CLI tool
mvt-project/mvt avatar
mvt-project/mvt

MVT (Mobile Verification Toolkit): forensic triage for iOS and Android spyware checks

MVT (Mobile Verification Toolkit) helps with conducting forensics of mobile devices in order to find signs of a potential compromise.

14,914 stars1,406 forksPythonNOASSERTION

At a glance

What is it?
MVT is Amnesty International's command-line toolkit for scanning iOS backups and Android acquisitions for spyware traces. It is built for investigators and technologists, not for end-user self-assessment, and it only finds what its indicators cover.
Who is it for?
MVT is for forensic examiners, security researchers and civil society technologists who already understand acquisition and indicator-based detection, and who can work from a terminal. It is not for a worried phone owner looking for a clean bill of health: the README states it is not intended for end-user self-assessment and that public indicators cannot prove a device is clean.
Can I use it commercially?
Check first. The repository uses a licence we do not classify automatically, so read its LICENSE file before any commercial use.
Is it still maintained?
Yes. The repository last received commits 3 days ago.
What is it written in?
Mainly Python, according to GitHub's language statistics.

Answers come from the project's GitHub data, last synced on September 27, 2026, and from our analysis. They are not legal advice.

Editorial analysis

What MVT actually solves, and for whom

MVT gathers and parses forensic traces from Android and iOS devices so an analyst can look for signs of a compromise. The README describes it as "a collection of utilities to simplify and automate the process of gathering forensic traces helpful to identify a potential compromise of Android and iOS devices." It was released by the Amnesty International Security Lab in July 2021 alongside a forensic methodology, in the context of the Pegasus Project, and continues to be maintained by Amnesty and other contributors.

The audience is narrow by design. The README states MVT "is a forensic research tool intended for technologists and investigators," requires understanding of digital forensics and command-line tools, and is "not intended for end-user self-assessment." That sentence is the most important line in the project. A person who suspects their own phone is infected is not the target user; MVT assumes someone who knows what an acquisition is, what an indicator of compromise represents, and how to interpret a hit without over-reading it.

The problem it addresses is triage at scale. Rather than manually walking a filesystem image, an examiner points MVT at an acquisition and at a set of indicators, and gets structured output to review. That is a different job from malware analysis and a different job from device hardening.

Three commands, two platforms, one indicator pipeline

The CLI is split deliberately. `mvt-ios` and `mvt-android` analyse acquisitions from devices of that platform. A third command, `mvt`, hosts what belongs to neither: `version`, `completion`, `plugins` and `download-iocs`. The README notes that `version` and `download-iocs` remain available on the platform commands for now, which suggests the split is still settling.

Running `mvt` with no arguments shows the installed version, update notices and the available commands. Verbosity is handled at the top level: pass `--verbose` before the command name, as in `mvt-ios --verbose check-backup ...`. The `--verbose` option that `check-*` commands accept after their name still works but is kept for compatibility only and will be removed in a future release. If you are writing new automation, use the pre-command form.

The detection layer is indicator-based. MVT supports public indicators of compromise from the mvt-indicators repository, including IOCs published by Amnesty International and other research groups, and scans devices for traces of targeting or infection by known spyware campaigns. The data flow is therefore: acquire a backup or bugreport, download an indicator set, run the relevant `check-*` module, then review the matches. The README is explicit that this pipeline is incomplete on its own. Public indicators "are insufficient to determine that a device is 'clean'," and reliance on them alone "can miss recent forensic traces and give a false sense of security." Non-public indicators, research and threat intelligence are what the project says reliable triage requires.

Extensibility runs through plugins. Plugin packages add forensic modules that execute inside the `check-*` commands, and can also register top-level commands on `mvt`, `mvt-ios` and `mvt-android`. The README points to the development documentation for writing and installing them and to the custom CLI command documentation for the entry points a package registers commands in.

Installing MVT and running a first check

The README gives two install paths. The simplest is PyPI with pip, which requires Python 3.10 or newer according to pyproject.toml:

bash
pip3 install mvt

The README warns that you will need some dependencies and points to the installation documentation for them. If you prefer isolated tool installs, MVT can also be installed with uv. Install uv first:

bash
curl -LsSf https://astral.sh/uv/install.sh | sh

Then install MVT as a command-line tool:

bash
uv tool install mvt

After installation, running `mvt` on its own prints the installed version, any update notices and the available commands. That is the quickest way to confirm the entry points resolved. Shell completion is generated separately:

bash
mvt completion bash

The command prints setup instructions by default. MVT only writes completion files or shell configuration when `--install` is passed. Bash, Zsh and Fish are supported, and the generated script covers `mvt`, `mvt-ios` and `mvt-android`.

For a first real use you need an acquisition and an indicator set. The indicator download lives under the `mvt` command as `download-iocs`, and the platform checks are invoked as `mvt-ios check-backup ...` or the Android equivalent. The README does not spell out the full flag set for either check command; it directs readers to the documentation at docs.mvt.re. Treat that as the real entry point rather than guessing flags. If you are working on iOS with an encrypted backup, note that `iphone_backup_decrypt` is a declared dependency, so decryption is handled inside the toolchain rather than by an external step.

What MVT cannot tell you

The clearest limitation is stated by the project itself: a scan that returns nothing is not evidence of a clean device. Public IOCs lag behind campaigns, and the README says reliance on them alone can miss recent forensic traces. Any report that frames an MVT run as a verdict is misusing the tool.

The second limitation is operational. MVT does not acquire devices for you in the sense of solving custody and consent problems. The licence section frames the project's purpose as facilitating "consensual forensic analysis" of devices belonging to people who might be targets of sophisticated mobile spyware, and the maintainers state they do not want MVT to enable privacy violations of non-consenting individuals. That is a design constraint, not a footnote.

The third is the v3 change. The README carries an important notice that the v3 branch was merged and introduced breaking changes, with the specific warning that if you relied on MVT output in other scripts, those might have broken. If your pipeline parses MVT JSON, the version bump is a migration task, not a routine upgrade. The README links issue 757 for details and does not document a rollback path for the output format.

Finally, MVT is the wrong tool when the question is not forensic. If you want to harden a device, choose safer communication channels, or assess risk before an incident, MVT has nothing to offer. It reads traces after the fact.

How MVT differs from a general mobile forensics suite

Commercial mobile forensics platforms such as Cellebrite and Magnet AXIOM acquire and parse devices broadly: messages, call logs, app data, deleted records, across a long list of handset models, with a GUI and vendor support. MVT does not compete on breadth. It parses a narrower set of artifacts and its purpose is spyware detection against indicators, not general evidence recovery. The practical difference shows up in workflow: a commercial suite produces a case file for review in its own interface, while MVT produces output you script around and correlate with an IOC set you maintain yourself.

The closer comparison is to writing your own parsers. An analyst could pull an iOS backup apart with libimobiledevice tooling and grep for known domains. MVT packages that work as maintained `check-*` modules, adds an indicator download path, and gives you a plugin interface so a team can add modules without forking. The trade-off is that you inherit the project's indicator model and its output format, and the v3 notice shows what that costs when the format changes.

If your need is strictly network-level detection of command-and-control domains, a DNS or network monitoring setup covers ground MVT does not. If your need is on-device artifact triage with an indicator corpus, MVT is aimed squarely at that.

Maintenance cadence, licence and upgrade cost

The repository is not archived and the last push was on 2026-09-21. Releases are frequent and date-stamped: v2026.9.21, v2026.9.14 and v2026.9.7 all landed within the same month, which fits a project that ships a version each week. That cadence is good for indicator freshness and bad for anyone pinning versions loosely, because a weekly release means weekly opportunities for behavior changes.

Upgrade cost is dominated by two things. First, the v3 output change already noted: scripts that consume MVT output need review against issue 757. Second, the dependency set is pinned tightly in pyproject.toml, including exact versions for click, rich, requests, cryptography, pydantic and others, plus native-adjacent packages such as adb-shell with USB support and libusb1. Tight pins make reproducible installs easier but can create conflicts if you install MVT into an environment shared with other tools. The uv tool install path avoids that by isolating the CLI.

On licensing, the README states MVT is released under its own license rather than a standard OSI identifier, and links to the licence documentation. The project's stated intent is to restrict use to consensual forensic analysis. That is a usage restriction with real implications for how you can deploy or redistribute it, particularly in a commercial context. Read the licence text and, if the terms matter to your organization, get proper legal review; this article is not legal advice.

Editorial conclusion

MVT is for forensic examiners, security researchers and civil society technologists who already understand acquisition and indicator-based detection, and who can work from a terminal. It is not for a worried phone owner looking for a clean bill of health: the README states it is not intended for end-user self-assessment and that public indicators cannot prove a device is clean. Before relying on it, verify two things in the documentation: that your platform's acquisition path (encrypted iOS backup or Android bugreport) is supported by the check commands you plan to run, and that the mvt-indicators set you download actually covers the campaign you care about. The v3 merge also changed output, so any script parsing MVT JSON needs re-checking against issue 757.

Frequently asked questions

Is MVT safe to use?

The project frames MVT as a tool for consensual forensic analysis, and its licence is written to prevent privacy violations of non-consenting individuals. The README also states it is intended for technologists and investigators rather than end-user self-assessment.

What is the Amnesty International Mobile Verification Toolkit (MVT)?

MVT is a collection of utilities that gather forensic traces from Android and iOS devices to help identify a potential compromise. It was developed and released by the Amnesty International Security Lab in July 2021 as part of the Pegasus Project.

What is the iOS Mobile Verification Toolkit (MVT)?

MVT ships a dedicated `mvt-ios` command that analyses iOS acquisitions, and the repository includes a Dockerfile.ios for that platform. The README directs readers to the documentation for the exact check commands to run.

What is the Mobile Verification Toolkit?

It is a Python command-line toolkit, installed as the `mvt` package, that automates the collection of forensic traces from mobile devices and scans them against indicators of compromise. It exposes three commands: `mvt`, `mvt-ios` and `mvt-android`.

Official sources

  1. Issues
  2. mvt-project/mvt on GitHub
  3. Project website
  4. README
  5. Releases
Add this badge to your README

If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.

Add this badge to your README

markdown
[![Hysen Labs](https://hysenlabs.com/badge/mvt-project-mvt.svg)](https://hysenlabs.com/projects/mvt-project-mvt)