Used Auditor - hardware-based intrusion detection for Android?


Editors’ Review

Download.com staff

Experience Auditor - hardware-based intrusion detection, developed by Daniel Micay, a tool that verifies Android device integrity. It uses cryptographic attestations from the device's Trusted Execution Environment or hardware security module to detect bootloader unlocks, verified boot failures, downgrades, and unauthorized firmware changes. Features include local QR-based cross-device verification, optional scheduled remote checks with email alerts, and open-source attestation code for public audit. Designed for privacy-conscious users, enterprise fleets, and security professionals needing high-assurance mobile integrity checks on Android devices.

Top Recommended Alternative

The app queries the device's Trusted Execution Environment or hardware security module to obtain cryptographic signatures that reflect bootloader and verified-boot status. This method detects tampering, operating system downgrades, and unauthorized firmware changes by comparing those signatures to an expected state. Local verification uses QR-based exchange so a separate monitor device shows results, while an optional remote service performs scheduled attestations and can send email alerts.

Auditor attests device state using hardware-rooted cryptography

Checks run as discrete cryptographic queries, not continuous intrusive scans

Because Auditor relies on hardware-generated signatures rather than filesystem scanning, it does not perform prolonged background sweeps of user storage. The verification flow is a short attestation request to the secure module, producing a compact result for display or transmission. Remote scheduled checks execute at configured times; the app's model centers on periodic attestations instead of constant monitoring.

Design choices prioritize high assurance and privacy for sensitive deployments

The tool uses hardware-rooted trust and a privacy-first approach that records device-specific cryptographic identifiers to avoid cross-device tracking. The attestation protocol and client code are open source for external review, and the Trust On First Use scheme pins a device identity for later comparisons. These elements make the app suitable for environments that require verifiable, tamper-evident device state reporting.

Some operational familiarity is required for correct use

Local audits need two devices and an understanding of Trust On First Use pairing to avoid accidental trust establishment. The optional remote monitoring path requires configuring scheduled checks and email alerts. Functionality depends on hardware-backed attestation support and Android 8.0 or later; the app is most effective on supported devices such as Google Pixel models and on GrapheneOS, where hardware attestation is fully available.

Enlarged image for Auditor - hardware-based …
Auditor - hardware-based intrusion detection 0/4
  • Pros

    • Hardware-backed attestation using TEE or hardware security module
    • Local QR-based verification displays results on a separate monitor device
    • Open-source attestation protocol and app code available for public audit
  • Cons

    • Requires devices with hardware-backed attestation support
    • Optimal functionality limited to Pixel devices and GrapheneOS
    • Initial Trust On First Use pairing needs careful first-time verification

Bottom Line

Auditor is a rigorous choice for high-assurance mobile integrity checks

Auditor is a rigorous option for security-focused individuals and enterprises that need hardware-rooted verification of device integrity, supported by open-source code and a privacy-first model. The main limitation is the dependence on hardware-backed attestation, which restricts full functionality to compatible devices. As a practical tip, perform the initial local pairing in person and schedule remote attestations during idle hours to avoid operational interference.


Used Auditor - hardware-based intrusion detection for Android?


Explore More


Full Specifications

GENERAL
Release
Latest update
Version
78
OPERATING SYSTEMS
Platform
Android
Operating System
Android 13.0
POPULARITY
Total Downloads
31
Downloads Last Week
0

Report Software

Program available in other languages


Last Updated


Developer’s Description

The Auditor app uses hardware security features on supported devices to validate the integrity of the operating system from another Android...

The Auditor app uses hardware security features on supported devices to validate the integrity of the operating system from another Android device. It will verify that the device is running the stock operating system with the bootloader locked and that no tampering with the operating system has occurred. It will also detect downgrades to a previous version. Supported devices:

* BlackBerry Key2 (BBF100-1 and BBF100-6 models)

* BQ Aquaris X2 Pro

* Google Pixel 2

* Google Pixel 2 XL

* Google Pixel 3

* Google Pixel 3 XL

* Google Pixel 3a

* Google Pixel 3a XL

* Huawei Honor 7A Pro (AUM-L29 model)

* Honor 9 Lite (LLD-L31 model)

* Huawei Honor 10 (COL-L29 model)

* Huawei Honor View 10 (BKL-L04 and BKL-L09 models)

* Huawei Mate 10 (ALP-L29 model)

* Huawei Mate 20 lite (SNE-LX1 model)

* Huawei Mate 20 Pro (LYA-L29 model)

* Huawei P smart 2019 (POT-LX3 model)

* Huawei P20 (EML-L09 model)

* Huawei P20 Pro (CLT-L29 model)

* Huawei Y7 2019 (DUB-LX3 model)

* Huawei Y9 2019 (JKM-LX3 model)

* HTC EXODUS 1

* HTC U12+

* LG Stylo 5 (LM-Q720 model)

* LG Q Stylo 4 (LG-Q710AL model)

* Motorola moto g

* Motorola One Vision

* Nokia 3.1

* Nokia 6.1

* Nokia 6.1 Plus

* Nokia 7.1

* Nokia 7 Plus

* OnePlus 6 (A6003 model)

* OnePlus 6T (A6013 model)

* OnePlus 7 Pro (GM1913 model)

* Oppo R15 Pro (CPH1831 model)

* Oppo A7 (CPH1903 model)

* Oppo A5s (CPH1909 model)

* Realme C2 (RMX1941 model)

* Samsung Galaxy A70 (SM-A705FN model)

* Samsung Galaxy Amp Prime 3 (SM-J337AZ model)

* Samsung Galaxy J2 Core (SM-J260A, SM-J260F and SM-J260T1 models)

* Samsung Galaxy J3 2018 (SM-J337A and SM-J337T models)

* Samsung Galaxy J7 (SM-J737T1 model)

* Samsung Galaxy M20 (SM-M205F model)

* Samsung Galaxy Note 9 (SM-N960F and SM-N960U models)

* Samsung Galaxy Note 10 (SM-N970F and SM-N970U models)

* Samsung Galaxy Note 10+ (SM-N975U model)

* Samsung Galaxy S9 (SM-G960F, SM-G960U, SM-G960U1, SM-G960W and SM-G9600 models)

* Samsung Galaxy S9+ (SM-G965F, SM-G965U, SM-G965U1 and SM-G965W models)

* Samsung Galaxy S10e (SM-G970F model)

* Samsung Galaxy S10+ (SM-G975F model)

* Samsung Galaxy Tab A 10.1 (SM-T510 model)

* Samsung Galaxy Tab S4 (SM-T835 model)

* Sony Xperia XA2 (H3113, H3123 and H4113 models)

* Sony Xperia XZ1 / XZ1 Compact (G8341 and G8342 models)

* Sony Xperia XZ1 Compact (G8441 model)

* Sony Xperia XZ2 (H8216 model)

* Sony Xperia XZ2 Compact (H8314 and H8324 models)

* T-Mobile REVVL 2

* Vivo 1807

* Xiaomi Mi A2

* Xiaomi Mi A2 Lite

* Xiaomi Mi 9

* Xiaomi POCOPHONE F1

It cannot be bypassed by modifying or tampering with the operating system (OS) because it receives signed device information from the device's Trusted Execution Environment (TEE) or Hardware Security Module (HSM) including the verified boot state, operating system variant and operating system version. The verification is much more meaningful after the initial pairing as the app primarily relies on Trust On First Use via pinning. It also verifies the identity of the device after the initial verification.

See


Download.com
Your review for Auditor - hardware-based intrusion detection