Skip to content
NoHack MobileAndroid · OWASP MASVS

Audit the Android build you actually ship.

Upload an APK. NoHack Mobile decompiles it, maps what it finds to OWASP MASVS, works out which components can be reached from outside the app, and hands you the exact commands to reproduce each finding.

rules in the mobile catalogue
98
rules in the mobile catalogue
OWASP MASWE weaknesses covered
37
OWASP MASWE weaknesses covered
minutes for a standard audit
5–7
minutes for a standard audit
MiB maximum APK size
512
MiB maximum APK size
01

From APK to reproducible finding.

Static analysis first, an agent where judgment is needed.

  1. 01 · upload

    Upload the APK

    The build you ship to users, up to 512 MiB.

  2. 02 · decompile

    Decompile and analyse

    Full decompilation and static analysis, mapped onto a 98-rule catalogue aligned with MASTG v2 and MASVS v2.

  3. 03 · surface

    Map the attack surface

    Which components are reachable from a web link, another app, or the system, and which network endpoints the app talks to.

  4. 04 · review

    Deep review

    Optional: an agent reads the decompiled source from entry points to sinks and verifies what it files, under a per-audit spend cap.

  5. 05 · reproduce

    Reproduce

    Exact adb shell and grep commands built from audit facts, not written by a model, so they run as given.

  6. 06 · compare

    Compare versions

    Diff findings between releases and see what a new build introduced or fixed.

02

Evidence a mobile tester would accept.

Mapped to MASVS

Every rule maps to OWASP MASVS v2 and MASWE weaknesses, with a coverage view of what was and was not tested.

Attack surface

Exported activities, services, receivers, and providers, and how each can be reached from outside the app.

Opt-in

Deep review agent

Reads decompiled code from entry points to sinks for issues static rules miss, with a spend cap per audit.

Reproducible steps

adb commands generated from facts the audit recorded. Paste them into a shell and watch the finding happen.

Version diff

See what changed between two builds, finding by finding.

Evidence export

Export audit logs and findings into your pentest report alongside web and code findings.

03

Commands that run as given.

Reproduction steps attached to a mobile finding.

HighSample finding

Exported transfer screen reachable from any installed app

package
com.acme.wallet 4.12.0
component
.ui.TransferActivity
reachable
another app · no permission required
maps to
MASVS-PLATFORM-1

Reproduce · generated from audit facts

$ grep -n 'TransferActivity' AndroidManifest.xml
41:  <activity android:name=".ui.TransferActivity" android:exported="true">

$ adb shell am start -n com.acme.wallet/.ui.TransferActivity \
    --es to "acct-0001" --es amount "500"
Starting: Intent { cmp=com.acme.wallet/.ui.TransferActivity (has extras) }
NH-M-0412-003sha256:0129…2cb1Android · APK
  • Reachability

    Which component, reachable from where (a web link, another app, or the system), and what permission, if any, stands in the way.

  • Reproduction

    Commands assembled from what the audit recorded, so the package, component, and extras are exact.

  • Standard

    Mapped to OWASP MASVS v2, so the finding drops straight into a mobile pentest report.

04 · Questions

What teams ask before an audit.

Something else? Email us.

Do you support iOS?

Not yet. NoHack Mobile audits Android APKs today. iOS is on the roadmap. App bundles (.aab) need to be built into an APK first.

Do you need our source code?

No. NoHack Mobile works from the compiled APK you ship, the same artifact an attacker would download.

How long does an audit take?

A standard audit takes about 5–7 minutes. The optional deep review adds roughly 5–20 minutes depending on the size of the app.

Security at the speed you ship.

Bring a repository, a web app, or an APK. We will walk you through a real audit of it.