Read the Risk Signals Overview
Risk Signals: Read the Risk Signals Overview
First select the application and time range
After entering the page, first select the application and time range to be analyzed.
- Select application: View the risk status of a business project.
- Select a time range: View available periods such as today, the last 7 days, or the last 30 days.
- Select all apps: View all apps that you have permission to access in the current Region, excluding data from other Regions.
Signal cards and trends are recalculated after switching applications or timeframes. Do not directly confuse the results of different applications and Regions into the same business conclusion.
Risk level
level indicates the signal's empirical risk severity and helps you rank investigation priorities. Products may display levels such as high, medium, and low risk.
Risk level is not a final business decision:
- High-risk signals usually deserve priority investigation, but still need to be combined with other information.
- Medium risk signals are suitable for further judgment based on account number, device history and business behavior.
- Low-risk signals can be used for observation and supplementary imaging. It is not recommended to trigger strong blocking alone.
Different services may have different tolerances for the same signal. For example, payment, login, marketing benefits, and content access are not treated in the same way.
Signal grouping
For easier reading, signals can be grouped by risk category, for example:
- Device environment: emulator, virtual machine, Root, jailbroken or cloned app.
- Network environment: VPN, proxy, IP blacklist or abnormal network.
- Client security: tampering tools, Frida, developer tools or man-in-the-middle attacks.
- Privacy and browser environment: Incognito mode, privacy settings or browser tampering.
- Bots and Automation: Bot detection or abnormal automated access.
The specific grouping and signal names are subject to the risk signal dictionary of the console.
Number of triggers
The number of triggers on a signal card represents the number of identified events that hit the signal within the selected application and time range.
An event can hit multiple signals at the same time. For example:
Event A: EMULATOR, IP_PROXY
Event B: EMULATOR
Event C: No risk signals
EMULATOR trigger count: 2
IP_PROXY trigger count: 1
Risk event count: 2Therefore, the sum of the number of triggers of all signals may be greater than the number of risk events.
Trend and cycle comparison
Once you select a signal, you can view its trend on the current timeframe and compare it to the previous period.
For example:
Current period: 2026-08-13 to 2026-08-19
Previous period: 2026-08-06 to 2026-08-12If comparable data is available for the previous period, the page can show increases or decreases. If there is no data for the previous period, the page displays “No data for the previous period” or —; it does not show +100%.
Graphic: Risk Signal Cards and Trends