Scenarios

Use Cases

Deployed globally by teams requiring fast, reliable iOS interrogation.

Corporate Security

Executive travel triage. Scan devices upon return from high-risk regions before reconnecting to the corporate network.

Incident Response

Rapid validation of suspected mobile compromise during a wider organizational breach.

Law Enforcement

First-responder field triage to determine if a device warrants full lab acquisition.

Border Security

Quick, targeted scans at points of entry to identify unauthorized configurations.

Insider Threat

Identifying unauthorized data exfiltration tools or MDM-bypassing profiles on corporate devices.

VIP Protection

Regular health checks on devices belonging to high-net-worth individuals or politicians.

Healthcare Compliance

Ensuring devices accessing patient records haven't been compromised or jailbroken.

Academic Research

Studying iOS artifact behavior and malware persistence mechanisms.

eDiscovery

Targeted collection of specific communication artifacts without full imaging.

Corporate Security Mobile Triage

Corporate security teams face a specific challenge after executive travel to high-risk regions: every device that left the network perimeter is a potential re-entry vector. Traditional MDM checks confirm policy compliance but cannot detect sophisticated spyware, unauthorized profiles installed by third parties, or configuration changes made under physical duress.

CALIBRE Mobile Labs gives security operations a deterministic answer in under five minutes. Connect the device over USB before it rejoins the network, run a full artifact scan, and review a structured report covering installed profiles, entitlements, background process activity, and suspicious plist entries. Common risk indicators include unexpected VPN configurations, side-loaded enterprise certificates, and MDM enrollment from an unrecognized server.

Devices that pass triage are cleared for reconnection. Devices that flag anomalies are quarantined and escalated to full forensic acquisition without the team having spent lab capacity on every returning handset.

Common risk indicators

  • • Unauthorized MDM enrollment profiles
  • • Third-party enterprise signing certificates
  • • VPN configurations pointing to unknown endpoints
  • • Suspicious background daemon registrations
  • • Modified system plists outside expected baselines

Typical workflow

  1. Device returned from travel — not yet on Wi-Fi
  2. USB connection to CALIBRE workstation
  3. 5-minute scan; structured report generated
  4. Clear → reconnect; flag → quarantine and escalate

Law Enforcement Field Triage

First-responder digital forensics teams frequently face a familiar bottleneck: far more seized devices than lab capacity, and a legal clock ticking on each one. Full Cellebrite or Magnet Axiom acquisitions are thorough but time-consuming — submitting every device to the lab is neither practical nor justifiable.

CALIBRE Mobile Labs is designed specifically for this prioritization decision. Without modifying the device or writing to its storage, CALIBRE reads iOS artifacts over a trusted USB pairing to surface indicators of interest: communication app presence, encrypted vault applications, known exploit tooling, and recently deleted application traces. A detective in the field can complete this assessment in the time it takes to book the device into evidence.

The output is a structured, exportable report that documents the findings and the methodology, maintaining chain-of-custody integrity and providing justification for further lab acquisition if required.

Triage output examples

  • • Encrypted messaging app inventory (Signal, Wickr, Element)
  • • Vault and burner app detection
  • • Deleted app traces and timeline reconstruction
  • • Device pairing and trust record history
  • • Exportable report for case file inclusion

Key constraint

CALIBRE is read-only. Nothing is written to the device. Forensic integrity is preserved throughout the triage process.

Border Device Screening

Border agencies and customs teams operate under time pressure with a high volume of devices and limited forensic resource. Travellers move through inspection in minutes, and the decision to escalate — detain the device for deeper examination or permit entry — must be made quickly on the basis of observable indicators rather than a full acquisition.

CALIBRE Mobile Labs provides exactly this capability. Connecting an iPhone over USB, the tool reads the device's installed profile list, app inventory, entitlement grants, and configuration artefacts without imaging the device or requiring the user's passcode. Suspicious configurations — such as active VPN tunnels to anonymizing infrastructure, MDM enrollment from unrecognized authorities, or the presence of anti-forensic or counter-surveillance applications — are surfaced immediately.

For border agencies, CALIBRE acts as the first filter: low-risk devices clear in minutes, while flagged devices are quarantined for full forensic acquisition with a documented justification for the escalation.

Screened artefacts

  • • Active MDM and configuration profiles
  • • Installed application inventory with entitlement data
  • • VPN and proxy configurations
  • • Anti-forensic and counter-surveillance tool presence
  • • Device trust and pairing history

Part of a Wider Investigation

CALIBRE is not designed to replace Cellebrite or Magnet Axiom. It is designed to sit in front of them. When you have 50 devices and need to know which 3 to send to the lab, CALIBRE provides the triage capability to make that decision in minutes.

The Triage Workflow

1. Device Seized
2. CALIBRE Scan (5m)
3. Lab Acquisition (If flagged)