Aller au contenu principal

Mobile app analysis

Encrypted traffic looks like noise from the outside. To see what a mobile app really sends, the PiRogue can instrument the app on a connected Android device: it records the network traffic, extracts the TLS keys and traces the cryptographic operations, even when the app uses certificate pinning.

What you get for each experiment:

  • the full network traffic (traffic.pcap) and the TLS keys to decrypt it (sslkeylog.txt)
  • a trace of the socket operations, showing which part of the app sent what
  • the encryption and decryption operations, in cleartext
  • a screen recording of the session

What's next​