Some info only goes cellular, the only way to capture that is using a hotspot which simulates the normal network.
The real sneaky spyware I found only goes over cellular and hides itself by using double encrypted SSL traffic to AWS endpoints.
Some info only goes cellular, the only way to capture that is using a hotspot which simulates the normal network.
The real sneaky spyware I found only goes over cellular and hides itself by using double encrypted SSL traffic to AWS endpoints.
Of course, you can also just check if the phone sends something by looking at the RF energy or even build an uplink decoder, but I doubt that this is very useful information by itself for this use case.
Finally, what I propose instead, is to use a private LTE network, which you can create using a SDR and srsLTE and some programmable SIM cards, which you need to insert into the phone. This way, it‘s easily possible to view any traffic leaving the phone on any connection. Plus, srsLTE has been shown to work on Raspberry Pi as well (I think).
However, there is also WiFi Calling - in that sense, your phone establishes some connection with the cell network. However, I don‘t think any user data may travel on this bearer, but there might be some edge case where this is possible.
Not sure if serious ...
Wouldn't it be pretty easy to fingerprint a TLS session that always starts with another TLS handshake?
I believe they also certificate pin the tunneled protocol.