Skip to content

Signals

Signals appear in result.signals, each with a strength that decides how much it counts. See Detection results for the rule. The strengths live in signal_strengths.dart, and a test fails if native code emits a signal missing from it.

Check Signal Strength
root su_binary_path Strong
root su_executable Strong
root magisk_artifacts Strong
root writable_system Strong
root superuser_apps_installed Medium
root root_cloaking_apps_installed Medium
root busybox_present Weak
root build_tags_test_keys Weak
root dangerous_system_props Weak
emulator qemu_pipe Strong
emulator fingerprint, model, manufacturer, hardware, product, brand_device Medium
debugger debugger_connected Strong
debugger waiting_for_debugger Strong
debugger debuggable_flag Weak
mock location mock_provider_flag Strong
mock location mock_app_selected_for_this_app Strong
mock location impossible_velocity Medium
mock location legacy_allow_mock_location_setting Medium
mock location fake_gps_app_installed Weak
Check Signal Strength
jailbreak jailbreak_app_paths Strong
jailbreak suspicious_system_paths Strong
jailbreak writable_outside_sandbox Strong
jailbreak process_spawn_check Strong
jailbreak dyld_env_var Strong
emulator simulator_target Strong
debugger ptrace_flag Strong
mock location known_spoofing_tweak_artifact Strong
mock location invalid_location_accuracy Medium
mock location impossible_velocity Medium

Jailbreak detection doesn’t run on the iOS Simulator, which can’t be jailbroken. It returns CheckStatus.notApplicable there.

A strength reflects how often a signal fires on devices that aren’t compromised. They’re our assessment, based on how each check works. Measure them against your own users before blocking anyone.