Android Pentest Toolkit — Overview
The big picture: a BurpSuite + Frida workflow for intercepting HTTPS traffic and bypassing security controls on rooted Android, and how the rest of this series fits together.
Android · 2026-03-075 posts tagged #frida.
The big picture: a BurpSuite + Frida workflow for intercepting HTTPS traffic and bypassing security controls on rooted Android, and how the rest of this series fits together.
Android · 2026-03-07The foundation every later technique depends on: ADB over USB/Wi-Fi, port forwarding, and getting frida-server running with the correct version and architecture.
Android · 2026-03-07Apps that refuse to run on rooted devices check packages, binaries, properties and exec calls. How frida_ssl.js neutralises each detection vector at both the Java and native layers.
Android · 2026-03-07A certificate in the trust store isn't enough when an app pins. Objection for standard stacks, Frida BoringSSL pattern-matching for Flutter and native, and ReFlutter as the static fallback.
Android · 2026-03-07The three reusable scripts behind the whole workflow — install_cert.sh (APEX-aware cert injection), frida_ssl.js (root + Flutter TLS bypass), LoggingHTTPServer.py — with full source and downloads.
Android · 2026-03-07