"description":"The defender correlates Android camera access by an app identity with app and device context showing that the capture is inconsistent with expected user-driven recording behavior. The strongest Android evidence is camera resource access followed by sustained capture duration, video or image artifact creation, buffer or cache growth, and optional outbound transfer, especially when the app is backgrounded, operating as a foreground service without visible user initiation, active while the device is locked, or capturing without recent user interaction. The detection is strengthened when the app is unmanaged, recently granted camera access, or not approved to record video.",
"channel":"Camera sensor access began from app identity and remained active for sustained capture interval in app context not mapped to approved video recording workflow"
"channel":"Camera sensor access occurred while AppState=background, foreground service active without visible user action, or DeviceLockState=locked during capture interval"
"channel":"LastUserInteractionDelta exceeded threshold before camera session start and no foreground transition occurred during sustained capture interval"
"channel":"App identity performing camera session was unmanaged, recently granted camera permission, or not approved to use camera for video or interval image capture"