Overview
Active Defense analyzes security-relevant network behavior from the user’s phone over a bounded assessment period. The objective is to identify indicators that may be consistent with mobile malware, commercial spyware, surveillance tooling, command-and-control behavior, or exfiltration-like activity. Active Defense is available in production to a selected user pool. Active Defense is designed as a non-intrusive capability:- It does not require root access.
- It does not require broad filesystem access.
- It does not decrypt application-layer traffic.
- It does not inspect message plaintext, call content, media, attachments, documents, or user conversations.
- It analyzes minimized technical signals, network-flow behavior, protocol characteristics, and security findings.
Purpose
Active Defense is designed to evaluate mobile malware-risk and suspicious device activity risk without inspecting protected communications. The purpose is to provide privacy-preserving security context that can support:- User security decisions.
- Device Trust evaluation.
- Account and device lifecycle decisions.
- Enigm Command review workflows where authorized.
- Enigm Intelligence correlation where policy permits.
Security Signals
Active Defense evaluates minimized security signals. Security signal categories may include:- Device security state.
- App integrity signals.
- Runtime protection findings.
- Network-risk indicators.
- Suspicious behavior indicators.
- Malware-risk findings.
- Security findings.
- Device-risk context.
- Network-flow characteristics.
- Protocol and transport characteristics.
- Device posture signals where available.
What Active Defense Does Not Inspect
Active Defense must not inspect:- Message plaintext.
- Call content.
- Media content.
- Attachments.
- User conversations.
- Private keys.
- Plaintext recovery phrases.
- Device-held private key material.
Device-Side Processing
Active Defense assessments are initiated by the user from Enigm App. The user can see when analysis is active. Active Defense is designed to process security-relevant signals from the device with least access necessary for the assessment. Device-side processing should prioritize:- Minimized technical signals.
- Security context rather than content.
- Local device-risk evaluation where possible.
- User visibility when assessment activity is active.
- Separation from protected communications and private key material.
Server-Side Processing
Active Defense analysis is performed in an Enigm-controlled VPN analysis environment. Analysis data is protected in transit and at rest. Server-side processing remains limited to the security purpose and uses minimized security context. It must not require message plaintext, call content, media content, attachments, user conversations, or private keys. Where Active Defense findings are shared with Enigm Intelligence or Enigm Command, access must remain authorization-scoped and separated from protected content.Telemetry Minimization
Active Defense telemetry should be minimized. Telemetry minimization means:- Prefer aggregated security context over raw observations where possible.
- Avoid unnecessary identity metadata.
- Use privacy-preserving identifiers where device correlation is required.
- Separate findings from protected content.
- Avoid broad retention of raw network observations where security context is sufficient.
Data Retention
Active Defense does not retain raw analysis data after the assessment workflow completes. Retained Active Defense state is limited to finding metadata and user-visible security context, such as whether suspicious behavior was detected, severity, category, and recommendation. The user controls whether Active Defense findings remain available in the app or are deleted.Access Control
Access to Active Defense findings should be restricted to authorized security workflows. Access control should:- Scope review by user role, account context, device context, and policy.
- Preserve separation from protected communications.
- Protect findings as security-sensitive information.
- Avoid expanding access through conversational, administrative, or support workflows.
- Ensure Enigm Command visibility does not become message content visibility.
Design Objectives
Active Defense is designed to:- Support mobile malware and spyware risk assessment.
- Identify suspicious network behavior during defined assessment windows.
- Detect indicators consistent with advanced targeted spyware activity without claiming complete detection of any specific family.
- Provide user-facing findings, severity context, and recommendations.
- Reduce uncertainty around Device Trust.
- Preserve content confidentiality during security analysis.
- Support Enigm Intelligence correlation where authorized and policy-permitted.
- Improve privacy by helping users identify device conditions that may expose protected communications.
Non-Intrusive Assessment Model
Active Defense is designed around network-behavior analysis rather than device-content inspection. The assessment model focuses on:- Network metadata and flow characteristics.
- Timing, recurrence, and burst behavior.
- Protocol and transport characteristics.
- Name-resolution behavior.
- Certificate and channel-integrity indicators.
- Destination-risk context.
- Covert-channel indicators.
- Multi-signal correlation.
Network Behavior Analysis
Advanced mobile spyware often remains invisible at the user-interface level, but its operational phases can still produce observable network behavior. Active Defense is designed to evaluate those network-behavior patterns without reading encrypted payload content. Examples of behavior categories include:- Periodic beaconing or recurring outbound communication patterns.
- Protocol behavior inconsistent with expected device activity.
- Destination or routing patterns that require review.
- Unusual upload/download asymmetry.
- High-entropy encrypted traffic patterns associated with non-standard channels.
- DNS behavior consistent with tunneling, generated domains, or unusual resolution patterns.
- Certificate-chain or transport-fingerprint anomalies.
- Protocol-port mismatch or tunnel-like behavior.
- Burst timing that may be consistent with staged data transfer.
AI-Assisted Risk Analysis
Active Defense uses AI-assisted analysis to evaluate network-behavior signals and produce security context. The AI layer is intended to support:- Multi-signal correlation.
- Pattern recognition across network-behavior categories.
- Confidence-based findings.
- Severity classification.
- User-readable recommendations.
- Escalation context for Enigm Intelligence where authorized.
Threat Analysis Model
Active Defense evaluates categories of security behavior rather than exposing internal detection logic. Analysis may consider:- Network behavior associated with suspicious communication patterns.
- Destination and protocol characteristics.
- Secure name-resolution behavior.
- Transport fingerprinting anomalies.
- Certificate and channel-integrity indicators.
- Repeated or unusual connection behavior.
- Timing, volume, and burst characteristics.
- Encrypted traffic metadata where inspection is not required to read payload content.
- Potential covert-channel indicators.
- Device posture and integrity signals where available.
- Security findings produced by platform protections.
- Correlation between multiple independent security indicators.
Malware And Spyware Risk
Active Defense is intended to help identify risk patterns associated with mobile malware, spyware, stalkerware, commercial surveillance tooling, and advanced targeted spyware. Examples of risk categories include:- Suspicious outbound communication behavior.
- Unusual network timing or connection recurrence.
- Protocol behavior inconsistent with expected device activity.
- Potential command-and-control communication patterns.
- Potential exfiltration-like traffic behavior.
- Potential post-compromise callback behavior after physical access or device exposure.
- Device posture degradation that may affect trust decisions.
Assessment Workflows
Active Defense supports security assessments initiated by the user. Conceptual assessment modes include:- On-demand assessment: initiated by the user before or after a security-sensitive activity.
- High-risk review assessment: initiated by the user after suspected device seizure, tampering, exposure, or unusual behavior.
- Keep the user informed when analysis is active.
- Avoid unnecessary access to private content.
- Produce understandable findings.
- Separate informational observations from higher-risk findings.
- Recommend next steps without making unsupported conclusions.
Privacy Model
Active Defense is designed to support privacy rather than expand surveillance of the user. The privacy model is based on:- Data minimization.
- Purpose limitation.
- Content confidentiality.
- Privacy-preserving device handles.
- Reduced identity exposure.
- Security context instead of broad user-content collection.
- Message plaintext.
- Call content.
- Media content.
- Attachments.
- Documents.
- User conversations.
Relationship With Enigm App
Enigm App remains the primary user-facing product. Active Defense extends the app with network-behavior security visibility that can help users make privacy and Device Trust decisions. Active Defense supports:- Device security review.
- User guidance after suspicious findings.
- Account and device lifecycle decisions.
- Multi-Device Trust evaluation.
- Managed-device reporting where enabled.
Relationship With Enigm OS
When Enigm OS is deployed, Active Defense may use additional local trust signals, such as Trust Security Center state, network policy state, managed-device state, privacy mode state, and device integrity posture. Enigm OS is an additional hardening layer. It does not replace Active Defense, Enigm App end-to-end encryption, or user trust decisions.Relationship With Enigm Intelligence
Active Defense findings may contribute security context to Enigm Intelligence where authorized and policy-permitted. Enigm Intelligence may correlate Active Defense findings with other security signals to support investigation, risk assessment, defensive response, and authorized user visibility. Correlation must preserve access controls, data minimization, and content confidentiality. Active Defense is not the full Threat Intelligence Platform. Enigm Intelligence provides broader correlation and risk evaluation across the ecosystem.Findings And User Guidance
Active Defense findings should provide clear security guidance without overstating certainty. Findings may include:- Informational network observations.
- Suspicious behavior requiring review.
- Higher-risk multi-signal correlation.
- Device Trust impact.
- Recommended user action.
- Recommended security review.
- Review recommended.
- Device Trust may be reduced.
- Network behavior requires attention.
- Update or configuration review recommended.
- Consider revoking or replacing a device if compromise is suspected.
- Contact security support through designated channels where appropriate.
User Visibility
Active Defense should provide user-visible security context. User-facing output should be understandable and should distinguish:- Informational observations.
- Suspicious findings.
- Higher-risk findings.
- Recommended review.
- Recommended user action.
Security Considerations
- Active Defense should operate with least access necessary for the assessment.
- Findings should be protected as security-sensitive information.
- Device-originated signals may be less reliable if the device is already compromised.
- Multi-signal correlation can improve confidence but does not eliminate uncertainty.
- Managed-device reporting must remain separate from protected communication content.
- Security analysis should not weaken end-to-end encryption or key protection.
Privacy Considerations
Active Defense supports the Enigm privacy-first model by helping identify device conditions that may expose private communications. Privacy considerations include:- Avoid collecting unnecessary identity metadata.
- Avoid broad retention of raw security observations where security context is sufficient.
- Avoid content inspection for message, call, media, attachment, and conversation data.
- Use privacy-preserving identifiers for account-device correlation where possible.
- Limit access to findings according to authorization and policy.
Trust Boundaries
Primary trust boundaries include:- User to Enigm App.
- Enigm App to Active Defense.
- Active Defense to minimized network and security signals.
- Active Defense to optional Enigm OS trust signals.
- Active Defense to Enigm Intelligence where authorized.
- Active Defense findings to Enigm Command review workflows.