Cyber-forensics & digital investigation
We show what a device, app or domain is really doing — and prove it.
Mythsect builds the tools and runs the investigations that let authorised teams recover the facts of a case from phones, networks and domains — captured without rooting or tampering, and preserved as evidence that holds up.
What we do
Four disciplines, one chain of custody.
Every engagement is authorised, non-destructive, and documented so the output survives review — whether it lands in a report, a briefing, or a courtroom.
device forensics
What a phone is actually doing
Live traffic, bundled trackers, sensitive-permission holders, hidden accessibility and admin access — read from the device without root, and tied back to the exact app responsible.
network & traffic
Every connection, named and sourced
Per-app connections resolved to real destinations, tracker and command-and-control endpoints flagged, and data-exfiltration patterns surfaced on the network you are authorised to watch.
attack surface
A domain's exposure, mapped
Subdomains, open ports and banners, weak TLS, email-spoofing gaps, exposed files and takeover risk — confirmed by content, not guessed from a status code. Detection-only, authorisation-gated.
evidence & reporting
Findings built to hold up
Hash-stamped, append-only case logs and reports. Each finding carries where it lives, how to reproduce it by hand, and how to resolve it — so an independent reviewer can check your work.
The platform
TrafficLens — our field toolkit.
The instrument we built to do this work: a no-root forensics suite that turns raw device and network activity into readable, reproducible, sealable evidence.
- Traffic monitor. Live per-app connections, with tracker SDKs identified and blockable on the spot.
- Attack-surface scanner. Domain mapping with evidence URLs, a verify command, and a fix for every finding.
- Tracker cross-reference. Which bundled SDKs are actually phoning home, matched against live captured traffic.
- Hash-stamped exports. Court-ready case reports sealed with SHA-256 and written to an append-only log.
Availability
Same engine across platforms — the Android field app ships now; desktop and web consoles are on the way for lab and remote work.
How we operate
The rules the work is built on.
Forensics is only useful if it is lawful and defensible. These are not slogans — they are constraints wired into every tool and engagement.
Authorised only
We operate strictly on devices, networks and domains you own or are lawfully authorised to examine. Every scanner is gated behind an explicit authorisation step.
Detection, not destruction
We observe and prove. No exploitation, no brute-force, no denial of service. We confirm a weakness and show you how to check it — we never weaponise it against the target.
Evidence that holds up
Every finding is reproducible, timestamped and hash-sealed. An independent reviewer can repeat the steps and arrive at the same result.
Work with us
Tell us the shape of the case.
A device, a network, or a domain — and what you need to establish. We will tell you what is recoverable, how it would be preserved, and what it would take.