# mvt-project/mvt

MVT (Mobile Verification Toolkit) helps with conducting forensics of mobile devices in order to find signs of a potential compromise.

Repository: https://github.com/mvt-project/mvt
Canonical: https://ross.abutalabs.com/products/mvt
Homepage: https://mvt.re
Language: Python
License: NOASSERTION
License Family: other
Topics: forensics, mobile, security, android, ios, forensics-tools
Last push: 2026-08-26T09:17:17+00:00

## Health v2 (maintenance only)
Score: 94/100 (v2, computed 2026-09-02T17:46:02.011165+00:00)
- activity 99, release rhythm 83, longevity 100
- inputs: {"age_days": 1874, "days_push": 7, "days_rel": 35, "gap_med": 77, "n_releases_24m": 6}
- flags: no_license
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 12967, forks 1280 (observed 2026-08-28T04:11:00.265869+00:00)

## What it is
Mobile Verification Toolkit (MVT) is a Python command-line toolkit for conducting forensic analysis of Android and iOS devices to detect traces of spyware compromise. Developed by Amnesty International's Security Lab during the Pegasus Project, it scans devices and backups against indicators of compromise from known spyware campaigns.

## Use cases
- scan an iPhone for traces of Pegasus spyware
- check an Android device for signs of compromise
- analyze iOS backups and crash logs for forensic evidence
- run indicators of compromise against a mobile device
- perform consensual forensic triage of a client's phone
- investigate suspected spyware targeting of civil society

## When to choose
- you are a forensic investigator or technologist analyzing Android or iOS devices for spyware
- you need to scan devices against published IOC lists from research groups
- you want an open-source, community-maintained mobile forensics tool

## When to avoid
- you are an end user wanting to self-check your device without forensic expertise
- you need a point-and-click GUI tool
- you require native Windows support without WSL
- you need guaranteed detection - public IOCs alone can miss recent compromises

## Facets
- artifact type: cli-tool
- maturity: active
- function: security, cli, developer-tools
- domain: security, mobile-development, privacy, developer-tools
- platform: cli, python
- tags: digital-forensics, spyware-detection, indicators-of-compromise, android, ios, pegasus, mobile-security, linux, macos

## Member repositories
- mvt-project/mvt (main) score 94

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:11:00.265869+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-29T17:13:38.986113+00:00, confidence not recorded.
  - readme: https://github.com/mvt-project/mvt (fetched 2026-08-28T04:11:00.265869+00:00, sha 7f41b53625da)
  - homepage: https://mvt.re (fetched 2026-08-29T08:09:33.754925+00:00, sha d5368e4b2de2)
  - site_page: https://docs.mvt.re/en/latest/install (fetched 2026-08-29T08:09:33.763503+00:00, sha 3038952d45bb)
  - site_page: https://docs.mvt.re/en/latest/ios/install (fetched 2026-08-29T08:09:33.765956+00:00, sha ccbee2ed7956)
  - registry_pypi: https://pypi.org/pypi/mvt/json (fetched 2026-08-29T08:09:33.767961+00:00, sha 6f38ec4bb234)
- Data as of 2026-08-30T08:39:29.467469+00:00.
