logoalt Hacker News

acdhayesterday at 4:38 PM1 replyview on HN

How did you link that traffic to malicious activity?


Replies

walterbellyesterday at 4:44 PM

By minimizing apps on device, blocking all traffic to Apple 17.x, using Charles Proxy (and NetGuard on Android) to allowlist IP/port for the remaining apps at the router level, and then manually inspecting all other network activity from the device. Also the disappearance of said traffic after hard-reset.

Sometimes there were anomalies in app logs (iOS Settings - Analytics) or sysdiagnose logs. Sadly iOS 26 started deleting logs that have been used in the past to look for IOCs.

show 2 replies