Skip to content

Debugger detection

final result = await DeviceShield.checkDebugger();
Signal Check
debugger_connected Debug.isDebuggerConnected()
waiting_for_debugger Debug.waitingForDebugger()
debuggable_flag The app was built with android:debuggable (ApplicationInfo.FLAG_DEBUGGABLE)

debugger_connected and waiting_for_debugger are strong. debuggable_flag is weak.

A debug build without a debugger attached therefore comes back clear, with debuggable_flag listed as a weak signal. Only a real debugger, or a process waiting for one, means detected.

Signal Check
ptrace_flag The kernel marks the process as traced (P_TRACED, read with sysctl)

This is Apple’s documented technique (Technical Q&A QA1361). It’s a single, exact, strong signal. If the sysctl call fails, the result is “not traced”.

A debugger attached after a check has run isn’t noticed until the next check. Tools that hook the check itself (such as Frida) can hide a debugger.