All guides · Page 3
Browse by topic, or search for a specific concept, tool or platform.
DexGuard: Android application protection
When evaluating DexGuard for Android app protection, assess code transformations separately from runtime checks.
Read the guideiXGuard: iOS code hardening and RASP
Evaluate iXGuard against iOS build, signing and framework requirements.
Read the guideIntroducing Promon Shield for Mobile
Assess Promon Shield by integration method and runtime coverage when building an application-protection shortlist.
Read the guideAppdome: a mobile application defense platform
When evaluating Appdome, establish how selected defenses enter the existing delivery pipeline.
Read the guideIntroducing Digital.ai Application Security
Define the platform and code scope of the proposed Digital.ai product. The product-family name alone does not establish protection of every application component.
Read the guideThe Zimperium MAPS product family
Do not treat MAPS as one control. Assess the questions answered by analysis, hardening and runtime components in separate evaluation entries.
Read the guideAssessing Zimperium zShield
For code-hardening products such as zShield, identify the protected code types and post-build output.
Read the guideZimperium zDefend and runtime risks
Assess which device or application risks zDefend turns into which responses in each workflow.
Read the guideDoveRunner and the former AppSealing name
Teams encountering DoveRunner and the older AppSealing name should first establish product and documentation continuity.
Read the guideIntroducing Talsec freeRASP
freeRASP is an option for teams assessing in-app security signals.
Read the guideIntroducing Talsec RASP+
Separate controls available in the free tier from the additional scope proposed for RASP+.
Read the guideApproov: app attestation and API protection
Assess Approov through the relationship between application and API trust.
Read the guideAppSweep mobile security testing
AppSweep supports mobile security assessment. Producing findings and embedding continuous protection into an application are different functions; choose tools…
Read the guideMobile threat visibility with ThreatCast
For services such as ThreatCast, event classification and context determine usefulness. The number of observed events is not a direct measure of prevented business loss.
Read the guideIntroducing Guardsquare App Attestation
Explain the boundaries where Guardsquare App Attestation evidence is generated and verified.
Read the guideAppknox mobile application security testing
Prioritize test scope and verifiable findings when assessing Appknox. An automated report does not independently accept every workflow or runtime defense.
Read the guideNowSecure mobile security assessment
Assess NowSecure through testing, evidence and integration with development. Preserve the relationship between the examined version and the final published package.
Read the guideIntroducing Quokka Q-mast
State which mobile risks Q-mast tests and under what conditions. Read its report alongside platform coverage and actual application behavior.
Read the guideOstorlab mobile security analysis
Analysis-platform output is a starting point. Teams must assess reachability, business impact and remediation evidence in application context.
Read the guideOversecured mobile application scanning
Oversecured output can support assessment of mobile code and configuration issues.
Read the guideRootBeer: an Android root-checking library
RootBeer provides checks for Android root indicators. Adding it does not complete an Android app protection architecture or establish certain knowledge of device state.
Read the guideIOSSecuritySuite: a Swift security library
IOSSecuritySuite is an option for Swift projects evaluating iOS security checks. Design how its results relate to server policy and legitimate usage.
Read the guideCertificate pinning with TrustKit
TrustKit is a library to consider for pinning implementations. Assess integration alongside pin transitions, failure behavior and older application versions.
Read the guideWhat is ProGuard, and can it replace RASP?
ProGuard transformations can affect analysis cost. Treating them as equivalent to integrity verification, root assessment or server enforcement creates incorrect…
Read the guideTalsec AppiCrypt and server-side risk decisions
Assess how AppiCrypt connects mobile data to server risk decisions. The protocol, failure policy and business outcome matter alongside product descriptions.
Read the guideFrida: mobile runtime analysis
Frida investigates the behavior of running applications. In app protection testing, the relevant question is which trust assumption and business outcome an authorized…
Read the guideobjection: exploring mobile runtime behavior
objection simplifies mobile runtime investigation. Its observations depend on specific device and application conditions, which the report should document.
Read the guideMobSF: a mobile security analysis platform
MobSF can support a mobile analysis workflow. Follow automated findings with source or package evidence and impact assessment in an actual business flow.
Read the guideAndroguard: Android analysis with Python
Androguard helps teams incorporate Android packages into Python analysis and automation.
Read the guideInspecting Android code with JADX
JADX helps explain Android code structure. Its output is an interpretation of the compiled program, not a guaranteed reconstruction of the complete original source.
Read the guideApktool: Android resources and package inspection
Apktool can inspect package resources and related structures. Record that the examined artifact corresponds to the actual release package.
Read the guideAnalyzing mobile native code with Ghidra
Ghidra supports binary analysis of native mobile components. Interpret its static view against the actual architecture and execution context.
Read the guideradare2: command-line binary analysis
radare2 provides tools for command-line binary inspection and automation. Record analysis steps and artifact versions during application-protection assessment.
Read the guideThe Rizin binary analysis toolkit
Useful Rizin output extends beyond function names. Connect data flows, reachable code and verification boundaries to actual application behavior.
Read the guideCutter: a graphical analysis environment for Rizin
Cutter helps organize binary investigation through a graphical interface. The meaning of displayed code still depends on analyst verification and architecture context.
Read the guideMobile binary inspection with Binary Ninja
Binary Ninja supports code and data-flow analysis in native mobile libraries. Higher-level representations provide hypotheses to test, not independent execution evidence.
Read the guideIDA Pro: the disassembler and decompiler ecosystem
IDA Pro can help explain native code in mobile packages. Security conclusions require connecting decompiler output to real entry points and business impact.
Read the guideJEB Decompiler and Android analysis
JEB is an option for Android application analysis. Treat protected-code readability and the effectiveness of a critical control as separate questions.
Read the guideInspecting Mach-O with Hopper
Hopper can support analysis of native iOS code. Read results alongside production signing, architecture and paths reachable during execution.
Read the guideLIEF: executable-file analysis with Python
LIEF supports programmatic inspection of executable structures. Python automation should not silently turn unexpected formats or missing fields into successful results.
Read the guideThe Capstone disassembly engine
Capstone translates machine code into instruction representations. It is an engine for broader analysis tooling, not a complete security product.
Read the guideThe Unicorn CPU emulator
Unicorn is a CPU-emulation component. Investigating a bounded code region differs from representing an entire mobile operating system or physical-device security.
Read the guideangr: symbolic analysis with Python
angr supports symbolic analysis and investigation of program behavior. Results for mobile binaries depend on the model, inputs and environmental assumptions.
Read the guidepwntools: Python automation for security laboratories
pwntools can assist automation in authorized security laboratories. Keep scope, test data and evidence sensitivity explicit in app protection work.
Read the guideInspecting ELF and DWARF with pyelftools
pyelftools helps Python scripts inspect ELF and DWARF data. Reports must not confuse an absent field with proof of application security.
Read the guideAutomating radare2 with r2pipe
r2pipe connects radare2 output to automation. A reliable pipeline checks versions, command results and parsing failures; empty output is not successful analysis.
Read the guidedex2jar: DEX and Java class tooling
dex2jar supports transformations between DEX and the Java class ecosystem for analysis.
Read the guideWhat are smali and baksmali?
smali and baksmali support inspection at the DEX level. Focus on how a critical control is used within a workflow, beyond the readability of the representation.
Read the guideInspecting Android distribution packages with bundletool
bundletool helps evaluate Android distribution packages against device conditions. Security tests should cover actual installation structures as well as a universal APK.
Read the guideVerifying APK signatures with apksigner
apksigner is a core tool for checking a final APK's signature information.
Read the guide