The Full Surface

100+ RASP Detection Vectors.

Every item below is a real, individually-named detector shipping in the NonaShield SDK today — not a marketing category. 100+ are implemented across Android and iOS; the most representative are grouped here by attack surface.

// Root, Jailbreak & Device Compromise

Root Probe — su binary scan Jailbreak Signal — sandbox-escape fork() test Jailbreak Classifier — definitive vs. heuristic Root Cloaking Signal — Magisk Hide KernelSU / APatch / Shamiko detection Combo Threat Evaluator — root + proxy fusion

// Debugger & Anti-Instrumentation

Ptrace Tracer Signal — /proc/self/status TracerPid Debugger Signal (iOS) — sysctl P_TRACED Runtime Integrity Gate — pre-signing re-check

// Hooking Frameworks (Frida / Xposed / LSPosed)

Hooking Framework Signal — 4-vector Frida/Xposed scan Hook Detection Signal (iOS) — Substrate/ElleKit Runtime Manipulation Signal — ClassLoader integrity Native Library Integrity Signal — SHA-256 .so check Reflection Guard Signal Shell Execution Signal — RE-tool spawn monitor

// Tamper, Repackaging & SDK Self-Integrity

Repackaged Signal — cert hash mismatch App Signature Verifier Static Integrity Verifier — classes.dex SHA-256 SDK Self-Tamper Signal Build Pipeline Signal — CI provenance hash App Downgrade Signal Local Storage Tamper Signal — canary UUID Sideloaded App Signal ContentProvider Firewall Signal — live SQLi probing

// Emulator & Bot-Farm Detection

Emulator Fingerprint Signal — HARD/SOFT model Zero Sensor Activity Signal Application Velocity Signal — enrollment burst Auto-Clicker / Macro Signal Form Timing Consistency Signal Bot Automation Pattern — zero-jitter gate

// Screen-Share, Overlay & UI Attacks

Overlay Attack Signal Tapjacking Protector Tapjacking Integrity Gate StrandHogg Signal — task-hijack 1.0 + 2.0 Accessibility Abuse Signal Remote Desktop Signal Screen Mirroring Signal Screen Recording Signal Secure Screen Enforcer — FLAG_SECURE

// Deepfake & Camera Attack Surface

Virtual Camera Signal — DroidCam/EpocCam/Iriun Background Camera Signal Deepfake Precondition Signal

// Network, MITM & SSL Pinning

Certificate Pinner — SHA-256 public-key pinning TLS Pin Mismatch Signal Proxy Detector VPN Conflict Signal

// Hardware Attestation

StrongBox Attestation Signal Key Attestation Verifier — Google root chain

// Fraud-Specific Device Detectors

SIM Swap Signal — ICCID/IMSI baseline GNSS Spoofing Signal — raw satellite C/N0 variance

Root-detection baseline integrates the third-party Free-RASP-KMP engine; every vector above is additional, SDK-authored defense-in-depth layered on top of it.

See It In Action

Watch the Attack Fail.

DEVICE ROOTED
APP ASKS ITSELF
ANSWER IS FAKED
HARDWARE ASKED
ACCESS BLOCKED
Ready to begin.

Final Verdict.

"Appdome operates inside the system boundary. NonaShield verifies outside the system boundary".

Deterministic Security