# TENEBRAE Mobile SOC — Mobile-first threat defense

> Mobile-first threat defense (iPhone/iPad app by Tenebrae Security.)

- Source: https://appshunter.io/ios/app/tenebrae-mobile-soc/id6773179652 (this page in markdown: same URL + `.md`)
- Developer: [Tenebrae Security](https://appshunter.io/developer/6773179654)
- Category: Business, Utilities
- Price: Free
- Age rating: 17+
- Requires: iOS 15.0 · 21 MB
- Languages: American English
- Released: 2026-06-22
- Data updated: 2026-07-16
- User reviews in markdown: https://appshunter.io/ios/app/tenebrae-mobile-soc/id6773179652/reviews.md

## What is TENEBRAE Mobile SOC?

Thank you for reviewing TENEBRAE.

TENEBRAE is an enterprise Security Operations Center (SOC) platform. Customers deploy it via Apple Business Manager and their MDM (Jamf, Intune, Mosyle, Workspace ONE), which provisions each device against the customer's tenant. End users do not sign in, so there is no usernamd, use the built-in App Review demo mode:

1. Launch the app.
2. On the sign-in screen, tap the TENEBRAE shield logo 5 times within ~1.5 seconds.
3. A button appears: "Apple App Review use oode".
4. Tap it. A sample SOC dashboard loads (one device, one phishing threat, one alert).

This gesture is compiled only into the review build; customers never see it.

NETWORK EXTENSION
The binary includes three providers under conetworkextension: a DNS Proxy(NEDNSProxyProvider), a Content Filter Data provider (NEFilterDataProvider), and a Content Filter Control provider    (NEFilterControlProvider). They enforce the e: the DNS Proxy answers NXDOMAIN forblocklisted hostnames; the Content Filter drops blocked flows (matched on TLS SNI / destination IP) so the connection simply fails. They do NOT decrypt TLS, read s, inject certificates, or proxy through anyTenebrae relay. Non-matching traffic is forwarded unchanged and not logged. Block events go to the customer's own SOC backend. Full disclosure: https://www.tenebrn 3.
                                                                                                                      WHY FILTERING IS NOT OBSERVABLE ON A STANDARtform requirement, not an app limitation):
- The Content Filter activates only on a SUPERVISED device. On a non-supervised device, iOS rejects the configuration ("permission denied") before any prompt.
- The DNS Proxy requires Automated Device Enrollment via MDM (Apple's docs: the payload "requires a device management service to install").
In production, the customer's MDM pushes a profile that pre-approves the providers and they activate silently.

ATTACHED VIDEO (~1:35, captioned, recorded on a supervised device) shows, in one take:
1. The populated SOC dashboard.
2. Protection ON: Safari fails to open phishing-test.tenebraesecurity.com ("cannot open the page") because the Content Filter drops the connection - no redirect, n
3. Kill-switch: turning Protection OFF lets the SAME URL load, proving the block was4. Protection back ON: blocked again.
5. The block recorded as a threat (phishing, MITRE Initial Access).                 
TEST HOST: phishing-test.tenebraesecurity.com is permanent production infrastructurePolicy 3.8). With filtering OFF - or from aning yours - it loads a controlled page; thatis the "filtering off" signal shown by the kill-switch. Verify it is live: curl -sI https://phishing-test.tenebraesecurity.com/ -canary: phishing-test"). This mirrors public test URLs from AdGuard, NextDNS, and Cisco Umbrella.

The full app UI is reviewable on any device via demo mode. If anything does not behave as described, please contact us before rejecting - we respond same-day, incla supervised device.

Contact: contact@tenebraesecurity.com
J & M International Group LLC, d/b/a Tenebrae Security
Team ID: J6FW6FW8BY  Bundle ID: com.tenebrae


## Version history (last 1 release)

### 1.0 — 2026-06-22

No release notes.

---

*Data collected daily from the US App Store and indexed by [AppsHunter](https://appshunter.io/). User reviews are verbatim App Store reviews. Ratings, prices and chart positions refresh continuously; this snapshot is from 2026-07-16.*
