# Heimdallr
Heimdallr is preserved as an exact log-context label associated by Bryant McGill with the RT Buddy/Pegasus observation.
## Observed relationship
Bryant states that the RT Buddy/Pegasus identification arose when the relevant activity or resources appeared in logs together with [[CrashCapture|CrashCapture]] or Heimdallr, particularly through documented resources visible in those logs.
## Disambiguation
**Heimdallr**, with a trailing “r,” remains the unresolved Apple log-context label described here. It must not be merged with [[Heimdall|Heimdall]], the distinct open-source Samsung download-mode firmware-flashing tool.
## Evidentiary boundary
The exact Heimdallr component, spelling variant, platform, version, process, bundle identifier, and resource path have not yet been recovered into this wiki. Because “Heimdall” and “Heimdallr” are reused names, this label must not be normalized to a particular product without the originating log context. Log proximity is observational evidence, not by itself proof of infection, control, authorship, or attribution.
## Related notes
[[RTBuddy|RTBuddy]] · [[Pegasus Spyware|Pegasus Spyware]] · [[NSO Group|NSO Group]] · [[CrashCapture|CrashCapture]] · [[Heimdall|Heimdall]].
## Pegasus heuristic caution
**Owner-supplied interpretation:** Bryant McGill states that finding Pegasus heuristics, standing alone, means nothing as proof of the underlying system or attribution. In his interpretation, “Pegasus” is a very clumsy cover for something else, which later documents in this archive will detail. Until those materials are incorporated, heuristic matches must not be treated as proof of Pegasus infection, NSO Group attribution, or final identification of the underlying mechanism.
## Scanned_20260730-1946 overlay
Heimdallr is not visibly written in [[Scanned_20260730-1946]]. It is linked only because the vault owner states that documented resources used for the RT Buddy/Pegasus identification were observed in logs with [[CrashCapture]] or Heimdallr.
This is owner-supplied cross-source context, not independent page proof. Preserve the originating log and its exact device/build, timestamp, process or bundle ID, and resource paths; heuristic matches alone do not prove infection or attribution.