Google Tuesday introduced a new optional Android called Intrusion Logging, which stores forensic logs to better analyze sophisticated spyware. The innovative feature is part of Advanced Protection Mode and was developed in partnership with Amnesty International and Reporters Without Borders. The rollout of the feature comes in response to the growing sophisticated threat of Pegasus spyware and other commercial surveillance tools targeting journalists and activists worldwide.
See also: GhostChat Spyware Targets Android Users

Intrusion Logging enables “persistent and privacy-friendly forensic logging to enable investigation of devices in the event of a suspected breach,” as Google. The feature records daily device and network activities, including information about the behavior of the device and the various applications running on it. This approach represents a significant evolution in mobile security, as it provides high-risk users with tools that were previously only available in corporate environments with specialized monitoring systems.
The types of activities recorded include application activity such as process launches, application installations and uninstallations with timestamps, network connections such as starting and stopping Wi-Fi , Bluetooth , DNS lookups and IP addresses , file transfers via USB with detailed metadata, changes to system certificates that may indicate a man-in-the-middle attack , and moments when the device is locked or unlocked. This extensive logging allows security experts to analyze patterns that may indicate the presence of sophisticated malware or zero-day exploits .
Intrusion Logging Encryption and Security
Google emphasized that the log data is encrypted end-to-end from the device and stored on Google servers using advanced AES-256 encryption algorithms. The encryption keys are protected by the Google Account password and screen lock credentials, meaning the files cannot be accessed by any third party, including Google itself, except the device owner. This security architecture ensures that even if Google ’s servers are compromised , the data remains inaccessible without the appropriate decryption keys.
See also: iOS 26.5: E2EE encryption in RCS iPhone-Android messages

As Reporters Without Borders, “by storing the data on a secure server, even malware installed on the smartphone cannot access, delete or manipulate it.” End-to-end encryption also ensures that neither Google nor state actors can access the data. This is particularly important for journalists and activists working in authoritarian regimes, where government authorities may request access to data from tech companies.
Encrypted files are stored for a period of 12 months, after which they are automatically deleted to ensure long-term privacy. Once Intrusion Logging, the user cannot delete the files before the 12-month, even if the account is closed or the feature is disabled. This restriction ensures that forensic evidence remains available for analysis even if an attacker gains access to the device and attempts to cover their tracks. Users have the option to download the files offline via the Settingsif they prefer to keep them for longer periods or share them with security experts.
Technical Details and Limitations
An important note is that the feature also records network events generated while browsing Chrome Incognito , such as DNS lookups and IP connections , as it operates at the system level and does not distinguish between browsing modes. In other words, anyone with access to the decrypted files can infer which websites were visited, but cannot infer specific pages on those websites. This limitation reflects the balance between forensic utility and privacy protection that Google tried to achieve with this feature.
See also: TrickMo banking malware for Android adopts TON blockchain

To get the most out of Intrusion Logging, security experts recommend that high-risk users also enable other Advanced Protection Mode, such as using hardware security keys for two-factor authentication and restricting app installation to only the Google Play Store. Additionally, it is recommended to regularly update the operating system and use apps from trusteddevelopers. Organizations supporting journalists or activists should develop protocols for analyzing logs and collaborating with cybersecurity experts when suspicious activity is detected.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
