After a few years, bought the 2025 iPad Pro to see if MTE/eMTE would help, and it did.
After a few years, bought the 2025 iPad Pro to see if MTE/eMTE would help, and it did.
Not understanding every bit of traffic from your device with hundreds of services and dozens of apps running is not evidence of a breach.
Have you found unsigned/unauthorized software? Have you traced traffic to a known malware collection endpoint? Have you recovered artifacts from malware?
Strong claims require strong evidence imo and this isn’t it.
Apple traffic was isolated separately, https://news.ycombinator.com/item?id=46994394
Traffic outside that baseline could then be reviewed closely.
I agree with other posters that you seem to be capable of network level forensics, but you have said nothing to back up what you consider a device breach other than 'some cloud destined network traffic which disapears after a hard reset'.
In my experience of forensic reports, this link is tenuous at best and would not be considered evidence or even suspected breach based on that alone.