📲 Device / Advertising ID
A mobile advertising or device identifier used in adtech data to track and locate devices.
Identity
Sources
1
1 no-auth
Disciplines
1
that use it
Mission domains
1
reach
Workbench
—
native tool
🔗 Analyst pivots
🔌 Sources that yield Device / Advertising ID (1)
| Source | Category | Auth | Format | |
|---|---|---|---|---|
| Mobile Advertising-ID / MADINT refs Mobile device & advertising-ID intelligence. | IDENT | NONE | html | home↗ |
🧭 Disciplines
🎯 Mission Domains
🔍 Lookup
📜 Playbook — Device / Advertising ID exploitation
- Direction — frame the requirement for Device / Advertising ID: what decision does this support, by when?
- Collection — pull the 1 mapped sources (1 free) and the native workbench; capture provenance and observe OPSEC.
- Processing — normalize, de-duplicate and enrich the collected data.
- Analysis — correlate against local holdings; apply ACH; assign confidence.
- Dissemination — open a case, draft a report, share via STIX/MISP.
- Feedback — set an alert rule / watchlist to monitor for change.
⚡ AI Skills & Automation
Automate unattended via the cron pipeline (collect → ingest → resolve → enrich → score → alert).
🧩 Advanced Capabilities
✨ Enrichment pathways
🎫 Device / Advertising ID
A device or advertising ID is a resettable or hardware-bound identifier (GAID, IDFA, Android ID, IMEI) that tracks a physical device across apps and ad networks. It is a powerful de-anonymization and co-location selector because ad-tech and MAID datasets tie devices to locations, behaviors, and often back to real identities.
Format: GAID/IDFA: UUID (8-4-4-4-12 hex). Android ID: 16 hex chars. IMEI: 15 digits with Luhn checksum. IMSI: 15 digits (MCC+MNC+MSIN). MAC: 12 hex (colon-separated).
📡 How it is collected
- Mobile ad-exchange bid-stream / MAID datasets
- App SDK telemetry and analytics logs
- Device forensic acquisition
- MDM / EMM enrollment records
- Wi-Fi/Bluetooth probe capture
- Data-broker location datasets
📚 Enrichment & validation sources
🔗 Pivot to
🧩 Analysis & hunting techniques
- MAID-to-location pattern-of-life analysis
- Device co-location and rendezvous detection
- TAC/OUI decoding for make and model
- IMEI Luhn validation and blacklist check
- App-fingerprint correlation via SDK trackers
- Cross-app identifier stitching
- Home/work location inference from dwell
- Probe-request device tracking
🔧 Tools
- MobSF
- Frida
- Wireshark
- Exodus Privacy
- Kismet
- adb (Android)
- Cellebrite (reference)
- AppCensus
⚡ Workbench actions
- Decode TAC/OUI to make and model
- Validate IMEI checksum
- Trace MAID location pattern-of-life
- Detect co-located devices
- Map app/SDK tracker exposure
- Correlate to IP and account
- Infer home/work locations
- Export device cluster to link analysis
📊 Dashboard KPIs
Distinct locations observedCo-located device countDevice make/model resolvedLinked apps/accountsIMEI validity/blacklist status
📂 Open
Workstation · Copilot · AI Skills · Automation · Playbooks · Lookups · Docs · Reports
🤖 AI Copilot
⚡ AI Skills
🔍 Lookup & Enrich
📚 Docs & Reports
💡 Recommendations
- Explore related tools below
- Automate recurring work via cron