
By The Numbers
What We Do
Binary Reverse Engineering
Static and dynamic analysis of compiled binaries, native libraries, and obfuscated payloads across iOS, Android, and desktop runtimes.
Network Protocol Analysis
Capturing, decrypting, and documenting the exact API calls, telemetry channels, and hidden endpoints your apps phone home to.
Privacy & Data Audits
Tracking what apps collect, store, and transmit — including clipboard reads, device fingerprinting, and background activity.
Long-Form Technical Reports
Multi-thousand-word investigations with annotated screenshots, packet captures, and reproducible methodology for every claim.
Reader Q&A and Triage
Submit suspicious app behavior. Our analysts triage community submissions weekly and publish confirmed findings.
Vendor Response Tracking
We follow up. Every disclosure, CVE, and patch timeline is documented so you know which companies actually fix problems.
How We Work
Target Selection
Reader nominations, breach reports, and our own anomaly hunting produce the next investigation queue.
Static & Dynamic Capture
Decompilation, sandbox execution, MITM proxies, and traffic capture under instrumented test devices and accounts.
Cross-Reference Findings
Every behavior is verified against documentation, prior versions, and known CVEs before publication.
Disclosure & Publish
Responsible vendor notification, embargo windows, then full public teardown with evidence archive.
What People Say
Anti Tgtsoft caught a background data exfiltration bug our internal QA missed for two years. Their methodology is unmatched.
I link their teardowns in every internal postmortem. The only publication that documents how software actually behaves, not how vendors claim it does.
Suspicious Behavior in an App You Use?
Send us the target. If it lands in the queue, the entire teardown publishes free for the community.
Submit a Target App →