Android + iOS · OWASP MASTG aligned · multi-tenant

See what your mobile app is leaking.

intjector is a browser-based security console for Android APKs and iOS IPAs. Static analysis plus an embedded Frida runtime - deep-link fuzzing, shared-preferences & keychain dumps, SSL pinning bypass, WebView bridge taps - inside per-company workspaces with client-ready reports.

Works with rooted and non-rooted Android devices, and with jailbroken or signed iOS builds.

intjector console - Android scan overview: risk profile, manifest security flags, hardcoded secrets and attack surface

What's inside

Two engines - static and dynamic - covering both platforms, mapped directly to OWASP MASTG, inside per-company workspaces.

AndroidAPK surface

  • DEX + native library scan, obfuscation & packer detection, embedded secrets.
  • Manifest review - exported activities / services / receivers, permission audit, android:debuggable, networkSecurityConfig.
  • Deep-link & intent filters - scheme collision, parseUri / intent-redirect, App Links (assetlinks.json) verification.
  • WebView hardening - setJavaScriptEnabled, @JavascriptInterface bridges, file-access flags, mixed content.
  • Content providers & FileProvider - exported paths, grantUriPermissions, path-traversal sinks.
  • Crypto & storage - weak cipher / IV reuse, hard-coded keys, SharedPreferences & SQLite without encryption.

iOSIPA surface

  • Mach-O inspection - PIE / ARC / stack canary, Swift reflection, embedded .mobileprovision & certs.
  • Info.plist & entitlements - ATS exceptions, keychain-access-group wildcards, associated-domains, URL schemes.
  • Universal Links - live AASA fetch, path wildcards, subdomain takeover checks.
  • WKWebView / deep link handlers - JS bridges, navigation delegate, continueUserActivity:, OAuth redirect hijack.
  • App Extensions (.appex) - privileged extension points, TRUEPREDICATE activation, full-access keyboards.
  • Keychain & storage - accessibility class audit, SQLCipher / Realm encryption, pasteboard exposure.

Static analysis & triage

Scan overview

Every scan opens on a risk profile: critical / high / medium / low counts, affected categories, manifest security flags, hardcoded secrets, and the full attack surface - exported activities, WebView, deep links, providers, services, receivers - plus a permission audit flagged against the malware-abuse list.

Findings, built for a report

Each finding carries what, impact, exploitation and remediation, with exact file:line locations and code. Filter by severity, category or signal; mark each reviewed, false-positive or accepted-risk. Optional AI enrichment adds an explanation as an unreviewed hypothesis, never a verdict.

Attack paths

Exploit-chain correlation draws attacker-to-impact graphs from exported components (provider escalation, file read / XSS, SSRF) and ranks each chain by confidence. Every chain ships a copy-paste adb payload and an in-process Frida payload so you can fire it against a live device.

OWASP MASTG audit

A MASVS-mapped checklist across storage, crypto, auth, network, platform, code and resilience, each test marked pass / fail / manual with a detected-vs-documented view and the code evidence that fired it. Export the matrix as CSV.

API enumeration

Pulls servers, base domains, DTOs and plain URL literals out of the decompiled sources, then offers canonical discovery probes - Swagger / OpenAPI, GraphQL, Spring actuator, well-known endpoints - to test against each origin with curl.

String & secret explorer

Search every string literal in the app - tens of thousands - filtered by source and category: secret-like, base64, URI-scheme, URL, identifier. Jumps straight to the file:line that holds a hardcoded credential, DB connection string or token.

Decompiled source browser

Walk the full JADX / decompiled tree in the browser with a syntax-highlighted AndroidManifest.xml and class viewer. Filter by path, grep file contents across the whole app, and pivot from a finding to its exact source.

Runtime instrumentation

Live Frida session

A persistent Python agent stays attached over the entire engagement. Install hooks, drain events, re-query - state survives between UI actions instead of re-spawning a fresh session per call. Active jobs panel lists every live hook / override / monitor / bypass in one place; one click to kill any of them.

Secret stores

Android - walk SharedPreferences, EncryptedSharedPreferences, SQLite databases, and Keystore aliases.

iOS - dump every keychain item the process can see (GenericPassword, InternetPassword, Certificate, Key, Identity) with the full attribute dictionary.

Sandbox filesystem browser

Navigate the app sandbox from the browser. Inline preview for any file under 4 MB with UTF-8 auto-decode.

Android - /data/data/<pkg>/, files, databases, caches, shared_prefs.

iOS - bundle, Documents, Library, Caches, Preferences, tmp.

Cookies & preferences

Android - dump every SharedPreferences XML under the data directory plus WebView cookie store.

iOS - enumerate NSHTTPCookieStorage (name, value, domain, path, flags) and NSUserDefaults.dictionaryRepresentation.

Class / method probe + set return value

List every ObjC or Java class, filter by name, click through to see its methods. Inline set return value editor on every method - force true / false / 0 / 1 / null / any literal without writing a Frida script. Type-aware coercion handles boolean, int, long, String. Neutralise isJailbroken / isRooted / isDebuggerConnected in one click.

Pattern watch

Wildcard hook against thousands of methods at once. Type *Login*!*auth* (Android) or *[*Login* *isLoggedIn] (iOS) and a tracing hook installs on every match. Args + return values stream into the live event timeline; one install becomes one job, kill restores all hooks atomically.

Heap explorer

Grab live instances of any class with Java.choose / ObjC.chooseSync. Walk fields, call zero-arg methods on the exact object in memory. Find the live LoginManager and dump its userToken; spot every WKWebView with javaScriptEnabled = true; read decoded NSURLCredentials from the heap.

URL launcher & scheme fuzzer

Send any myapp:// URL or Android intent to the running app from the UI. The scheme fuzzer tries nine built-in payloads - empty URL, open redirect, javascript:, path traversal, null-byte - to find deep-link handlers that don't validate input.

Bypasses & hooks

Android TLS bypass

Disables OkHttp CertificatePinner, Conscrypt, X509TrustManager, WebViewClient.onReceivedSslError, and Network Security Config pin sets in one step. Works even when an app uses several TLS libraries at once.

iOS SSL pinning bypass

One click installs hooks on SSL_set_verify (BoringSSL), SecTrustEvaluate / SecTrustEvaluateWithError, AFSecurityPolicy (AFNetworking), and TSKPinningValidator (TrustKit). Lets you intercept HTTPS traffic without modifying the app binary.

Root / jailbreak / biometrics bypass

Hides root and jailbreak indicators, and forces biometric checks to succeed.

Android - hides Magisk, superuser apps, su binaries, and test-keys; strips FLAG_SECURE from windows so screenshots work for evidence; observes KeyStore.load / getKey / aliases usage.

iOS - hooks NSFileManager.fileExistsAtPath:, UIApplication.canOpenURL:, libc stat / lstat / access / fopen; replaces the reply block on LAContext.evaluatePolicy:reply: to force Touch ID / Face ID success.

Custom bypass-script generator

Reads your static-scan findings + SBOM and generates a Frida script that hooks only what this app actually uses - custom TrustManager and HostnameVerifier classes the scanner caught, app-specific su / magisk paths from bytecode strings, RootBeer if bundled, AFNetworking / TrustKit / OkHttp blocks conditional on imports. Smaller, faster, fewer false hooks. Saves to the codeshare library so the next scan of the same target opens with the right bypass.

Intent / openURL monitor

Logs every URL or IPC the app fires or receives.

Android - hooks Activity.startActivity*, Context.startActivity / startService / sendBroadcast, and BroadcastReceiver.onReceive; decomposes each Intent into action / data / extras / flags / categories / component.

iOS - hooks UIApplication.openURL:, openURL:options:completionHandler:, canOpenURL:, every application:openURL:options:, legacy sourceApplication:annotation:, and continueUserActivity:.

Crypto monitor

Captures every symmetric crypto / KDF / RNG call the app makes - keys, IVs, plaintext, PBKDF rounds - with hex previews streaming into the live event timeline.

Android - hooks Cipher.init / Cipher.doFinal, Mac.doFinal, MessageDigest.digest, KeyGenerator.generateKey.

iOS - hooks CCCrypt, CCCryptorCreate, CCKeyDerivationPBKDF, SecRandomCopyBytes with full argument decoding.

WebView bridge tap

Captures every message passed from JavaScript to native.

Android - hooks @JavascriptInterface methods and evaluateJavascript callbacks.

iOS - captures userContentController:didReceiveScriptMessage: with handler name, body, frameInfo.request.URL, and isMainFrame.

Deserialization tap

Catches unsafe class-graph reads as they fire.

Android - hooks Parcel, Intent.getParcelableExtra, ObjectInputStream.

iOS - instruments NSKeyedUnarchiver legacy + secure decode, NSCoder, NSXMLParser, PropertyListSerialization.

Deployment & reporting

Device & app picker

Lists every USB / network Frida device (Android & iOS) and enumerates installed apps with package / bundle-id, name, and PID. Filter, click, attach - the UI handles process spawning, script loading, and teardown.

APK repackaging

Works against any debuggable build out of the box; for release APKs, re-signs with a debug cert or injects Frida Gadget into lib/<abi>/ and aligns / signs the output so it installs on a non-rooted device.

IPA patcher (no jailbreak)

Unzips an IPA, copies FridaGadget.dylib into Frameworks/, injects an LC_LOAD_DYLIB command via insert_dylib --strip-codesig, removes _CodeSignature/ and embedded.mobileprovision, and repacks. Re-sign with your cert and install - no jailbreak required.

Remote device agent

Issue a one-time agent token, run the self-contained installer on the box with your phone plugged in (macOS or Linux), and its USB devices show up in intjector. From the runtime tabs, adb and Frida route through that agent - the device never has to be reachable from the internet.

OWASP MASTG alignment

Every signal maps to a MASVS category and, where one exists, a specific MASTG v2 test id - validated against the upstream catalogue so no identifier is invented. A detected-vs-documented view shows which checks fired on this build, not just which exist.

Reports, ready to ship

One click renders a pentest-ready PDF: cover grade, business-impact overview, severity-ordered findings table and per-finding cards. The same data exports as JSON for automation, Markdown for GitHub / Notion, and Excel (.xlsx) with a MASTG / MASVS checklist sheet.

Multi-tenant, browser-first

Everything runs in one web UI - upload, scan, triage, attach, patch, report - inside per-company workspaces with superadmin, workspace-admin and tester roles enforced on the server. No terminal, no Frida CLI, no Python setup; share the workspace with your team and sessions persist across users.

Who uses it

Useful for anyone working with mobile app security.

How access works

intjector is multi-tenant and invite-based. You request access, verify your e-mail, and - once approved - get your own company workspace. Sign-in is passwordless throughout: a single-use code by e-mail, no passwords to manage.

Request access

Sign up with your name, company and work e-mail. Nothing is provisioned yet.

Sign up

Verify your e-mail

Enter the one-time code we send you. Verification confirms the address; it does not activate an account.

OTP

Get approved

Platform administration reviews the request and, on approval, creates your workspace and sends an invitation.

Review

Start testing

Accept the invitation to become your workspace admin, then add testers and upload apps.

Workspace admin

Three roles, cleanly separated

Superadmin

Platform administration

  • Approves registrations and tester requests.
  • Manages workspaces, the allow-list and invitations.
  • Never sees a workspace's scans, findings or reports.
Workspace admin

One company, its work

  • Uploads apps and runs the full static + runtime toolkit.
  • Adds testers through User Management.
  • Authority stops at their own workspace.
Tester

Security work

  • Runs scans, inspects findings, drives the runtime session.
  • Exports and ships reports.
  • No user management, no access to other workspaces.

Every boundary is enforced on the server and at the data layer - not just hidden in the UI.

Preview

A look at the tool in action - same workflow for Android and iOS.

intjector live demo
Live demo - upload, scan, triage findings, and report from one browser tab.
Scanner - streaming audit terminal pulling the APK from the device and decompiling with JADX
Scanner - live audit log, APK pull and JADX decompile.
Findings - a critical javascript-interface finding with what, impact, exploitation and remediation, plus review actions
Findings - what, impact, exploitation, remediation, with review and AI enrichment.
Attack Paths - an attacker-to-impact exploit-chain graph with per-chain adb and Frida payloads
Attack Paths - exploit chains from entry point to impact, with ready payloads.
MASTG Audit - MASVS categories with per-test pass and fail status and code evidence
MASTG Audit - MASVS categories, per-test pass/fail, code evidence.
File Explorer - the app sandbox with auth_prefs.xml exposing session token, credentials and API key, read over run-as
File Explorer - walk the sandbox and read files over run-as.
File Explorer - an in-browser SQL panel querying the app database and reading the users table
Databases - query the app's SQLite with live SQL in the browser.
Strings - searching tens of thousands of string literals filtered by secret-like, base64, URI-scheme and URL
Strings - search every literal, filtered for secrets and URLs.
APIs - enumerated endpoints, base domains, discovery probes and plain URL literals from the binary
APIs - endpoints, base domains and discovery probes from the binary.
Source - the decompiled source browser showing AndroidManifest.xml with syntax highlighting
Source - decompiled tree with manifest and class viewer.
Agent - issue a device-agent token and see the online agent with its attached USB devices
Remote agent - drive a device over the internet through an analyst-run agent.

Designer-grade output

The report you ship to your client.

Every scan produces a single PDF - pentest-ready, 13 sections, MASVS-mapped. Same evidence, structured for both an executive read and a technical fix-list. No separate exec summary, no template wrangling, no manual screenshotting.

intjector PDF report cover - letter grade, 0 to 100 composite risk score, target metadata and signing fingerprint

Composite score, calibrated.

Letter grade plus a 0-100 score across nine weighted deductions, calibrated for direct comparison so the client knows exactly where the bar is.

Per-finding cards, drop-in for a report.

Each finding renders with F-id, severity chip, CVSS vector, MASTG / MASVS / CWE tags, affected file:line, code snippet, reproduction steps and remediation. Copy-paste into Jira, no editing needed.

Business impact up front.

Every finding pairs what it means for the organisation with the technical evidence behind it - one document that reads for an executive and a fix-list at once, no separate exec summary.

Overview and risk posture page - severity donut, business-impact table and top issues to fix first
Overview - severity donut, business-impact table.
Findings table page - rows of F-001 onward with severity, CVSS and status chips
Findings table - every finding, severity-ordered.
Per-finding detail card - F-001 deeplink-jsbridge-webview with CVSS, MASTG, MASVS, CWE, reproduction and remediation
Per-finding card - full evidence and fix.

Same data exports as JSON, Markdown, or XLSX - pick the shape your client wants.

PDF JSON MD XLSX

Coming soon.

intjector is in private beta. A public build is on the way.