$ ./pentest --android

A hands-on Android pentest series: BurpSuite + Frida for HTTPS interception, certificate injection (pre-14 & APEX), root detection & SSL pinning bypass, and the reusable scripts behind it.

01
Fundamentals beginner

Android Pentest Toolkit — Overview

The big picture: a BurpSuite + Frida workflow for intercepting HTTPS traffic and bypassing security controls on rooted Android, and how the rest of this series fits together.

Android · 2026-03-07
02
Certificate Injection beginner

The Android CA Trust Store Across Versions

Why your proxy CA strategy depends entirely on the Android version: the three breakpoints — user-store trust (≤6), system-store-only (7+), read-only root (9–10), and APEX (14+) — that decide whether you need root and how you inject the cert.

Android · 2026-03-07
03
Fundamentals beginner

ADB & Frida Setup

The foundation every later technique depends on: ADB over USB/Wi-Fi, port forwarding, and getting frida-server running with the correct version and architecture.

Android · 2026-03-07
04
Certificate Injection intermediate

Certificate Injection — Android < 14

Installing a BurpSuite CA into the system trust store on Android 13 and below via direct /system remount, the hash-based filename rule, plus an OpenSSL certificate-operations reference.

Android <14 · 2026-03-07
05
Certificate Injection advanced

Certificate Injection — Android 14+ (APEX)

Android 14 moved the CA store under an APEX module with per-process mount namespaces. Injecting a cert now means tmpfs overlay plus nsenter into every Zygote and app namespace.

Android 14+ · 2026-03-07
06
Root Detection Bypass intermediate

Root Detection Bypass

Apps that refuse to run on rooted devices check packages, binaries, properties and exec calls. How frida_ssl.js neutralises each detection vector at both the Java and native layers.

Android · 2026-03-07
07
SSL Pinning Bypass intermediate

SSL Pinning Bypass

A certificate in the trust store isn't enough when an app pins. Objection for standard stacks, Frida BoringSSL pattern-matching for Flutter and native, and ReFlutter as the static fallback.

Android · 2026-03-07
09
Tools & Scripts intermediate

Tools & Scripts

The three reusable scripts behind the whole workflow — install_cert.sh (APEX-aware cert injection), frida_ssl.js (root + Flutter TLS bypass), LoggingHTTPServer.py — with full source and downloads.

Android · 2026-03-07