Hello I am using poco f4 Android and this issue has popped up today after the update, it wasnt happening before. Everytime I restart my phone the anomaly scan radar count keeps going up even though the main scanner says everything is clean.
Hello,
App Anomaly Detection monitors applications based on their behavior. The scan counter increments whenever an action performed by an application is verified. Since a reboot has occurred, I think it makes sense for applications to perform various actions that trigger such a scan.. I don't think it's related to the update, the behavior has always existed, but perhaps you have only noticed it recently?
Regards
I found out what was doing it but it's weird it was the Google drive, recently it was updated. I had google drive for months since I had installed bitdefender but the anomaly app scan count never went up. Recent update, the day I posted this post I updated my Google drive. I have uninstalled the app now. Its back to being stable but the the thing is still weird none the less as I didn't have any issues for months until the recent update. Bitdefender also got updated too
Another query, is it normal for anomaly app detection to trigger even if the phone is clean and the apps too? It showed increasing anomaly count but when I scanned everything was clean and there is a green symbol with " Your Device is Clean"
So, an increase in that counter for App Anomaly scans doesn't necessarily mean there is anything suspicious on the device. Mobile Security constantly scans specific actions performed by apps on the device, even if it is completely clean, to ensure everything is safe. The primary use case for this process is the existence of applications that may appear clean but later turn malicious or have managed to bypass traditional detection methods.
Bottom line is, as long as App Anomaly hasn't detected anything as infected, the device is safe. If Mobile Security didn't perform these anomaly scans on a clean device, what would actually be the point of this feature?
In the following example, the application was detected by the scan engine (the on-install alert is visible). Subsequently, an alert from App Anomaly Detection is triggered when it attempts to steal user data. This type of behavior (and many others) is detected by AAD; even if the sample were marked as "clean," this serves as an additional layer of protection: