This page is a completeness check for the current RKNHardering 2.10.0 source tree. It does not replace the topic-specific explanations. The “without root” and “with root” columns describe changes to the observable state, not a guaranteed pass. External projects may cover only part of a row on a particular kernel or ROM. Specific downloads and step-by-step installation are collected on the VPNHide, VPNHide Next, and root stack page, while primary references are listed under sources.
EvidenceSource values — 65| ID | Area | What the source reports | Without root | With root | Limitation |
|---|---|---|---|---|---|
GEO_IP |
Server path | Country, ASN/ISP, hosting/datacenter, and proxy/VPN indicators for the public IP. | Choose a consistent egress in the required country and network type; an external router does not change GeoIP by itself. | Root cannot correct remote databases; change the route or exit. | GeoIP databases disagree and lag; one clean provider does not guarantee the final verdict. |
DIRECT_NETWORK_CAPABILITIES |
Framework | TRANSPORT_VPN, IS_VPN, and VpnTransportInfo for the active network. |
This generally cannot be hidden locally; remove VpnService from the phone by using an external gateway. |
Run VPNHide or VPNHide Next in system_server with only System Framework in scope. |
A native backend without the framework layer does not change the Binder model. |
INDIRECT_NETWORK_CAPABILITIES |
Framework | Missing NOT_VPN, inconsistent capabilities, and an indirect VPN model. |
Use an external gateway; per-app bypass can leave a contradiction. | Filter NetworkCapabilities and related Parcel data at the system level. |
The active network, capabilities, callbacks, and LinkProperties must agree. |
ICMP_SPOOFING |
Server path | ICMP replies from addresses or domains the operator is expected to block, including possible substitution. | Do not falsify this locally; test on the actual operator network and repeat the run. | Root is normally unnecessary; a firewall can distort the result and create a false signal. | ICMP behavior depends on the operator, NAT, and rate limits; this is more often a review signal. |
RTT_TRIANGULATION |
Server path | Latency comparison between Russian and foreign hosts (SNITCH β or diagnostics). | Use a real, consistent route; do not treat a single RTT sample as proof. | Root cannot remove physical latency; local delay injection is unreliable. | Mobile networks, congestion, and Wi-Fi introduce substantial noise. |
SYSTEM_PROXY |
Proxy | Java properties, Proxy, default and per-network proxy state, PAC, exclusions, and validity. |
Disable the system proxy or PAC; use a TUN or an external gateway instead. | A system hook is possible, but removing the proxy is preferable; VPNHide Zygisk can filter some properties. | Applications may ignore the proxy, but its presence remains a separate signal. |
INSTALLED_APP |
Packages | Known VPN or proxy packages and name heuristics. | Do not install the client in the same profile; use an external router or a separate profile. | Use VPNHide Apps or PackageManager filtering for the observer UID. | Package visibility depends on Android, the OEM, and permissions; installation does not prove activity. |
VPN_SERVICE_DECLARATION |
Packages | Services declaring the android.net.VpnService intent. |
Keep the VPN client outside the target profile or on another device. | Filter PackageManager query, resolve, and direct-lookup paths. | System or privileged callers and self-lookups must continue to work. |
ACTIVE_VPN |
Framework | An active VPN network reported by Android connectivity APIs. | Remove the local VpnService or accept that it is visible. |
Filter the active network and network list in system_server. |
Native TUN and route indicators must be closed at the same time. |
LOCAL_PROXY |
Localhost | SOCKS5 or HTTP CONNECT on loopback and comparison of proxy and direct IP addresses. | Disable the listener or API; do not rely on changing the port. | Use a UID firewall, portshide, or kernel security_socket_connect filtering. |
A timeout and a refused connection are different; the shell UID is not equivalent to the application UID. |
XRAY_API |
Localhost | The Xray gRPC control API and its outbound list. | Disable the API or listener, or move the control plane off the phone. | Block loopback for the target UID; a secret does not conceal the port itself. | A full scan can discover the service on a different port. |
CLASH_API |
Localhost | Clash, Mihomo, or sing-box REST endpoints such as /configs, /connections, and /proxies. |
Disable the controller, use a Unix socket, or place it in an inaccessible namespace. | Use a UID firewall, portshide, or a kernel block. | A strong secret protects control operations, not the existence of the listener or protocol. |
SPLIT_TUNNEL_BYPASS |
Bypass | An explicit direct path for the application while a VPN or TUN exists. | Per-app direct routing fixes the egress but remains detectable; the best non-root option is an external gateway. | Conceal the local TUN and Binder model and make the direct egress consistent. | When the server IP and local model contradict each other, the bypass remains strong evidence. |
PROXY_AUTH_BYPASS |
Localhost | Weak or absent authentication on a local SOCKS or HTTP proxy. | Use strong authentication and disable any unnecessary listener. | Block the target UID even when authentication is enabled. | The scanner may identify the proxy before checking credentials. |
NETWORK_INTERFACE |
Interfaces | Java NetworkInterface, tun, wg, ppp, or ipsec names, and MTU. |
Use an external gateway; renaming an interface or changing MTU does not close the other channels. | Use a kernel backend; the framework layer alone is insufficient. | Raw netlink, ioctl, and the interface type must be consistent. |
ROUTING |
Routes | LinkProperties, /proc/net/route, default and split routes, and policy routing. |
Use an external gateway; a local split route remains visible. | Combine kernel route and netlink filtering with LinkProperties filtering in system_server. |
Single lookup, host-route, and backend-parity coverage vary by backend. |
DNS |
DNS | Loopback, private, or replaced DNS and differences between VPN and direct resolution. | Make DNS follow the HTTP and UDP outbound and remove the system proxy. | Root does not replace correct routing; the framework can hide DNS in LinkProperties, but server-side DNS remains. |
DoH, DoT, and IPv6 can take a different path. |
PROXY_TECHNICAL_SIGNAL |
Proxy | Known ports, multiple high ports, and proc socket artifacts. | Disable the daemon and listeners or use an external gateway. | Block loopback for the UID and filter proc or socket views when necessary. | Closing a control port does not remove the VPN interface itself. |
DUMPSYS |
Framework | dumpsys vpn_management and active VpnService instances when accessible. |
Access is often restricted on stock systems; a local application cannot conceal a system service. | Harden the system or framework and do not grant shell, Shizuku, or privileged access to the target. | ROM and privilege level determine access; denial does not prove that no VPN exists. |
LOCATION_SIGNALS |
Location | MCC/MNC, SIM, cell, Wi-Fi or BeaconDB, and Russia versus non-Russia context. | Use a real, consistent location and egress; do not base the strategy on fake GPS. | Root-level substitution is risky and creates inconsistencies; a correct egress is preferable. | Missing permissions or data usually lowers confidence but does not clear other channels. |
HOME_ROUTED_ROAMING |
Location | Legitimate roaming in which the visited network exits through the home country. | Preserve this context and ensure the SIM and roaming state explains the foreign egress. | Root is not required. | The context reduces false conclusions but does not conceal a VPN automatically. |
VPN_GATEWAY_LEAK |
Bypass | Discovery of a VPN gateway or underlying path that exposes a separate network. | Remove ambiguous multipath behavior or use an external gateway. | Conceal local routes and socket identity and make routing consistent. | The actual gateway may remain observable from the server side. |
VPN_NETWORK_BINDING |
Bypass | Binding a socket to the VPN or underlying Network produces a different path or IP. |
Do not leave an allowed bypass, or make both paths consistent. | Framework or native concealment does not change the real bind; correct the policy or route. | Internal and external observations must agree. |
TUN_ACTIVE_PROBE |
Bypass | A TUN exists while the application does not consider the active network a VPN, with DNS or path mismatch. | Do not use local per-app bypass as the only measure; use an external router. | Combine kernel and framework concealment with a consistent direct or in-tunnel path. | The probe is designed to catch split tunneling combined with a local TUN. |
TELEGRAM_CALL_TRANSPORT |
UDP and calls | Telegram, MTProto, or UDP transport probes and a possible leak. | Make UDP follow the intended route; do not block it without understanding the effect on calls. | A root firewall can route or block it, but may break the service. | Often experimental or review-only; repeat the test. |
WHATSAPP_CALL_TRANSPORT |
UDP and calls | WhatsApp STUN or UDP path and a possible separate egress. | Make UDP consistent and verify fallback behavior. | Use root firewall or routing changes only deliberately. | Blocking the response is not always a clean result. |
STUN_PROBE |
UDP and calls | The mapped address reported by Russian and global STUN servers. | UDP must follow the selected outbound; use an external gateway where appropriate. | Root does not alter a server-reported mapped IP; change routing or NAT. | NAT, IPv6, and blocking produce different states. |
NATIVE_INTERFACE |
Native | Native interface names, types, and addresses. | Use an external gateway. | Prefer a kernel backend; use Zygisk only as a fallback. | Raw syscalls bypass userspace hooks. |
NATIVE_ROUTE |
Native | Native route dumps, policy state, and proc routes. | Use an external gateway. | Use a kernel backend. | Verify IPv4 and IPv6, dump and single-lookup behavior, and interface indices. |
NATIVE_HOST_ROUTE |
Native | A public /32 or /128 host route to the VPN server through a physical interface. |
This is normally absent with VpnService; when present, change VPN routing. |
Upstream kernel backends claim route-shape filtering. | A server route through a physical interface is not concealed by a simple name filter. |
NATIVE_SOCKET |
Native | Socket addresses, bind-to-device state, UDP port conflicts, MSS, PMTU, and related socket indicators. | Use an external gateway or normalize the client where possible. | Use a kernel backend or VPNHide Next Medium or Max for the specific signal. | Some signals are heuristic and kernel-dependent. |
NATIVE_HOOK_MARKERS |
Integrity | maps, hook libraries, RWX memory, and known markers. |
Do not repackage or inject the target. | Use a kernel plus system_server architecture and remove the target from Xposed or Zygisk scope. |
Renaming a module does not remove structural artifacts. |
NATIVE_JVM_MISMATCH |
Integrity | Java and native APIs report different interfaces or routes. | Avoid partial hooks; use an external gateway. | Enable matching framework and kernel layers from the same release and verify the UID. | Partial concealment is worse than no concealment. |
NATIVE_LIBRARY_INTEGRITY |
Integrity | dlsym, ELF, linker, and library integrity. |
Do not repackage or use rootless injection. | Do not inject the target; use a kernel backend. | Zygisk or inline hooks may remain visible. |
NATIVE_ROOT_DETECTION |
Root | su, /data/adb, properties, mounts, SELinux, and UID 0. |
Use a stock device without root. | Do not grant root; use unmount or deny behavior, enforcing SELinux, read-only system partitions, and a minimal stack. | Undetectable root is not guaranteed. |
NATIVE_EMULATOR |
Device | QEMU, Goldfish, BlueStacks, and build indicators. | Use a physical device. | Root-based spoofing does not make an emulator physical and is not recommended. | Hardware and driver inconsistencies remain. |
SANDBOX_ISOLATION |
Profile | Secondary-user, work-profile, clone, and profile identity. | Run under the owner user; a profile is not concealment. | Do not break UserManager; only target the correct full UID. |
The truthful isolation signal remains. |
BETA_VPN_BINDER |
β Framework | A hidden Binder probe of the VPN service or state. | Use an external gateway. | Filter in system_server and verify with repeated runs. |
One of two β hard-authority paths when repeated results are stable. |
BETA_USER_PROFILE |
β Profile | User, profile, and foreground-user context. | Use the owner user. | Do not conceal this globally; target the correct UID. | A profile combined with a network discrepancy can form a quorum. |
BETA_CONNECTIVITY_BINDER |
β Framework | Binder connectivity state compared with the public API. | Use an external gateway. | The system_server hook must remain internally consistent. |
A partial Java hook appears as a mismatch. |
BETA_NETD_NETID |
β Kernel | netd, network ID, and extended rtnetlink context. | Use an external gateway. | Apply kernel and system filtering; VPNHide Next claims broader coverage. | Backend parity depends on the ROM and kernel. |
BETA_SOCKET_MARK |
β Socket | Socket mark, network ID, and identity. | Use an external gateway or one consistent path. | Apply kernel-level socket filtering or correct route policy. | A userspace hook may not observe raw socket metadata. |
BETA_SOCKET_DIAG |
β Socket | INET_DIAG cookie and socket identity. | Use an external gateway. | Filter in the kernel; do not weaken SELinux merely to hide the result. | Denial is neutral; access depends on the kernel. |
BETA_WIREGUARD_GENL |
β Kernel VPN | The WireGuard generic-netlink control plane. | Do not run kernel WireGuard on the phone; use an external gateway. | Filter or conceal it with a compatible kernel backend. | This privileged probe is opt-in; denial is neutral. |
BETA_OVPN_GENL |
β Kernel VPN | OpenVPN DCO or generic-netlink state. | Use an external gateway or avoid local DCO. | Filter in the kernel. | The privileged probe is opt-in. |
BETA_XFRM |
β IPsec | XFRM states and policies. | Use an external gateway or avoid local IPsec. | Filter in the kernel. | IPsec can be legitimate in an enterprise context. |
BETA_UNIX_DIAG |
β Localhost | Unix sockets and peer identity for the local control plane. | Disable or move the daemon off the device. | Filter by namespace or UID. | Hiding a TCP port does not close a Unix socket. |
BETA_BPF_NETFILTER |
β Policy | BPF, netd, cgroup, netfilter, and original-destination state. | Use an external gateway and minimize local redirection. | Apply kernel-level policy concealment; Next Max claims BPF coverage. | Portability across kernels is difficult; this is usually a review signal. |
BETA_NAMESPACE |
β Integrity | Mount and network namespace identity. | Do not use virtualization or profile wrappers. | Use a correct unmount namespace without breaking system namespaces. | The root manager itself can create namespace differences. |
BETA_SANDBOX_IDENTITY |
β Integrity | Process, filesystem, and fscrypt identity of virtualization. | Use the original APK in an ordinary owner-user sandbox. | Do not repackage or run through a virtual container. | Root does not turn a virtualized APK into an ordinary one. |
BETA_HOOK_CONSISTENCY |
β Integrity | Direct syscalls, io_uring, file descriptors, and linker consistency. | Do not inject or repackage the process. | Use a kernel backend and keep the target outside Zygisk and Xposed. | Alternate paths reveal a partial hook. |
BETA_TUN_FD |
β Kernel VPN | A kernel query on a TUN file descriptor. | Remove the local VpnService or use an external gateway. |
Filter in the kernel and verify the exact backend. | The second β hard-authority path when repeated results are stable. |
BETA_DNS_NETID |
β DNS | DNS network ID and native resolver path. | Make DNS and egress consistent. | Framework or kernel concealment does not replace correct DNS routing. | DoH and the native resolver can diverge. |
BETA_ROUTE_LOOKUP |
β Route | A single route lookup to selected targets. | Use an external gateway. | Use a kernel backend and account for the upstream single-lookup gap. | A clean route dump does not guarantee a clean single lookup. |
BETA_POLICY_RULE |
β Route | Policy rules by UID and network ID. | Use an external gateway. | Use a kernel backend with RTM_GETRULE coverage. |
ROM and netd can create complex legitimate rules. |
BETA_RTNL_ADDRESS |
β Interface | An RTNL address dump. | Use an external gateway. | Apply kernel netlink filtering. | Both IPv4 and IPv6 must be covered. |
BETA_LINK_DRIVER |
β Interface | Interface driver, kind, and details. | Use an external gateway. | Filter in the kernel; Next claims sysfs and driver coverage. | Renaming an interface does not change its driver or kind. |
BETA_INTERFACE_TRAFFIC |
β Path | Traffic counters showing the active egress. | Use an external gateway or one consistent route. | Next Max claims BPF and statistics concealment. | Counters and timing must remain consistent. |
BETA_PROXY_SELECTOR |
β Proxy | Java ProxySelector and the system proxy model. |
Disable the proxy or PAC. | Use a system hook only when necessary; removing the setting is preferable. | Application and native paths can disagree. |
BETA_TRANSPORT_MATRIX |
β Server | An HTTP, DNS, and UDP transport matrix against canary endpoints. | Make every protocol follow the intended path. | Root does not alter server observation; change the route. | The network and epoch must remain stable. |
BETA_TLS_INTERCEPTION |
β TLS | Certificate and handshake indicators of TLS interception. | Do not install a MITM CA or proxy for the target; use direct TLS. | Exclude the target from MITM and remove injected trust or hooks. | An enterprise CA can be legitimate; this is usually a review signal. |
BETA_PKTINFO |
β Socket | IP_PKTINFO, IPv6 packet info, and incoming-interface identity. |
Use an external gateway. | Apply kernel socket filtering. | The result must agree with the route and interface model. |
BETA_NETWORK_TRANSITION |
β Timeline | Netlink transitions and the temporal sequence of networks. | Do not run the test during a handover; use an external gateway. | System and kernel filtering must be atomic. | Policy suppresses races, but repetition remains important. |
BETA_TRACEROUTE |
β Path | Traceroute and path observation. | Use a real, consistent route. | A root firewall can only restrict the probe; the server-side path remains. | Usually system context, not hard VPN evidence. |
BETA_SERVER_FINGERPRINT |
β Server | Canary or server fingerprint of the active path. | Select the expected egress. | Root cannot correct a server fingerprint. | System-network context alone is excluded from the β hard quorum. |
NativeSignalId values — 85Each row links to an existing article in the native reference, where the signal interpretation is explained. This table adds the practical inverse path.
| ID | What is checked | Without root | With root | What may remain |
|---|---|---|---|---|
NATIVE_LIBRARY |
Loading and availability of the native check library. | Do not “fix” a denied or unavailable result; repeat the check on a control device. | Root is needed only for diagnostics; do not weaken SELinux. | Usually informational or availability-related; interpret it together with the other rows. |
INTERFACE_ENUMERATION |
Interface enumeration through native APIs. | Move the VPN off the phone to an external gateway; renaming one artifact is insufficient. | Prefer a kernel backend, add the framework layer for Binder, and use only one native backend. | Verify IPv4 and IPv6, raw syscalls, proc and sysfs, and socket paths. |
TUNTAP_TYPE |
The TUN or TAP interface type, such as ARPHRD_NONE or 65534, rather than only its name. | Move the VPN off the phone to an external gateway; renaming one artifact is insufficient. | Prefer a kernel backend, add the framework layer for Binder, and use only one native backend. | Verify IPv4 and IPv6, raw syscalls, proc and sysfs, and socket paths. |
IPSEC_INTERFACE |
IPsec, XFRM, or VTI interfaces and their related names and types. | Move the VPN off the phone to an external gateway; renaming one artifact is insufficient. | Prefer a kernel backend, add the framework layer for Binder, and use only one native backend. | Verify IPv4 and IPv6, raw syscalls, proc and sysfs, and socket paths. |
JVM_NATIVE_MISMATCH |
The Java and native views of the network do not agree. | Use an external gateway or avoid partial hooks. | Enable matching framework and kernel layers from the same release and keep the target outside injection scope. | Any uncovered channel recreates the mismatch. |
ROUTE_TABLE |
The native routing table and VPN routes. | Move the VPN off the phone to an external gateway; renaming one artifact is insufficient. | Prefer a kernel backend, add the framework layer for Binder, and use only one native backend. | Verify IPv4 and IPv6, raw syscalls, proc and sysfs, and socket paths. |
HOST_ROUTE |
A public /32 or /128 host route to the VPN server. |
Move the VPN off the phone to an external gateway; renaming one artifact is insufficient. | Prefer a kernel backend, add the framework layer for Binder, and use only one native backend. | Verify IPv4 and IPv6, raw syscalls, proc and sysfs, and socket paths. |
HOOK_MARKERS |
Known hook or injection libraries and markers inside the process. | Do not repackage the APK or inject rootless or Xposed hooks. | Use a kernel backend with system_server scope and remove the target from Zygisk or Xposed. |
Process-local Zygisk and third-party concealment modules may remain visible. |
RWX_MEMORY_REGIONS |
Memory regions that are both writable and executable. | Do not repackage the APK or inject rootless or Xposed hooks. | Use a kernel backend with system_server scope and remove the target from Zygisk or Xposed. |
Process-local Zygisk and third-party concealment modules may remain visible. |
LIBRARY_INTEGRITY |
Integrity of libc, the linker, symbols, and dlsym paths. |
Do not repackage the APK or inject rootless or Xposed hooks. | Use a kernel backend with system_server scope and remove the target from Zygisk or Xposed. |
Process-local Zygisk and third-party concealment modules may remain visible. |
ROOT_INDICATORS |
Aggregate root signal. | A stock non-root system is the only reliable non-root baseline. | Do not grant root to the target; use unmount or deny behavior, keep SELinux enforcing and the system read-only, and minimize the manager and module stack. | Individual kernel, property, or mount artifacts may remain; there is no guarantee. |
ROOT_SU_BINARY |
An accessible su binary at a common path. |
A stock non-root system is the only reliable non-root baseline. | Do not grant root to the target; use unmount or deny behavior, keep SELinux enforcing and the system read-only, and minimize the manager and module stack. | Individual kernel, property, or mount artifacts may remain; there is no guarantee. |
ROOT_PROPERTY |
Unsafe root or debug system properties. | A stock non-root system is the only reliable non-root baseline. | Do not grant root to the target; use unmount or deny behavior, keep SELinux enforcing and the system read-only, and minimize the manager and module stack. | Individual kernel, property, or mount artifacts may remain; there is no guarantee. |
ROOT_MANAGEMENT |
Magisk, KernelSU, APatch, and module directories or files. | A stock non-root system is the only reliable non-root baseline. | Do not grant root to the target; use unmount or deny behavior, keep SELinux enforcing and the system read-only, and minimize the manager and module stack. | Individual kernel, property, or mount artifacts may remain; there is no guarantee. |
ROOT_SYSTEM_RW |
Writable system partitions. | A stock non-root system is the only reliable non-root baseline. | Do not grant root to the target; use unmount or deny behavior, keep SELinux enforcing and the system read-only, and minimize the manager and module stack. | Individual kernel, property, or mount artifacts may remain; there is no guarantee. |
ROOT_SUSPICIOUS_MOUNT |
Unusual bind or magic mounts. | A stock non-root system is the only reliable non-root baseline. | Do not grant root to the target; use unmount or deny behavior, keep SELinux enforcing and the system read-only, and minimize the manager and module stack. | Individual kernel, property, or mount artifacts may remain; there is no guarantee. |
ROOT_OVERLAY_MOUNT |
OverlayFS or overlay mounts typical of module systems. | A stock non-root system is the only reliable non-root baseline. | Do not grant root to the target; use unmount or deny behavior, keep SELinux enforcing and the system read-only, and minimize the manager and module stack. | Individual kernel, property, or mount artifacts may remain; there is no guarantee. |
ROOT_SELINUX |
SELinux in permissive or disabled state, or an inconsistent state. | A stock non-root system is the only reliable non-root baseline. | Do not grant root to the target; use unmount or deny behavior, keep SELinux enforcing and the system read-only, and minimize the manager and module stack. | Individual kernel, property, or mount artifacts may remain; there is no guarantee. |
ROOT_UID |
The process or helper obtained UID or GID 0. | A stock non-root system is the only reliable non-root baseline. | Do not grant root to the target; use unmount or deny behavior, keep SELinux enforcing and the system read-only, and minimize the manager and module stack. | Individual kernel, property, or mount artifacts may remain; there is no guarantee. |
ROOT_MAGISK_PROPERTY |
Magisk service or configuration properties. | A stock non-root system is the only reliable non-root baseline. | Do not grant root to the target; use unmount or deny behavior, keep SELinux enforcing and the system read-only, and minimize the manager and module stack. | Individual kernel, property, or mount artifacts may remain; there is no guarantee. |
EMULATOR_INDICATORS |
Aggregate emulator signal. | Use a physical device. | Do not partially spoof an emulator; root-based spoofing creates inconsistencies. | Hardware, driver, and build indicators remain. |
EMULATOR_QEMU_PROPERTY |
QEMU or system properties. | Use a physical device. | Do not partially spoof an emulator; root-based spoofing creates inconsistencies. | Hardware, driver, and build indicators remain. |
EMULATOR_QEMU_PIPE |
QEMU pipes or devices. | Use a physical device. | Do not partially spoof an emulator; root-based spoofing creates inconsistencies. | Hardware, driver, and build indicators remain. |
EMULATOR_GOLDFISH |
Goldfish or Ranchu artifacts. | Use a physical device. | Do not partially spoof an emulator; root-based spoofing creates inconsistencies. | Hardware, driver, and build indicators remain. |
EMULATOR_QEMU_DRIVER |
QEMU drivers or kernel markers. | Use a physical device. | Do not partially spoof an emulator; root-based spoofing creates inconsistencies. | Hardware, driver, and build indicators remain. |
EMULATOR_BLUESTACKS |
BlueStacks files or properties. | Use a physical device. | Do not partially spoof an emulator; root-based spoofing creates inconsistencies. | Hardware, driver, and build indicators remain. |
EMULATOR_BUILD |
Emulator build fingerprint, model, or tags. | Use a physical device. | Do not partially spoof an emulator; root-based spoofing creates inconsistencies. | Hardware, driver, and build indicators remain. |
ISOLATION_PROFILE |
Aggregate profile or isolation state. | Run under the owner user; use a profile only as a deliberate test. | Add the full UID correctly to the concealment configuration and do not break UserManager. |
The user or profile fact remains true. |
ISOLATION_CLONE |
Clone or Dual Apps user ranges and OEM context. | Run under the owner user; use a profile only as a deliberate test. | Add the full UID correctly to the concealment configuration and do not break UserManager. |
The user or profile fact remains true. |
ISOLATION_SECONDARY_USER |
Execution with userId > 0. |
Run under the owner user; use a profile only as a deliberate test. | Add the full UID correctly to the concealment configuration and do not break UserManager. |
The user or profile fact remains true. |
ISOLATION_WORK_PROFILE |
A managed or work profile and profile owner. | Run under the owner user; use a profile only as a deliberate test. | Add the full UID correctly to the concealment configuration and do not break UserManager. |
The user or profile fact remains true. |
VPN_PROPERTY |
System properties resembling VPN state. | Move the VPN off the phone to an external gateway; renaming one artifact is insufficient. | Prefer a kernel backend, add the framework layer for Binder, and use only one native backend. | Verify IPv4 and IPv6, raw syscalls, proc and sysfs, and socket paths. |
DNS_PROPERTY |
DNS properties indicating an altered path. | Normalize the actual VPN, route, or socket parameter, or use an external gateway. | VPNHide Next Medium or Max claims some coverage; verify the exact signal. | These heuristics depend on the kernel and network; false positives are possible. |
VPN_FILE |
Files or paths associated with VPN artifacts. | Move the VPN off the phone to an external gateway; renaming one artifact is insufficient. | Prefer a kernel backend, add the framework layer for Binder, and use only one native backend. | Verify IPv4 and IPv6, raw syscalls, proc and sysfs, and socket paths. |
VPNHIDE |
VPNHide regression oracles and markers for clean or inconsistent states. | Move the VPN off the phone to an external gateway; renaming one artifact is insufficient. | Prefer a kernel backend, add the framework layer for Binder, and use only one native backend. | Verify IPv4 and IPv6, raw syscalls, proc and sysfs, and socket paths. |
LSPOSED |
LSPosed, Vector, or Xposed indicators. | Do not repackage the APK or inject rootless or Xposed hooks. | Use a kernel backend with system_server scope and remove the target from Zygisk or Xposed. |
Process-local Zygisk and third-party concealment modules may remain visible. |
HOOK_PROPERTY |
Properties associated with hooks or frameworks. | Do not repackage the APK or inject rootless or Xposed hooks. | Use a kernel backend with system_server scope and remove the target from Zygisk or Xposed. |
Process-local Zygisk and third-party concealment modules may remain visible. |
TCP_VPN_PORT |
A TCP listener or connection on a characteristic VPN or proxy port. | Disable the listener or control API, or move the daemon to a gateway. | Use a UID firewall, portshide, or a kernel loopback block. | The shell and target UIDs may see different rules; changing the port is insufficient. |
UDP_VPN_PORT |
A UDP listener or connection on a characteristic VPN or proxy port. | Disable the listener or control API, or move the daemon to a gateway. | Use a UID firewall, portshide, or a kernel loopback block. | The shell and target UIDs may see different rules; changing the port is insufficient. |
INET6_VPN_INTERFACE |
A VPN-like interface in /proc/net/if_inet6. |
Move the VPN off the phone to an external gateway; renaming one artifact is insufficient. | Prefer a kernel backend, add the framework layer for Binder, and use only one native backend. | Verify IPv4 and IPv6, raw syscalls, proc and sysfs, and socket paths. |
ROUTE_VPN_INTERFACE |
A VPN interface in /proc/net/route or route output. |
Move the VPN off the phone to an external gateway; renaming one artifact is insufficient. | Prefer a kernel backend, add the framework layer for Binder, and use only one native backend. | Verify IPv4 and IPv6, raw syscalls, proc and sysfs, and socket paths. |
ARP_VPN_INTERFACE |
A VPN-like interface or neighbor in ARP data. | Move the VPN off the phone to an external gateway; renaming one artifact is insufficient. | Prefer a kernel backend, add the framework layer for Binder, and use only one native backend. | Verify IPv4 and IPv6, raw syscalls, proc and sysfs, and socket paths. |
SYSCTL_FORWARDING |
An unusual IP forwarding state. | Normalize the actual VPN, route, or socket parameter, or use an external gateway. | VPNHide Next Medium or Max claims some coverage; verify the exact signal. | These heuristics depend on the kernel and network; false positives are possible. |
SYSCTL_RP_FILTER |
An unusual reverse-path filter state. | Normalize the actual VPN, route, or socket parameter, or use an external gateway. | VPNHide Next Medium or Max claims some coverage; verify the exact signal. | These heuristics depend on the kernel and network; false positives are possible. |
ESTABLISHED_VPN_SOCKET |
An established socket associated with a VPN address or port. | Disable the listener or control API, or move the daemon to a gateway. | Use a UID firewall, portshide, or a kernel loopback block. | The shell and target UIDs may see different rules; changing the port is insufficient. |
VPN_POLICY_RULES |
Policy rules characteristic of VPN or per-UID routing. | Move the VPN off the phone to an external gateway; renaming one artifact is insufficient. | Prefer a kernel backend, add the framework layer for Binder, and use only one native backend. | Verify IPv4 and IPv6, raw syscalls, proc and sysfs, and socket paths. |
VPN_QDISC |
A qdisc or queue discipline on the VPN path. | Use an external gateway; this generally cannot be filtered locally without root. | Use a kernel backend; for BPF, qdisc, or timing, treat Next Max as an experiment. | Backend parity and kernel ABI differ; repeated verification is required. |
HIDDEN_MAC_NEIGHBORS |
Inconsistent MAC or neighbor data. | Use an external gateway; this generally cannot be filtered locally without root. | Use a kernel backend; for BPF, qdisc, or timing, treat Next Max as an experiment. | Backend parity and kernel ABI differ; repeated verification is required. |
TCP_MSS_LOW |
A reduced TCP MSS as an indirect tunnel indicator. | Normalize the actual VPN, route, or socket parameter, or use an external gateway. | VPNHide Next Medium or Max claims some coverage; verify the exact signal. | These heuristics depend on the kernel and network; false positives are possible. |
SO_BINDTODEVICE |
SO_BINDTODEVICE behavior and interface availability. |
Use an external gateway; this generally cannot be filtered locally without root. | Use a kernel backend; for BPF, qdisc, or timing, treat Next Max as an experiment. | Backend parity and kernel ABI differ; repeated verification is required. |
LOOPBACK_PORT_CONFLICT |
A loopback-port conflict or occupancy difference between paths. | Disable the listener or control API, or move the daemon to a gateway. | Use a UID firewall, portshide, or a kernel loopback block. | The shell and target UIDs may see different rules; changing the port is insufficient. |
BPF_MAP_ACCESSIBLE |
Accessibility of BPF maps or netd statistics. | Use an external gateway; this generally cannot be filtered locally without root. | Use a kernel backend; for BPF, qdisc, or timing, treat Next Max as an experiment. | Backend parity and kernel ABI differ; repeated verification is required. |
IP_RECVERR |
Error-queue, IP_RECVERR, and PMTU behavior. |
Normalize the actual VPN, route, or socket parameter, or use an external gateway. | VPNHide Next Medium or Max claims some coverage; verify the exact signal. | These heuristics depend on the kernel and network; false positives are possible. |
SYSCALL_UNAVAILABLE |
A native syscall probe is unavailable or unsupported. | Do not “fix” a denied or unavailable result; repeat the check on a control device. | Root is needed only for diagnostics; do not weaken SELinux. | Usually informational or availability-related; interpret it together with the other rows. |
SYSFS_VPN_LEAK |
A VPN interface exposed through sysfs. | Move the VPN off the phone to an external gateway; renaming one artifact is insufficient. | Prefer a kernel backend, add the framework layer for Binder, and use only one native backend. | Verify IPv4 and IPv6, raw syscalls, proc and sysfs, and socket paths. |
GETIFADDRS_VPN |
A VPN interface or address returned by getifaddrs(). |
Move the VPN off the phone to an external gateway; renaming one artifact is insufficient. | Prefer a kernel backend, add the framework layer for Binder, and use only one native backend. | Verify IPv4 and IPv6, raw syscalls, proc and sysfs, and socket paths. |
SYSCLASSNET_VPN |
A VPN interface in /sys/class/net. |
Move the VPN off the phone to an external gateway; renaming one artifact is insufficient. | Prefer a kernel backend, add the framework layer for Binder, and use only one native backend. | Verify IPv4 and IPv6, raw syscalls, proc and sysfs, and socket paths. |
RTM_GETLINK_VPN |
A VPN interface in netlink RTM_GETLINK output. |
Move the VPN off the phone to an external gateway; renaming one artifact is insufficient. | Prefer a kernel backend, add the framework layer for Binder, and use only one native backend. | Verify IPv4 and IPv6, raw syscalls, proc and sysfs, and socket paths. |
PROC_IF_INET6_VPN |
A VPN IPv6 entry in /proc/net/if_inet6. |
Move the VPN off the phone to an external gateway; renaming one artifact is insufficient. | Prefer a kernel backend, add the framework layer for Binder, and use only one native backend. | Verify IPv4 and IPv6, raw syscalls, proc and sysfs, and socket paths. |
PROC_IPV6_ROUTE_VPN |
A VPN route in /proc/net/ipv6_route. |
Move the VPN off the phone to an external gateway; renaming one artifact is insufficient. | Prefer a kernel backend, add the framework layer for Binder, and use only one native backend. | Verify IPv4 and IPv6, raw syscalls, proc and sysfs, and socket paths. |
PROC_NET_DEV_VPN |
A VPN interface or counters in /proc/net/dev. |
Move the VPN off the phone to an external gateway; renaming one artifact is insufficient. | Prefer a kernel backend, add the framework layer for Binder, and use only one native backend. | Verify IPv4 and IPv6, raw syscalls, proc and sysfs, and socket paths. |
IFINDEXNAME_VPN |
Resolution from an interface index to a VPN name or synthetic if<N>. |
Move the VPN off the phone to an external gateway; renaming one artifact is insufficient. | Prefer a kernel backend, add the framework layer for Binder, and use only one native backend. | Verify IPv4 and IPv6, raw syscalls, proc and sysfs, and socket paths. |
VPN_POLICY_RULES_NETLINK |
VPN policy rules obtained through netlink RTM_GETRULE. |
Move the VPN off the phone to an external gateway; renaming one artifact is insufficient. | Prefer a kernel backend, add the framework layer for Binder, and use only one native backend. | Verify IPv4 and IPv6, raw syscalls, proc and sysfs, and socket paths. |
FIB_TRIE_DENIED |
Access to /proc/net/fib_trie is denied or behaves specially. |
Do not “fix” a denied or unavailable result; repeat the check on a control device. | Root is needed only for diagnostics; do not weaken SELinux. | Usually informational or availability-related; interpret it together with the other rows. |
INET_DIAG_DENIED |
INET_DIAG access is denied or behaves specially. | Do not “fix” a denied or unavailable result; repeat the check on a control device. | Root is needed only for diagnostics; do not weaken SELinux. | Usually informational or availability-related; interpret it together with the other rows. |
BINDTODEVICE_LEAK |
Binding to a physical or VPN interface exposes the path. | Use an external gateway; this generally cannot be filtered locally without root. | Use a kernel backend; for BPF, qdisc, or timing, treat Next Max as an experiment. | Backend parity and kernel ABI differ; repeated verification is required. |
GETSOCKNAME_LEAK |
getsockname() exposes the path address or interface. |
Use an external gateway; this generally cannot be filtered locally without root. | Use a kernel backend; for BPF, qdisc, or timing, treat Next Max as an experiment. | Backend parity and kernel ABI differ; repeated verification is required. |
UDP_PORT_CONFLICT_PHYSICAL |
A UDP bind or port conflict differs between the physical and VPN paths. | Use an external gateway; this generally cannot be filtered locally without root. | Use a kernel backend; for BPF, qdisc, or timing, treat Next Max as an experiment. | Backend parity and kernel ABI differ; repeated verification is required. |
DEEP_VPN_QDISC |
An extended qdisc probe. | Use an external gateway; this generally cannot be filtered locally without root. | Use a kernel backend; for BPF, qdisc, or timing, treat Next Max as an experiment. | Backend parity and kernel ABI differ; repeated verification is required. |
DEEP_BPF_MAP_ACCESSIBLE |
Extended BPF or netd statistics. | Use an external gateway; this generally cannot be filtered locally without root. | Use a kernel backend; for BPF, qdisc, or timing, treat Next Max as an experiment. | Backend parity and kernel ABI differ; repeated verification is required. |
ROUTE_COUNT |
The route count as an indirect oracle. | Use an external gateway; this generally cannot be filtered locally without root. | Use a kernel backend; for BPF, qdisc, or timing, treat Next Max as an experiment. | Backend parity and kernel ABI differ; repeated verification is required. |
TRIM_ORACLE |
The size or trimming of a netlink dump reveals a hidden entry. | Use an external gateway; this generally cannot be filtered locally without root. | Use a kernel backend; for BPF, qdisc, or timing, treat Next Max as an experiment. | Backend parity and kernel ABI differ; repeated verification is required. |
PMTU_MSS_COMBINED |
A combined PMTU and MSS fingerprint. | Normalize the actual VPN, route, or socket parameter, or use an external gateway. | VPNHide Next Medium or Max claims some coverage; verify the exact signal. | These heuristics depend on the kernel and network; false positives are possible. |
UDP_PMTU_OK |
A UDP PMTU probe succeeds at a characteristic size. | Normalize the actual VPN, route, or socket parameter, or use an external gateway. | VPNHide Next Medium or Max claims some coverage; verify the exact signal. | These heuristics depend on the kernel and network; false positives are possible. |
UDP_PMTU_FAIL |
A UDP PMTU probe fails in a characteristic way. | Normalize the actual VPN, route, or socket parameter, or use an external gateway. | VPNHide Next Medium or Max claims some coverage; verify the exact signal. | These heuristics depend on the kernel and network; false positives are possible. |
NORMAL_PMTU |
The normal or baseline PMTU control. | Normalize the actual VPN, route, or socket parameter, or use an external gateway. | VPNHide Next Medium or Max claims some coverage; verify the exact signal. | These heuristics depend on the kernel and network; false positives are possible. |
TIMING_ORACLE |
A timing difference between the physical and concealed paths. | Normalize the actual VPN, route, or socket parameter, or use an external gateway. | VPNHide Next Medium or Max claims some coverage; verify the exact signal. | These heuristics depend on the kernel and network; false positives are possible. |
BACKPRESSURE |
Socket backpressure or buffering as an indirect fingerprint. | Normalize the actual VPN, route, or socket parameter, or use an external gateway. | VPNHide Next Medium or Max claims some coverage; verify the exact signal. | These heuristics depend on the kernel and network; false positives are possible. |
GSO_FAILED |
A GSO option or probe is unsupported or rejected. | Normalize the actual VPN, route, or socket parameter, or use an external gateway. | VPNHide Next Medium or Max claims some coverage; verify the exact signal. | These heuristics depend on the kernel and network; false positives are possible. |
GSO_SEND_FAILED |
Sending a GSO datagram fails. | Normalize the actual VPN, route, or socket parameter, or use an external gateway. | VPNHide Next Medium or Max claims some coverage; verify the exact signal. | These heuristics depend on the kernel and network; false positives are possible. |
GSO_OK |
The GSO control succeeds. | Normalize the actual VPN, route, or socket parameter, or use an external gateway. | VPNHide Next Medium or Max claims some coverage; verify the exact signal. | These heuristics depend on the kernel and network; false positives are possible. |
HW_TIMESTAMP |
Hardware and software timestamping behavior. | Normalize the actual VPN, route, or socket parameter, or use an external gateway. | VPNHide Next Medium or Max claims some coverage; verify the exact signal. | These heuristics depend on the kernel and network; false positives are possible. |
TRACEROUTE_DENIED |
A traceroute or path probe is unavailable or blocked. | Do not “fix” a denied or unavailable result; repeat the check on a control device. | Root is needed only for diagnostics; do not weaken SELinux. | Usually informational or availability-related; interpret it together with the other rows. |
GENERAL_DIAGNOSTICS |
General native diagnostic output. | Do not “fix” a denied or unavailable result; repeat the check on a control device. | Root is needed only for diagnostics; do not weaken SELinux. | Usually informational or availability-related; interpret it together with the other rows. |
UNKNOWN |
An unknown or unmapped native kind. | Do not “fix” a denied or unavailable result; repeat the check on a control device. | Root is needed only for diagnostics; do not weaken SELinux. | Usually informational or availability-related; interpret it together with the other rows. |
| ID | Source | Domain / group | What is checked | Without root | With root | Residual state |
|---|---|---|---|---|---|---|
beta.vpn_binder |
BETA_VPN_BINDER |
VPN_OR_PROXY / android_vpn_service; hard-authority |
A Binder query to the Android VPN service or state. | Use an external gateway. | Apply framework filtering in system_server and keep the target outside Xposed scope. |
The Binder and native models must agree. |
beta.user_profile |
BETA_USER_PROFILE |
ISOLATED_PROFILE / android_user_manager |
The current user or profile through Android user APIs. | Run under the owner user. | Target the correct UID only; do not break UserManager. |
The truthful profile signal remains. |
beta.foreground_user |
BETA_USER_PROFILE |
ISOLATED_PROFILE / android_user_manager |
The foreground user and its consistency with the process context. | Run under the owner user. | Target the correct UID only; do not break UserManager. |
The truthful profile signal remains. |
beta.connectivity_binder |
BETA_CONNECTIVITY_BINDER |
NETWORK_PATH_DIVERGENCE / android_connectivity |
Connectivity Binder responses compared with the public model. | Use an external gateway. | Apply framework filtering in system_server and keep the target outside Xposed scope. |
The Binder and native models must agree. |
beta.netd_netid |
BETA_NETD_NETID |
NETWORK_PATH_DIVERGENCE / netd |
The netd or network ID of the active path. | Use an external gateway or remove the local VPN. | Apply kernel-level filtering to the exact channel; advanced VPNHide Next coverage is experimental. | Denial is often neutral, and kernel or ROM parity differs. |
beta.socket_identity |
BETA_SOCKET_MARK |
NETWORK_PATH_DIVERGENCE / kernel_socket |
Socket mark, network ID, and identity. | Use an external gateway or remove the local VPN. | Apply kernel-level filtering to the exact channel; advanced VPNHide Next coverage is experimental. | Denial is often neutral, and kernel or ROM parity differs. |
beta.inet_diag_cookie |
BETA_SOCKET_DIAG |
NETWORK_PATH_DIVERGENCE / socket_diag |
INET_DIAG cookie and socket identity. | Use an external gateway or remove the local VPN. | Apply kernel-level filtering to the exact channel; advanced VPNHide Next coverage is experimental. | Denial is often neutral, and kernel or ROM parity differs. |
beta.route_lookup |
BETA_ROUTE_LOOKUP |
NETWORK_PATH_DIVERGENCE / kernel_route |
A single route lookup to a control target. | Use an external gateway or remove the local VPN. | Apply kernel-level filtering to the exact channel; advanced VPNHide Next coverage is experimental. | Denial is often neutral, and kernel or ROM parity differs. |
beta.policy_rules |
BETA_POLICY_RULE |
NETWORK_PATH_DIVERGENCE / kernel_route |
Policy-routing rules for the UID or network ID. | Use an external gateway or remove the local VPN. | Apply kernel-level filtering to the exact channel; advanced VPNHide Next coverage is experimental. | Denial is often neutral, and kernel or ROM parity differs. |
beta.rtnl_address |
BETA_RTNL_ADDRESS |
NETWORK_PATH_DIVERGENCE / kernel_link |
An IPv4 and IPv6 RTNL address dump. | Use an external gateway or remove the local VPN. | Apply kernel-level filtering to the exact channel; advanced VPNHide Next coverage is experimental. | Denial is often neutral, and kernel or ROM parity differs. |
beta.extended_rtnetlink |
BETA_NETD_NETID |
NETWORK_PATH_DIVERGENCE / kernel_routing |
Extended rtnetlink and netd routing context. | Use an external gateway or remove the local VPN. | Apply kernel-level filtering to the exact channel; advanced VPNHide Next coverage is experimental. | Denial is often neutral, and kernel or ROM parity differs. |
beta.interface_driver |
BETA_LINK_DRIVER |
VPN_OR_PROXY / kernel_link |
Network-interface driver, kind, and details. | Use an external gateway or remove the local VPN. | Apply kernel-level filtering to the exact channel; advanced VPNHide Next coverage is experimental. | Denial is often neutral, and kernel or ROM parity differs. |
beta.interface_traffic |
BETA_INTERFACE_TRAFFIC |
NETWORK_PATH_DIVERGENCE / active_egress |
Interface counters and the actual egress. | Use an external gateway or remove the local VPN. | Apply kernel-level filtering to the exact channel; advanced VPNHide Next coverage is experimental. | Denial is often neutral, and kernel or ROM parity differs. |
beta.wireguard_genl |
BETA_WIREGUARD_GENL |
VPN_OR_PROXY / kernel_vpn |
WireGuard generic-netlink state. | Use an external gateway or remove the local VPN. | Apply kernel-level filtering to the exact channel; advanced VPNHide Next coverage is experimental. | Denial is often neutral, and kernel or ROM parity differs. |
beta.ovpn_genl |
BETA_OVPN_GENL |
VPN_OR_PROXY / kernel_vpn |
OpenVPN DCO or generic-netlink state. | Use an external gateway or remove the local VPN. | Apply kernel-level filtering to the exact channel; advanced VPNHide Next coverage is experimental. | Denial is often neutral, and kernel or ROM parity differs. |
beta.xfrm |
BETA_XFRM |
VPN_OR_PROXY / kernel_ipsec |
XFRM or IPsec states and policies. | Use an external gateway or remove the local VPN. | Apply kernel-level filtering to the exact channel; advanced VPNHide Next coverage is experimental. | Denial is often neutral, and kernel or ROM parity differs. |
beta.unix_diag |
BETA_UNIX_DIAG |
VPN_OR_PROXY / local_control_plane |
Unix-domain sockets in the local control plane. | Disable the proxy or control daemon. | Block by UID or namespace. | The listener or Unix socket may remain visible. |
beta.unix_peer_identity |
BETA_UNIX_DIAG |
VPN_OR_PROXY / local_control_plane |
Peer credentials and identity on a Unix socket. | Disable the proxy or control daemon. | Block by UID or namespace. | The listener or Unix socket may remain visible. |
beta.tun_fd |
BETA_TUN_FD |
VPN_OR_PROXY / process_fd; hard-authority |
A kernel query on a TUN file descriptor. | Remove the local VpnService through an external gateway. |
Filter in the kernel; a userspace hook is insufficient. | This is hard evidence only after at least two stable, matching samples. |
beta.bpf_netd |
BETA_BPF_NETFILTER |
NETWORK_PATH_DIVERGENCE / packet_policy |
BPF or netd maps and traffic policy. | Use an external gateway or remove the local VPN. | Apply kernel-level filtering to the exact channel; advanced VPNHide Next coverage is experimental. | Denial is often neutral, and kernel or ROM parity differs. |
beta.cgroup_bpf |
BETA_BPF_NETFILTER |
NETWORK_PATH_DIVERGENCE / packet_policy |
Cgroup BPF attachment and policy. | Use an external gateway or remove the local VPN. | Apply kernel-level filtering to the exact channel; advanced VPNHide Next coverage is experimental. | Denial is often neutral, and kernel or ROM parity differs. |
beta.netfilter_path |
BETA_BPF_NETFILTER |
NETWORK_PATH_DIVERGENCE / packet_policy |
Netfilter path or redirection state. | Use an external gateway or remove the local VPN. | Apply kernel-level filtering to the exact channel; advanced VPNHide Next coverage is experimental. | Denial is often neutral, and kernel or ROM parity differs. |
beta.original_destination |
BETA_BPF_NETFILTER |
NETWORK_PATH_DIVERGENCE / packet_policy |
The original destination after transparent redirection. | Use an external gateway or remove the local VPN. | Apply kernel-level filtering to the exact channel; advanced VPNHide Next coverage is experimental. | Denial is often neutral, and kernel or ROM parity differs. |
beta.direct_syscall_consistency |
BETA_HOOK_CONSISTENCY |
HOOK_OR_TAMPERING / hook_consistency |
Comparison of a libc API with a direct syscall. | Avoid process injection. | Use a kernel backend and keep the target outside Zygisk and Xposed. | An alternate path exposes a partial hook. |
beta.io_uring_consistency |
BETA_HOOK_CONSISTENCY |
HOOK_OR_TAMPERING / alternate_syscall_path |
An alternate io_uring path compared with a hooked API. | Avoid process injection. | Use a kernel backend and keep the target outside Zygisk and Xposed. | An alternate path exposes a partial hook. |
beta.fd_identity |
BETA_HOOK_CONSISTENCY |
HOOK_OR_TAMPERING / process_fd |
The type and identity of process file descriptors. | Avoid process injection. | Use a kernel backend and keep the target outside Zygisk and Xposed. | An alternate path exposes a partial hook. |
beta.sandbox_identity.process |
BETA_SANDBOX_IDENTITY |
APP_VIRTUALIZATION / process_identity |
Process identity inside a virtual container. | Use the original APK in an ordinary sandbox. | Do not use a virtual container or repackaged APK. | Root does not turn a container into an ordinary profile. |
beta.sandbox_identity.filesystem |
BETA_SANDBOX_IDENTITY |
APP_VIRTUALIZATION / filesystem_identity |
Sandbox filesystem layout and identity. | Use the original APK in an ordinary sandbox. | Do not use a virtual container or repackaged APK. | Root does not turn a container into an ordinary profile. |
beta.sandbox_identity.namespace |
BETA_NAMESPACE |
APP_VIRTUALIZATION / namespace_identity |
Sandbox or virtualization namespace identity. | Use the original APK in an ordinary sandbox. | Do not use a virtual container or repackaged APK. | Root does not turn a container into an ordinary profile. |
beta.fscrypt_identity |
BETA_SANDBOX_IDENTITY |
APP_VIRTUALIZATION / filesystem_identity |
fscrypt and user-storage identity. | Use the original APK in an ordinary sandbox. | Do not use a virtual container or repackaged APK. | Root does not turn a container into an ordinary profile. |
beta.linker_integrity |
BETA_HOOK_CONSISTENCY |
HOOK_OR_TAMPERING / loader_integrity |
Linker and loader integrity and hooks. | Avoid process injection. | Use a kernel backend and keep the target outside Zygisk and Xposed. | An alternate path exposes a partial hook. |
beta.dns_netid |
BETA_DNS_NETID |
NETWORK_PATH_DIVERGENCE / dns_path |
DNS resolver network ID and path. | Make the actual route, DNS, and TLS path consistent, or use an external gateway. | Root cannot alter the server-side path; exclude the target from MITM. | Network-epoch changes and noise matter; server context alone is not always hard evidence. |
beta.native_dns_resolver |
BETA_DNS_NETID |
NETWORK_PATH_DIVERGENCE / dns_path |
The native resolver compared with framework DNS. | Make the actual route, DNS, and TLS path consistent, or use an external gateway. | Root cannot alter the server-side path; exclude the target from MITM. | Network-epoch changes and noise matter; server context alone is not always hard evidence. |
beta.proxy_selector |
BETA_PROXY_SELECTOR |
VPN_OR_PROXY / android_proxy |
Java ProxySelector and system-proxy consistency. |
Disable the proxy or control daemon. | Block by UID or namespace. | The listener or Unix socket may remain visible. |
beta.transport_matrix |
BETA_TRANSPORT_MATRIX |
NETWORK_PATH_DIVERGENCE / active_egress |
An HTTP, DNS, and UDP matrix against canary endpoints. | Make the actual route, DNS, and TLS path consistent, or use an external gateway. | Root cannot alter the server-side path; exclude the target from MITM. | Network-epoch changes and noise matter; server context alone is not always hard evidence. |
beta.tls_interception |
BETA_TLS_INTERCEPTION |
VPN_OR_PROXY / tls_path |
TLS interception and certificate path. | Make the actual route, DNS, and TLS path consistent, or use an external gateway. | Root cannot alter the server-side path; exclude the target from MITM. | Network-epoch changes and noise matter; server context alone is not always hard evidence. |
beta.pktinfo |
BETA_PKTINFO |
NETWORK_PATH_DIVERGENCE / kernel_socket |
IP_PKTINFO or IPv6 packet info for the incoming or outgoing path. |
Use an external gateway or remove the local VPN. | Apply kernel-level filtering to the exact channel; advanced VPNHide Next coverage is experimental. | Denial is often neutral, and kernel or ROM parity differs. |
beta.netlink_transitions |
BETA_NETWORK_TRANSITION |
NETWORK_PATH_DIVERGENCE / network_timeline |
The temporal sequence of netlink network events. | Use an external gateway or remove the local VPN. | Apply kernel-level filtering to the exact channel; advanced VPNHide Next coverage is experimental. | Denial is often neutral, and kernel or ROM parity differs. |
beta.traceroute |
BETA_TRACEROUTE |
SYSTEM_NETWORK_CONTEXT / path_observation |
Traceroute and path observation. | Make the actual route, DNS, and TLS path consistent, or use an external gateway. | Root cannot alter the server-side path; exclude the target from MITM. | Network-epoch changes and noise matter; server context alone is not always hard evidence. |
beta.server_fingerprint |
BETA_SERVER_FINGERPRINT |
SYSTEM_NETWORK_CONTEXT / server_observation |
A remote fingerprint of the observed path. | Make the actual route, DNS, and TLS path consistent, or use an external gateway. | Root cannot alter the server-side path; exclude the target from MITM. | Network-epoch changes and noise matter; server context alone is not always hard evidence. |
beta.root_emulator |
NATIVE_ROOT_DETECTION |
DEVICE_INTEGRITY / device_integrity |
Aggregate β assessment of root, emulator, and device integrity. | Use a physical stock device without root. | Minimize the root surface and do not partially spoof an emulator. | A review state or quorum remains possible. |
GEO_IP, IP consensus, DNS, CDN, STUN and call transport, and underlying-network binding.LinkProperties, and Binder β checks.This order reduces false conclusions. Installing a root-concealment module is pointless while the application still sees an open Clash API and a foreign egress; tuning MTU is pointless while TRANSPORT_VPN remains direct evidence.
The matrix is considered complete only when _validate.py confirms an exact match between the rows in all three sections and the source code, with populated root and non-root columns. When a new EvidenceSource, NativeSignalId, or BetaCheckRegistry.definition() is added, the local validation must fail until a separate row is added here.