1200KM / tool
FlexiSpy — Attack Tool
FlexiSpy is sophisticated surveillanceware for iOS and Android. Publicly-available, comprehensive analysis has only been found for the Android version. FlexiSpy markets itself as a parental control and employee monitoring application.
Tool identity and evidence
Included because the active pinned ATT&CK object has type tool. This is an upstream classification, not an assurance of benignness or a recommendation to run it.
Aliases: FlexiSpy
Existing author guides
No reviewed association in this snapshot.
Primary documentation
No reviewed association in this snapshot.
Connected ecosystem references
Linked tags
Technique-specific simulations and detections
Detection links describe the associated behavior, not independently verified tool-specific signatures.
- T1406 · Obfuscated Files or Information · Detection rules & anomalies
- T1409 · Stored Application Data · Detection rules & anomalies
- T1417.001 · Keylogging · Detection rules & anomalies
- T1418 · Software Discovery · Detection rules & anomalies
- T1421 · System Network Connections Discovery · Detection rules & anomalies
- T1429 · Audio Capture · Detection rules & anomalies
- T1430 · Location Tracking · Detection rules & anomalies
- T1509 · Non-Standard Port · Detection rules & anomalies
- T1512 · Video Capture · Detection rules & anomalies
- T1513 · Screen Capture · Detection rules & anomalies
- T1533 · Data from Local System · Detection rules & anomalies
- T1624.001 · Broadcast Receivers · Detection rules & anomalies
- T1625.001 · System Runtime API Hijacking · Detection rules & anomalies
- T1628.001 · Suppress Application Icon · Detection rules & anomalies
- T1630.002 · File Deletion · Detection rules & anomalies
- T1636.001 · Calendar Entries · Detection rules & anomalies
- T1636.003 · Contact List · Detection rules & anomalies
- T1636.004 · SMS Messages · Detection rules & anomalies
Telemetry context
Derived from the explicitly linked TTPs; not proof of sensor coverage for this tool.
- API Calls · DC0112
- Application Log Content · DC0038
- Application Permission · DC0114
- Application State · DC0123
- Command Execution · DC0064
- File Access · DC0055
- File Creation · DC0039
- File Deletion · DC0040
- Host Status · DC0018
- Module Load · DC0016
- Network Traffic Content · DC0085
- OS API Execution · DC0021
- Process Access · DC0035
- Process Creation · DC0032
- System Settings · DC0118
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.