Scan a phone for forensic traces of spyware infection
Made by MVT
View profile on GitHub (opens in a new tab)The Mobile Verification Toolkit (MVT) is a set of command-line tools for gathering forensic evidence from Android and iOS devices that may help identify a spyware infection.
It was built by Amnesty International's Security Lab as part of the 2021 Pegasus Project investigation and is maintained today by the same lab and outside contributors. It checks a device against published indicators of compromise (IOCs) — known technical fingerprints of specific spyware campaigns — but the project explicitly says public indicators alone cannot prove a device is clean, and that this is a research tool for investigators, not a self-check app for the public.
You could use it to…
- Scan a phone for forensic traces of a spyware infection
- Check a device against published indicators of compromise
- Gather forensic evidence for a security investigation
Can I use this?
You'll need Python, a terminal, and comfort with digital forensics · Setup needed
Worth knowing The project states clearly that this requires understanding digital forensics and command-line tools, is not meant for end-user self-assessment, and that a clean result from public indicators does not prove a device was not targeted. Anyone concerned about their device's security should seek expert help rather than rely on this alone. MVT-licence (based on a modified MPL 2.0). BuildTube has not run or verified this software.
Why it's here
Not trending this week
Last seen on the GitHub trending list on 28 September 2026. It stays on BuildTube so you can still find it.
- 15,240 people have starred it on GitHub.
Numbers checked on 6 October 2026; not refreshed since.
Behind it
See the code on GitHubBuildTube has not run or verified this project. Everything above is written from what the creator published.
Made this?