Data Points

📲 Device / Advertising ID

A mobile advertising or device identifier used in adtech data to track and locate devices.
Identity

Sources

1
1 no-auth

Disciplines

1
that use it

Mission domains

1
reach

Workbench

native tool

🔌 Sources that yield Device / Advertising ID (1)

SourceCategoryAuthFormat
Mobile Advertising-ID / MADINT refs
Mobile device & advertising-ID intelligence.
IDENTNONEhtmlhome↗

🧭 Disciplines

IDENT (1) →

🎯 Mission Domains

Fraud & Identity (1) →

🔍 Lookup

📜 Playbook — Device / Advertising ID exploitation

  1. Direction — frame the requirement for Device / Advertising ID: what decision does this support, by when?
  2. Collection — pull the 1 mapped sources (1 free) and the native workbench; capture provenance and observe OPSEC.
  3. Processing — normalize, de-duplicate and enrich the collected data.
  4. Analysis — correlate against local holdings; apply ACH; assign confidence.
  5. Dissemination — open a case, draft a report, share via STIX/MISP.
  6. Feedback — set an alert rule / watchlist to monitor for change.

⚡ AI Skills & Automation

🤖 Copilot brief⚡ AI SkillsResolveEnrichAuto-CollectHuntReportExport

Automate unattended via the cron pipeline (collect → ingest → resolve → enrich → score → alert).

🎫 Device / Advertising ID

A device or advertising ID is a resettable or hardware-bound identifier (GAID, IDFA, Android ID, IMEI) that tracks a physical device across apps and ad networks. It is a powerful de-anonymization and co-location selector because ad-tech and MAID datasets tie devices to locations, behaviors, and often back to real identities.

Format: GAID/IDFA: UUID (8-4-4-4-12 hex). Android ID: 16 hex chars. IMEI: 15 digits with Luhn checksum. IMSI: 15 digits (MCC+MNC+MSIN). MAC: 12 hex (colon-separated).

📡 How it is collected

  • Mobile ad-exchange bid-stream / MAID datasets
  • App SDK telemetry and analytics logs
  • Device forensic acquisition
  • MDM / EMM enrollment records
  • Wi-Fi/Bluetooth probe capture
  • Data-broker location datasets

🧩 Analysis & hunting techniques

  • MAID-to-location pattern-of-life analysis
  • Device co-location and rendezvous detection
  • TAC/OUI decoding for make and model
  • IMEI Luhn validation and blacklist check
  • App-fingerprint correlation via SDK trackers
  • Cross-app identifier stitching
  • Home/work location inference from dwell
  • Probe-request device tracking

🔧 Tools

  • MobSF
  • Frida
  • Wireshark
  • Exodus Privacy
  • Kismet
  • adb (Android)
  • Cellebrite (reference)
  • AppCensus

⚡ Workbench actions

  • Decode TAC/OUI to make and model
  • Validate IMEI checksum
  • Trace MAID location pattern-of-life
  • Detect co-located devices
  • Map app/SDK tracker exposure
  • Correlate to IP and account
  • Infer home/work locations
  • Export device cluster to link analysis

📊 Dashboard KPIs

Distinct locations observedCo-located device countDevice make/model resolvedLinked apps/accountsIMEI validity/blacklist status
Workstation · Copilot · AI Skills · Automation · Playbooks · Lookups · Docs · Reports

🤖 AI Copilot

🔍 Lookup & Enrich

💡 Recommendations

⚙ Automation

Cron: 0 * * * * php /home/zaptf0zdggll/public_html/threats/cron.php