The Full Surface
100+ RASP Detection Vectors.
Every item below is a real, individually-named detector shipping in the NonaShield SDK today — not a marketing category. 100+ are implemented across Android and iOS; the most representative are grouped here by attack surface.
// Root, Jailbreak & Device Compromise
Root Probe — su binary scan
Jailbreak Signal — sandbox-escape fork() test
Jailbreak Classifier — definitive vs. heuristic
Root Cloaking Signal — Magisk Hide
KernelSU / APatch / Shamiko detection
Combo Threat Evaluator — root + proxy fusion
// Debugger & Anti-Instrumentation
Ptrace Tracer Signal — /proc/self/status TracerPid
Debugger Signal (iOS) — sysctl P_TRACED
Runtime Integrity Gate — pre-signing re-check
// Hooking Frameworks (Frida / Xposed / LSPosed)
Hooking Framework Signal — 4-vector Frida/Xposed scan
Hook Detection Signal (iOS) — Substrate/ElleKit
Runtime Manipulation Signal — ClassLoader integrity
Native Library Integrity Signal — SHA-256 .so check
Reflection Guard Signal
Shell Execution Signal — RE-tool spawn monitor
// Tamper, Repackaging & SDK Self-Integrity
Repackaged Signal — cert hash mismatch
App Signature Verifier
Static Integrity Verifier — classes.dex SHA-256
SDK Self-Tamper Signal
Build Pipeline Signal — CI provenance hash
App Downgrade Signal
Local Storage Tamper Signal — canary UUID
Sideloaded App Signal
ContentProvider Firewall Signal — live SQLi probing
// Emulator & Bot-Farm Detection
Emulator Fingerprint Signal — HARD/SOFT model
Zero Sensor Activity Signal
Application Velocity Signal — enrollment burst
Auto-Clicker / Macro Signal
Form Timing Consistency Signal
Bot Automation Pattern — zero-jitter gate
// Screen-Share, Overlay & UI Attacks
Overlay Attack Signal
Tapjacking Protector
Tapjacking Integrity Gate
StrandHogg Signal — task-hijack 1.0 + 2.0
Accessibility Abuse Signal
Remote Desktop Signal
Screen Mirroring Signal
Screen Recording Signal
Secure Screen Enforcer — FLAG_SECURE
// Deepfake & Camera Attack Surface
Virtual Camera Signal — DroidCam/EpocCam/Iriun
Background Camera Signal
Deepfake Precondition Signal
// Network, MITM & SSL Pinning
Certificate Pinner — SHA-256 public-key pinning
TLS Pin Mismatch Signal
Proxy Detector
VPN Conflict Signal
// Hardware Attestation
StrongBox Attestation Signal
Key Attestation Verifier — Google root chain
// Fraud-Specific Device Detectors
SIM Swap Signal — ICCID/IMSI baseline
GNSS Spoofing Signal — raw satellite C/N0 variance
Root-detection baseline integrates the third-party Free-RASP-KMP engine; every vector above is additional, SDK-authored defense-in-depth layered on top of it.
See It In Action
Watch the Attack Fail.
DEVICE ROOTED
APP ASKS ITSELF
ANSWER IS FAKED
HARDWARE ASKED
ACCESS BLOCKED
Ready to begin.
Final Verdict.
"Appdome operates inside the system boundary. NonaShield verifies outside the system boundary".
Deterministic Security