Digital Forensics
Spyware Detection Service for Phones, Computers and Accounts
Find out whether stalkerware, remote-access tools, a rogue management profile or a compromised Apple ID or Google account is exposing you, with findings documented to support a protective order, police report or lawsuit.
When a spyware detection service makes sense
A spyware detection service is for the moment when someone seems to know things they should not: where you parked, what you texted, who you met for lunch. Honeybadger Solutions examines phones, computers and the accounts tied to them for stalkerware, commercial spyware, remote-access tools, unknown device management profiles and location tracking. The work is part of our digital forensics services, so every finding is preserved with chain of custody and written up in a report that a lawyer, an advocate or a court can follow.
People usually reach out after one of these:
- A current or former partner, relative or coworker repeats details from private messages, emails or calls.
- Someone shows up where you are without being told the location.
- The phone shows a profile under VPN & Device Management that you never installed, or apps you do not recognize.
- Your Apple ID, iCloud or Google account lists devices, sign-ins or two-factor codes you did not trigger.
- A connected car app, home-security camera or smart-home account has users or shared access you did not set up.
- A business needs to know whether a laptop was remotely controlled or quietly monitored.
The FTC lists faster battery drain, unexpected data use and an abuser knowing your location as possible signs of stalkerware. Each of those also has innocent explanations. A forensic examination replaces guesswork with documented findings.
Safety first: plan before you remove anything
If you are in immediate danger, call 911. If the person watching you is a current or former partner, the National Domestic Violence Hotline offers free, confidential help 24/7 by phone, chat and text, and its advocates can help you build a safety plan.
Removing stalkerware, deleting a profile or changing a password can alert the person who installed it. The FTC warns that steps like these “could tip off your abuser,” and a sudden loss of access can escalate behavior. That is why we work in a fixed order: plan safety first, preserve the evidence second, and remediate third, on your timeline.
Contact us from a device the other person has never had access to, such as a work computer, a library computer or a new phone. Tell us on the request form how and when it is safe to reach you.
What our spyware detection service delivers
Every engagement starts with an assessment and adds only the acquisitions your devices and accounts need.
Compromise and stalkerware assessment
An examiner-led review of a phone or computer for stalkerware, spyware, remote-access tools, unknown management profiles, suspicious accessibility or device-admin permissions and tracking. Each finding is classified and paired with a remediation plan that fits your safety plan. Acquisition is a separate line item.
Standard phone extraction
One supported, unlocked phone with the passcode you supply, captured by logical or backup acquisition. Includes evidence intake, chain of custody, acquisition notes and hash verification. Analysis and expert opinions are separate.
Advanced phone extraction
A full file-system acquisition of one supported device, which reaches app data, logs and configuration files that a backup leaves out. We confirm the method, OS version and tool support before we start. Analysis is separate.
Computer imaging: Windows, Linux and Mac
One accessible disk imaged and hash-verified so we can hunt for remote-access tools, keyloggers and persistence without altering the original. Mac methods are documented according to hardware and encryption, with credentials you supply. Destination media is extra.
Locked or damaged phone assessment
A short, capped feasibility check when a phone is locked, broken or not yet supported. Extraction, specialist lab work and advanced access attempts are quoted separately once we know what is possible.
Account compromise review
For your own Apple ID and iCloud, Google, Microsoft, social media, connected car and home-security accounts: signed-in devices, sharing, recovery settings and access history, preserved per account before anything changes. Deleted or private third-party content is not guaranteed.
What we check on phones, computers and accounts
| Source | What we examine | Why it matters |
|---|---|---|
| iPhone and iPad | Configuration profiles and device management enrollment, Apple Account devices, Find My and location sharing, backups | Apple warns that profiles and device management “may allow access to data or location information on the device” |
| Android | Device-admin and accessibility apps, sideloaded packages, hidden icons, notification access | These permissions let an app read screens, messages and notifications |
| Windows, Mac and Linux | Remote-access tools, keyloggers, browser extensions, scheduled tasks, launch agents and services | Persistence shows how monitoring survives a reboot and who set it up |
| Cloud and email accounts | Signed-in devices, forwarding rules, app passwords, recovery email and phone | Account access often needs no software on the phone at all |
| Car and home apps | Authorized drivers and users, shared access, location and event history | Vehicle and camera apps can reveal movements and routines |
For physical GPS trackers on a vehicle or hidden cameras and microphones in a home or office, see our TSCM and bug sweep services. Many cases need both.
How an engagement runs
- Safe intake. Request the service online from a safe device and tell us the safest way to reach you.
- Scope and authority. We confirm who owns each device and account, what you suspect, and whether an advocate, attorney or police report is already involved.
- Preserve first. We acquire the phone or computer and preserve account data before any change, with chain of custody and hash verification. Clients outside Arizona can use a remote collection kit or remote collection for their own devices; we go onsite where needed.
- Examine. An examiner reviews the acquisition with tools such as Oxygen Forensic Detective, Cellebrite UFED or Magnet AXIOM, then checks profiles, permissions, logs and account access by hand.
- Report. You get a plain-language report that classifies each finding as confirmed, suspicious, benign or not determinable, with screenshots, hash values and stated limits.
- Remediate on your timeline. A step-by-step plan covering what to remove, what to reset and which accounts to secure in what order, coordinated with your safety plan.
This follows the collection, examination, analysis and reporting phases described in NIST SP 800-86 (2006), including the rule that analysis is done on a verified copy, not the original.
Authority, consent and legal limits
We examine only devices and accounts that you own or are lawfully authorized to access: your own phone or computer, a company device under a written policy, a minor child’s device as parent or guardian, or a device produced with the owner’s written consent or under court order.
We will not install monitoring software on another adult’s device, sign in to someone else’s account, bypass authentication we are not authorized to bypass, or “hack back” against the person you suspect. Arizona law treats several of those acts as crimes. A.R.S. 13-2316 (computer tampering) covers knowingly accessing a computer or network without authority and introducing a computer contaminant. A.R.S. 13-3005 makes intercepting electronic communications without the consent of a party a class 5 felony. A.R.S. 13-2923 includes in stalking the use of “any electronic, digital or global positioning system device to surveil a specific person” without authorization.
Vehicle apps come up often. In 2024 the FCC proposed rules (FCC 24-38) under the Safe Connections Act of 2022 to help survivors cut off an abuser’s access to connected car services. On work or school devices, Apple advises checking with the administrator before deleting a profile, because some profiles are legitimate. We confirm ownership before we call a profile hostile.
This is general information, not legal advice. Talk with an attorney or advocate about protective orders and reporting.
How it is priced
The assessment at the heart of our spyware detection service is billed hourly against an allowance we agree on after scoping. If the work needs more time, we ask for written approval first. Phone extractions and computer imaging are quoted per device, with scope set by device type, data volume and lock state. A locked or damaged phone assessment is a fixed fee per assessment with capped examiner time. Account preservation is quoted per account and date range.
What moves the quote: the number of devices and accounts, operating system and tool support, whether a device is locked or damaged, data volume, whether the report must support a protective order or testimony, and travel for onsite work.
| Included in every engagement | Quoted separately |
|---|---|
| Evidence intake and chain of custody | Destination media and extra data volume |
| Acquisition notes and hash verification | Specialist lab work and advanced access attempts |
| Findings classified with stated limits | Expert declarations and testimony |
| Safety-aware remediation plan | Onsite travel and TSCM sweeps |
Mistakes to avoid before your phone is checked
- Do not factory reset first if you may need proof. The FTC lists a reset or a new phone as a way to remove stalkerware, but a reset also erases the evidence. Preserve first when it is safe to wait.
- Do not restore apps from an old backup. The FTC warns that reinstalling apps from backups can bring the problem back.
- Do not confront the person you suspect. It can escalate risk and prompt them to wipe their own tracks.
- Do not research or plan on the suspected device. Use a safe device for searches, messages and our request form.
- Do not delete profiles, apps or account sessions yet. Screenshots are helpful, but forensic preservation keeps the details that screenshots miss.
- Do keep a written incident log. Dates, places and what the person knew help us focus the examination.
Who this is for
- Domestic violence survivors and advocates
- Family law and criminal defense firms
- Executives, public figures and their security teams
- Businesses with a suspected compromised laptop
- Parents and guardians of minors
- HR and corporate investigators
Frequently asked questions
How do I know if my phone has spyware?
Warning signs include faster battery drain, unexpected data use, unknown apps or profiles, and someone knowing your location or private conversations. Those signs have innocent causes too. A forensic spyware detection service confirms or rules out monitoring and documents what it finds.
Will the person who installed it know I had my phone checked?
A forensic acquisition copies data and does not remove anything, so by itself it does not cut off the other person’s access. Some monitoring tools report when a phone is offline, so we cannot promise they will not notice anything. Removal is the step most likely to be noticed, and we schedule it with your safety plan.
Can you check my iCloud, Apple ID or Google account for unauthorized access?
Yes, for accounts you own. We preserve the signed-in devices, sharing settings, recovery details and available access history before anything is changed, then give you an order of steps to lock the account down. Apple and Google both publish account checklists, and we document what they show.
Is a factory reset enough to remove stalkerware?
A reset removes many app-based tools, but it erases the evidence and does not fix a compromised cloud account, a shared Apple ID or a car or camera app. The FTC also warns against reinstalling apps from old backups. Preserve first when it is safe to wait.
Can you check someone else’s phone for me?
No. We only examine devices and accounts you own or are lawfully authorized to access, such as a company device under policy or a minor child’s device. We do not access another adult’s phone or account and we do not install monitoring software on anyone’s device.
Can the findings be used in court or for a protective order?
Our reports are court-ready by design: chain of custody, hash verification, the tools and methods used, and stated limits. Whether a court accepts them is up to the judge, so we work with your attorney or advocate on what the report needs to show.
Related guides
- Stalkerware detection and safe removal guide
- How to tell if your phone has spyware: the forensic signs
- Rogue MDM and malicious configuration profiles on iPhone
- Device admin and accessibility abuse on Android phones
- How to detect a hidden GPS tracker on your car
- Stalking threat assessment and response guide
- Mobile and tablet forensics service
- Computer and hard drive forensics service
- Cloud account extraction for iCloud, Google and Microsoft
- TSCM bug sweeps for homes, vehicles and offices
Sources: FTC: Stalkerware, What To Know; Apple Personal Safety User Guide; Google: See devices with account access; A.R.S. 13-2923; FCC 24-38 connected cars; NIST SP 800-86. Checked as of October 2026.
We examine only devices and accounts the client owns or is lawfully authorized to access, and we never install monitoring software on another adult’s device.
Get your devices checked safely
Request this service online from a safe device and pick spyware or stalkerware detection on the form. That routes your request straight to our cyber and forensics lead, so there is no phone tag and no voicemail left on a device someone else may see. If you are in immediate danger, call 911; for other urgent matters, use our urgent intake form.