Static content signals include sensitive APIs, permission combinations, embedded binaries, strings, domains, and third-party SDKs. Some are legitimate product requirements; others expose a real issue. Dynamic signals include downloaded code, background behavior, runtime defenses, injection detection, and network activity. They need controlled observation of the exact conditions under which they execute.
Reputation signals often relate to the signing certificate, package name, first-seen time, download host, and distribution history. Packaging and protection signals can include compression layout, DEX or native changes, shell behavior, and unusual build characteristics. Finally, vendors differ: each product has its own data, naming system, thresholds, and update schedule.