Mobile app analysis
Encrypted traffic looks like noise from the outside. To see what a mobile app really sends, the PiRogue can instrument the app on a connected Android device: it records the network traffic, extracts the TLS keys and traces the cryptographic operations, even when the app uses certificate pinning.
What you get for each experiment:
- the full network traffic (
traffic.pcap) and the TLS keys to decrypt it (sslkeylog.txt) - a trace of the socket operations, showing which part of the app sent what
- the encryption and decryption operations, in cleartext
- a screen recording of the session
What's next
- Upload the results to Colander to decrypt, decode and report on them: Analyze traffic with Colander
- Prefer to run the analysis from your own computer? See Octopus