> For the complete documentation index, see [llms.txt](https://docs.facephi.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.facephi.com/docs.facephi-en/products/facephi-intelligence-platform/modulos/behaviour/device-intelligence-system.md).

# Device Intelligence System

Device Intelligence System (DIS) allows the technical context of sessions to be analyzed based on information about the device, the network, the location, and the environment from which the user interacts.

The collected smart signals help identify configurations or patterns that may require a more detailed review.

<figure><img src="/files/263cdb5114a621cc3120256d9462bf154c4397ad" alt=""><figcaption></figcaption></figure>

## What you can do

From Device Intelligence System, you can:

* View the general activity recorded over a period.
* Identify the smart signals detected most frequently.
* Locate sessions using filters.
* Access the session details.
* Analyze the device and connection information.
* Review the events recorded during each operation.
* View the activity recorded in the audit log.
* Access the related identity, when available.

{% hint style="info" %}
A smart signal provides context about the session, but it does not by itself confirm that fraud exists. Interpret it together with the rest of the available information.
{% endhint %}

## How it's organized

Device Intelligence System is divided into three areas:

* **Dashboard**, to view aggregated information.
* **Sessions**, to locate a session.
* **Session detail**, to analyze the information recorded during that session.

## Dashboard

The Dashboard provides an overview of the activity recorded during the selected period.

Use it to identify changes in activity, view the most frequent smart signals, and decide which information you need to investigate in more detail.

### Main indicators

The indicators summarize the activity for the selected period:

* Unique visitors.
* Unique devices.
* Smart signals detected.

<figure><img src="/files/7a9c4cebd0d64ec6ddd89bf27485a8d2eae68b42" alt=""><figcaption></figcaption></figure>

When a comparison with the previous period is shown, use it to identify how activity has changed.

A variation does not necessarily imply a positive or negative trend. It must be interpreted according to the type of indicator and the context.

### Change the period

Use the date selector to modify the analyzed range.

When you select a new period, the Dashboard indicators and blocks are updated with the corresponding data.

<figure><img src="/files/b7298c8e41b014ad5c6c45e0876fa62f35d7aed0" alt=""><figcaption></figcaption></figure>

{% hint style="warning" %}
The selected range cannot exceed one year.
{% endhint %}

### Smart signals

Smart signals shows the signals detected most frequently during the selected period.

<figure><img src="/files/8639d7c55b0b06843a07fe961d5cf9406b1f09e0" alt=""><figcaption></figcaption></figure>

The signals are ordered according to their detection volume.

Select **View all** to view the full list when there are more signals than initially shown.

Each Smart signal represents a condition detected on the device, the network, or the runtime environment.

#### VPN

Indicates that the session is using a virtual private network.

A VPN can modify or hide the visible IP address or location of the connection.

Interpret this signal together with the location, the network, and the rest of the available information.

#### Incognito mode

Indicates that the session is running in private or incognito browsing mode.

This mode may limit some of the information available about the browser or the session.

Its use does not by itself imply suspicious activity.

#### Residential proxy

Indicates that the connection uses a proxy associated with a residential IP address.

This type of connection can make it harder to identify the true origin of the traffic by making it appear to come from a conventional residential connection.

#### Datacenter IP

Indicates that the connection comes from an IP address associated with a data center, hosting provider, or similar infrastructure.

This can be common in certain technical contexts, but it is less common in a session carried out directly from a residential connection.

#### High-activity device

Indicates that the device shows an unusually high volume of activity during the analyzed period.

Also review the session frequency and the rest of the signals associated with the device.

#### Developer tools

Indicates that active developer tools were detected during the session.

These tools can be used for legitimate purposes, but they also allow the behavior of an application or website to be inspected or modified.

#### Bad bots

Indicates that the activity shows characteristics associated with malicious automation or bots classified as risky.

Review the speed and interaction pattern together with the rest of the available signals.

#### Rooted device

Indicates that an Android device shows signs of root access.

Root access changes the usual operating system restrictions and may reduce some of its security guarantees.

#### Tor

Indicates that the IP address used is associated with the Tor network or with known nodes in that network.

Tor can hide the true origin of a connection by routing traffic through different nodes.

#### Network anomalies

Indicates that unusual or inconsistent characteristics were detected in the network used during the session.

View **Network & Location** to analyze the available network context.

#### Android Emulator

Indicates that the application may be running in an emulated Android environment rather than on a conventional physical device.

Emulators can be used for legitimate purposes, but they can also be part of automated or manipulated environments.

#### Velocity anomaly

Indicates that an activity or movement pattern inconsistent with the elapsed time was detected.

It may be related to rapid changes between IP addresses, countries, or locations.

#### Factory reset

Indicates signs compatible with a recent factory reset of the device.

A reset can modify or remove some of the information used to recognize a previously known device.

#### Attack IP blocklist

Indicates that the IP address used appears on a list associated with attack sources or known malicious activity.

Review the session and the rest of the network context before determining its relevance.

#### Geolocation spoofing

Indicates that there are signs the location reported by the device may have been manipulated.

Compare this information with the location obtained from the network and with other sessions when available.

#### Tampering

Indicates that signs of tampering with the application, the device, or its runtime environment were detected.

#### Jailbreak

Indicates that an iOS device shows signs of jailbreak.

Jailbreak changes certain operating system restrictions and may reduce some of its security protections.

#### Frida

Indicates that signs related to instrumentation tools such as Frida were detected.

These tools can be used to inspect or modify the behavior of an application while it is running.

#### Cloned app

Indicates that the application may be running from a copy or cloned instance.

Review the device and the rest of the signals to determine whether it corresponds to an expected environment.

#### MitM attack

Indicates signs compatible with a Man-in-the-Middle attack.

In this type of situation, a third party may try to intercept or alter the communication between the device and the service.

{% hint style="warning" %}
Smart signals should be analyzed together. The combination of several signals can provide more context than an isolated detection.
{% endhint %}

### Investigate a signal

Dashboard shows aggregated information.

When a Smart signal needs a more detailed review, use [**Sessions**](#sessions) to locate the related sessions and view their evidence.

***

## Sessions

Sessions shows the sessions recorded by Device Intelligence System.

Each row represents a session and provides access to all the information collected during its lifecycle.

<figure><img src="/files/59f2116b4c13cfa3f96bf50b49e00e78aa74d644" alt=""><figcaption></figcaption></figure>

### Search sessions

Use **Search** to locate a session using the available identifiers.

Depending on the recorded information, the search may accept identifiers such as:

* Session ID.
* Identity ID or associated identifier.
* Device ID.
* IP address.

The availability of each criterion depends on the data received during the session.

### Filter sessions

Use the available filters to narrow the results by:

* Date.
* Country.
* Environment.
* Status.

When you apply multiple filters, the sessions must meet all the selected criteria.

If you select multiple values within the same filter, the sessions that match any of those values are shown.

### View the list

Each row shows the main available data about a session, such as:

* Session identifier.
* Associated user, when available.
* Channel.
* Date and time.
* Status.

Some data may not appear if it was not received during the session or if the user was not identified.

### Open a session

Select **View session** in the row **Actions** to open the full detail.

<figure><img src="/files/d1f1f3f5fb90f11b66dea6d19472378717d724a8" alt=""><figcaption></figcaption></figure>

If the applied filters return no results, modify or remove some of them to broaden the search.

***

## Session detail

Session detail gathers the information recorded during a session.

<figure><img src="/files/7d95e216e2929a32d6cab0fc96a56667993efecb" alt=""><figcaption></figcaption></figure>

The header lets you identify it and view its main data. The rest of the information is distributed across different tabs.

Select a tab to view another category of information. Changing tabs does not modify the session data.

{% hint style="info" %}
The detail information is read-only and represents the data recorded during the session. It cannot be modified from DIS.
{% endhint %}

### Summary

Summary provides an overview of the session.

Use it as a starting point to understand the context before reviewing more specific information.

It may include:

* Session identifier.
* Date and duration.
* Associated user.
* Channel and environment.
* Main device information.
* Main connection information.
* Summary of the smart signals detected.

When there is an associated identity, select the available access to open its detail and view other sessions and related information.

Summary is a query screen and does not allow the session status to be modified.

### Alerts

Alerts gathers the detections and alerts recorded during the session, including those associated with Smart signals.

<figure><img src="/files/882d6e694a588ac2e90187009197afdc0fab44fc" alt=""><figcaption></figcaption></figure>

Use this tab to identify which conditions were detected and view the available context for each one.

Each item may include:

* Name.
* Result.
* Contextual information.
* Other data related to the detection.

#### View a smart signal

Select the information icon for a signal to open its detail.

The information displayed helps you understand:

* What condition the signal detects.
* What result was recorded.
* In what context it may occur.

Close the detail to return to the list of signals.

The detection of a smart signal does not automatically change the status of the session.

### Devices

Devices shows the technical information for the device used during the session.

<figure><img src="/files/c202fff1a92ae98efa99559c014c0b7b7102d146" alt=""><figcaption></figcaption></figure>

Depending on the available data, it may include:

* Device type.
* Brand and model.
* Operating system and Version.
* Browser.
* Device identifier or fingerprint.
* Technical configuration.
* Indicators related to device integrity.

Use this information to check:

* Whether the device shows any unusual condition.
* Whether there are signs of tampering.
* Whether an emulated environment is being used.
* Whether the device matches other available records.

Interpret this data together with the Smart signals and the rest of the session context.

### Network & Location

Network & Location gathers the available information about the connection and the approximate location of the session.

<figure><img src="/files/072eed3aca561a4aeb75419066a6b6b26061e490" alt=""><figcaption></figcaption></figure>

It may include:

* IP address.
* Country, region, or city.
* Network provider.
* Connection type.
* Use of VPN or proxy.
* Other smart signals related to the network.

Use this tab to contextualize where the interaction took place and check whether the connection presents conditions that require attention.

{% hint style="info" %}
The location obtained from an IP address is approximate and may be affected by VPNs, proxies, or other network services.
{% endhint %}

Network & Location is a query screen. It does not allow an IP address or a network to be modified or blocked.

### Timeline

Timeline shows the events recorded during the session in chronological order.

<figure><img src="/files/76325c1809b7f64c9f5dda858c0ebff3d94e90fd" alt=""><figcaption></figcaption></figure>

When a session contains multiple operations, its events are grouped into separate blocks. This makes it possible to identify what happened within each operation without mixing their data.

#### View an operation

Review the header of each block to identify the corresponding operation.

Within the block you can view the events, the smart signals, and the rest of the activity recorded during that operation.

#### Collapse or expand an operation

Select the control in the upper-right corner of the block to show or hide its content.

You can collapse operations you do not need to view to reduce scrolling and focus on the relevant information.

#### Reconstruct the activity

Review the items in chronological order to identify:

* What events occurred.
* When a smart signal was detected.
* In which operation it was recorded.
* What result each event had, when available.

Timeline is a query view. The recorded events cannot be modified.

### Audit log

Audit log shows the actions performed on the session from the back office.

<figure><img src="/files/207d7751770af5dcca84123379662069d6cfc914" alt=""><figcaption></figcaption></figure>

Each record may include:

* Date and time.
* User who performed the action.
* Action.
* Result.

Use this tab to review the traceability of the queries and actions performed by FIP users.

Audit log is a read-only screen. The records cannot be edited or deleted.

{% hint style="info" %}
Timeline shows what happened during the session. Audit log shows the actions performed later from the back office.
{% endhint %}

***

### How to investigate a session

{% hint style="info" icon="note" %}

1. Start with **Summary** to understand the overall context.
2. View **Alerts** to identify the detections and registered Smart signals.
3. Review the technical information in **Devices**.
4. Check the connection and location in **Network & Location**.
5. Use **Timeline** to reconstruct the order of events and relate them to each operation.
6. View **Audit log** when you need to review the subsequent traceability.
7. Access the related identity when you need to expand the context.
   {% endhint %}

Do not base a conclusion solely on a Smart signal. Interpret the device, the network, the detections, and the activity recorded during the session together.
