD-0412
com.quick.loan.app · v3.2.1MALICIOUSBanking trojan family · linked to 3 prior cases
94Threat score
Accessibility service abuseHigh
SMS and OTP interceptionHigh
Overlay screens on 14 banking appsHigh
Exfiltration endpoint outside IndiaCritical
Contacts and location read at launchMedium
Signing certificate seen in prior casesCampaign
PDF reportSTIX exportCustody log
Sample report · illustrative values

An analyst that never skips a step.

Autonomous forensic engineAn AI analyst runs the full toolkit on every sample: extraction, manifest and permission review, string and entropy analysis.
Live threat intelligenceEvery indicator checked against multiple global threat feeds and sandboxes at once.
Campaign correlationNew samples matched against every prior case by signing certificate, infrastructure, code and malware family.
Court-ready outputPDF reports, STIX indicator exports and custody logs, ready for submission.
Case managementCase numbers, analyst assignment, jurisdiction tracking and multi-app case bundles.
Data sovereigntySamples, artefacts and evidence stay in your environment from upload to report.

Where it is used

App vetting before anything is allowed onto employee devices.Brand protection for apps published under your name, and the clones imitating them.Supply-chain review of vendor and partner apps that touch your data.Incident root cause when an app is the suspected breach vector.Investigations for suspect apps recovered from a device.

Aligned with the DPDP Act, 2023.

Shodhan supports your compliance programme. Accountability stays with the organisation as data fiduciary.

Excess collection, flagged. Permission analysis shows apps asking for more than their function needs.Hidden transfers, found. Embedded endpoints outside approved jurisdictions are surfaced.Breach clarity. Fast root cause supports accurate, timely notification.Audit trail. Case history documents a demonstrable security safeguard.

Two ways to run it.

Shodhan EnterpriseApp analysis for security teams, with onboarding, intelligence updates and support included.Per-analyst licensingLive intelligence feedsPriority support
Shodhan PrivateA deployment inside your own environment or private cloud, offered under agreement.On-premise or private cloudSOC workflow integrationBriefing under NDA

Send us the app you are unsure about.

Briefings are held under NDA. Tell us about your environment and we will set one up.