Threat catalog

Every threat Burein names — across eight families. Each carries an ID, a severity, a confidence, and an evidence list.

Eight families

The full threat taxonomy.

Runtime tampering

IDDescriptionSev
FRIDA_HOOK_DETECTEDFrida runtime instrumentation present.Critical
XPOSED_DETECTEDXposed / LSPosed / EdXposed framework.Critical
CODE_INJECTIONLD_PRELOAD / DYLD_INSERT_LIBRARIES injected library.Critical
DEBUGGER_ATTACHEDptrace or native debugger attached.Critical
NATIVE_LIB_TAMPERText segment or GOT/PLT integrity violation.Critical

Environment integrity

IDDescriptionSev
MAGISK_ROOTMagisk-rooted Android device.High
BOOTLOADER_UNLOCKEDUnlocked bootloader.High
EMULATOR_QEMURunning on a QEMU-class emulator.High
VIRTUAL_APP_HOSTEDRunning inside VirtualXposed / Parallel Space.High
JAILBROKEN_IOSiOS jailbreak detected.High
ROOTLESS_JB_IOSDopamine / palera1n / RootHide class.High
TROLLSTORE_INSTALLTrollStore-sideloaded.Medium

App integrity

IDDescriptionSev
APP_REPACKAGEDSigning certificate mismatch.Critical
PLAY_INTEGRITY_FAILPlay Integrity verdict failed.High
APP_ATTEST_FAILApp Attest verdict failed.High
INSTALL_SOURCE_SIDELOADInstalled from a non-store source.Medium

Network integrity

IDDescriptionSev
TLS_MITMCustom root CA in the chain or cert pinning bypass.High
VPN_ACTIVEVPN tunnel interface present.Medium
RESIDENTIAL_PROXY_HINTASN + latency tells consistent with residential proxy (local inference).Medium
ARP_ANOMALYRogue gateway / ARP table mismatch.Medium

Identity automation

IDDescriptionSev
HEADLESS_CHROMEHeadless Chrome inconsistency triad.High
WEBDRIVER_PRESENTnavigator.webdriver or hidden variant.High
PLAYWRIGHT_DETECTEDPlaywright hooks or environment.High
PUPPETEER_DETECTEDPuppeteer / puppeteer-extra-stealth bypass detection.High
ANTI_DETECT_BROWSERMultilogin / Kameleo / AdsPower / Dolphin / GoLogin.High
FARM_BROWSER_PROFILECookie-jar / storage rotation pattern.High

Agentic actors

IDDescriptionSev
AGENTIC_COMPUTER_USEAnthropic Computer Use cadence pattern.Critical
AGENTIC_OPERATOROpenAI Operator pattern.Critical
AGENTIC_BROWSER_USEbrowser-use library signatures.Critical
AGENTIC_SKYVERNSkyvern automation harness.High
AGENTIC_BROWSERBASEBrowserBase remote browser session.High
AI_SYNTHETIC_TYPINGToken-boundary cadence, no error-correction.High
AI_SYNTHETIC_MOUSEKinematically implausible trajectories.High

Social-engineering vectors

IDDescriptionSev
SCREEN_SHARE_ACTIVERemote-access app active + screen capture.Critical
ACCESSIBILITY_ABUSEKnown-malicious accessibility service active.Critical
OVERLAY_ATTACK_RISKSYSTEM_ALERT_WINDOW overlay during sensitive flow.High
BANKING_TROJAN_IOCKnown banking-trojan package fingerprint present.Critical

Inconsistency

IDDescriptionSev
UA_SPOOF_INCONSISTENTUA disagrees with platform tells.Medium
TZ_GEO_MISMATCHTimezone disagrees with IP geo.Medium
SENSOR_TAMPERINGSensor values implausible or replayed.High
MOCK_LOCATIONMock location provider.Medium

Want to go deeper?

Talk to us about your fraud and integrity goals — we'll show you the signals that matter for your stack.