Skip to content

Frida and Dynamic Analysis

Frida is the central tool of dynamic mobile pentesting: an instrumentation toolkit that injects JavaScript into a running app’s process, letting you intercept and modify function calls, read and change variables in memory, bypass checks (root/jailbreak detection, SSL pinning), and understand what the app does internally in real time. It’s what turns “reading the code” into “controlling the app while it runs.”

- Hooking: intercept any function (native, Java, Objective-C/Swift) before/after it runs
- Read/modify arguments, return values, and variables in memory
- Call the app's internal functions from outside
- Bypass checks: root/jailbreak detection, SSL pinning, anti-debugging
- Dump secrets, encryption keys, decrypted data from memory
# on the computer
pip install frida-tools
# on the device
# Android (root): a frida-server matching the version; run it
adb push frida-server /data/local/tmp/ ; adb shell "/data/local/tmp/frida-server &"
# iOS (jailbreak): install Frida from Cydia/Sileo
# list processes/apps
frida-ps -U # device processes (USB)
frida-ps -Ua # installed apps

Objection wraps Frida with ready-made commands for the most common tasks:

objection -g com.target.app explore
# inside:
android hooking list classes # list classes
android hooking watch class com.target.Crypto # watch a class
android sslpinning disable # bypass SSL pinning
android root disable # bypass root detection
android keystore list ; ios keychain dump # secrets
memory search / dump # search memory

Objection is the starting point; for specific logic you write Frida scripts.

# Android (Java): hook a method and see/change its behavior
Java.perform(function() {
var Login = Java.use("com.target.LoginManager");
Login.checkPassword.implementation = function(pw) {
console.log("entered password: " + pw); // intercept
return true; // force login OK
};
});
# iOS (Objective-C): hook a method
Interceptor.attach(ObjC.classes.LoginManager["- isValid:"].implementation, {
onEnter: function(args) { ... },
onLeave: function(ret) { ret.replace(0x1); } // force true
});
# run the script
frida -U -f com.target.app -l script.js --no-pause
# bypass client-side protections (which should NEVER be the only security)
- SSL pinning bypass (see mob-ssl)
- root/jailbreak detection bypass
- biometrics / local PIN bypass
# extract secrets at runtime
- encryption keys, decrypted data, tokens in memory
# understand/force logic
- change return values (isPremium -> true), skip validations
# discover the internal flow and feed the backend attack

Detection and anti-Frida (what you’ll see)

Section titled “Detection and anti-Frida (what you’ll see)”

Some apps detect Frida (ports, thread names, frida-gadget) or use anti-debugging. It can be evaded (anti-anti-Frida scripts, rename frida-server, gadget), but remember: these protections raise the cost, they don’t replace backend security.

  • Don’t trust client-side checks (pinning, root/jailbreak, local biometrics): an attacker with Frida bypasses them. Real security is in the backend.
  • RESILIENCE (MASVS): instrumentation/Frida detection, anti-debugging, code integrity, obfuscation — as layers that raise the cost, not an absolute barrier.
  • Minimal sensitive data in memory/client; encryption with non-extractable keys (hardware-backed keystore/Secure Enclave).
  • Assume the device can be compromised: always validate and authorize on the server.
  • frida-server/gadget running and app detected (frida-ps)
  • Objection: explore, list classes, basic hooks
  • Bypass SSL pinning (SSL Pinning and Bypass) and root/jailbreak detection
  • Custom hooks: intercept key arguments/returns
  • Extract secrets/keys/decrypted data from memory
  • Force logic (isPremium, validations, login)
  • Evade anti-Frida if the app implements it
  • Use what’s learned to attack the backend (Web section)