Action log — specific things the apps did, newest first
Live feed — connecting…
Interaction threads — one thread is one sitting
A notification, an app opened, what happened next. A new thread starts when the
device goes five minutes with no app activity, and a stretch that runs past about 45 minutes is
split again at its own quietest moment. That second rule exists because social apps refresh every
couple of minutes on their own, so a phone in a pocket never actually falls silent.
History — every day on record; click a day to inspect it
Activity timeline
Sessions
⛔ Blocked
The story
Auto-generated narrative of what this device was doing
Daily rhythm — every day on record; when the phone is awake, asleep, or off the network
00:0006:0012:0018:0024:00
Habits — what follows what
Most common app-to-app moves across every session
Typical day & binges
Which app usually dominates each part of the day
00040812162024
Security & anomaly watch — what's new and what never stops talking
Newly-seen domains — first appearance in 24 h
Always-on / beaconing connections
Notifications & attention — what pulls vs. what's chosen
Digital wellbeing — sleep, screen & focus
New apps & services — first-ever appearances, newest first
Registered domains this device had never contacted before, grouped and de-noised,
each classified by kind. Stays listed for the whole window, so a one-time open never scrolls
away. The strip highlights sensitive and app-like arrivals (dating, finance, health, AI…);
the table below classifies everything, background infra included.
Unidentified services — what the knowledge base cannot name yet
Domains this device uses regularly that match no rule, ranked by how much traffic
we are failing to explain. This is the coverage gap, stated plainly: the work-list for the next
intelligence ingest rather than a hole we hide. Names arrive as the catalogue grows, or you can
train one yourself from the app row.
Attempted — tried to reach something a pack blocks
Every lookup this device made that was refused. On the phone a block just looks like a
page that failed to load, so this is the only place it is visible. One caveat kept in view throughout:
a blocked lookup does not prove a person typed the address. An embedded ad frame, a preloaded link or
a background SDK all produce them. Attempts that look like someone actually opening something are
counted separately from background noise.
Most recent attempts
Phoning home to China — who is on the other end
Two different questions, kept apart on purpose. Where it landed is measured:
the resolver records the network each answer geolocated to. Who operates it is ownership:
the service belongs to a company headquartered in China even when a US or European cloud serves
it. TikTok is the reason both matter — it resolves inside the United States and is run by
ByteDance. DNS shows which services are contacted and where they resolve. It cannot see what was
sent, and nothing here claims otherwise.
Places — which network this device is attached to, and for how long
DNS reveals a network fingerprint, never a coordinate. A place becomes an address when you name it. Open map →
Association intelligence — which selectors cross over on the same network, and when
Two devices on one fixed network at the same time is a link. Cellular is excluded — a shared carrier gateway is not a place. Open the operating picture →
Fleet association graph — edge weight = total co-presence; selected pair highlighted