Back to updates
New releaseSep 9, 2026

mobileAudit v3.2.0

Django application that performs SAST and Malware Analysis for Android APKs

Share

Mobile Audit

Security analysis for Android APKs, from upload to actionable findings.

Mobile Audit is a Django application for static application security testing and malware inspection. It extracts APK metadata, detects risky implementation patterns, organizes findings by severity, and provides a focused workspace for review and reporting.

Application dashboard with scan summaries

Get started

Docker Compose runs the complete local stack: Django, PostgreSQL, RabbitMQ, Celery, and Nginx.

docker compose build
docker compose up

Open http://localhost:8888 when the services are ready.

To run in the background or stop the stack:

docker compose up -d
docker compose down

Before using Mobile Audit outside a local environment, replace the example secret, database credentials, and administrator credentials in .env.example.

Core capabilities

AreaWhat Mobile Audit provides
APK inspectionApplication metadata, components, permissions, certificates, strings, databases, and files
Static analysisConfigurable SAST rules with CWE and Mobile Top 10 mappings
Malware checksDomain checks against MalwareDB and Maltrail sources
Finding managementSeverity summaries, detailed evidence, editing, and false-positive triage
IntegrationsOptional VirusTotal inspection and DefectDojo export
ReportingPDF exports plus a token-authenticated REST API

Interface tour

Application workspace

Review an application's scan history and compare how its finding count changes between APK versions.

Application detail workspace with findings chart

Scan analysis

Move from the security summary into application metadata, permissions, components, findings, certificates, strings, files, and databases.

Scan analysis overview

The interface uses Bootstrap 5 and native JavaScript. Navigation, live table filtering, sorting, pagination, confirmations, and scan status updates do not require jQuery.

Analysis workflow

  1. Create an application workspace.
  2. Upload an APK and start a scan.
  3. Review severity totals and inspect the supporting evidence.
  4. Triage findings, export a PDF report, or use an integration.

Analysis rules can be enabled or disabled from the Patterns screen. Some hardcoded patterns are derived from apkleaks.

Architecture

Mobile Audit architecture

ServiceResponsibility
Django 5.2 LTSWeb application and REST API
PostgreSQL 16Persistent application data
CeleryBackground APK analysis
RabbitMQ 4.2Task broker
NginxHTTP or TLS entry point

The application runtime uses Python 3.12. APK decompilation is provided by JADX.

API

Request a token:

POST /api/v1/auth-token/

Authenticate subsequent requests:

Authorization: Token <api-key>
DocumentationPath
Swagger UI/swagger/
ReDoc/redoc/
OpenAPI JSON/swagger.json
OpenAPI YAML/swagger.yaml

Optional integrations

The following features are disabled by default and configured through .env.example:

  • VirusTotal API v3 lookups and optional uploads
  • DefectDojo API v2 finding exports
  • MalwareDB and Maltrail domain checks

Enable only the services for which you have valid endpoints and credentials.

TLS

Place the certificate and private key in nginx/ssl, then start the TLS configuration:

docker compose -f docker-compose.prod.yaml up -d

The application will be available at https://localhost.

For local testing, generate a one-day self-signed certificate:

openssl req -x509 -nodes -days 1 -newkey rsa:4096 \
  -subj "/C=ES/ST=Madrid/L=Madrid/O=Example/OU=IT/CN=localhost" \
  -keyout nginx/ssl/nginx.key \
  -out nginx/ssl/nginx.crt

Project resources

Categories