SReverseby Simpa Labs

Network analysis · Hidden traffic

Android certificate pinning and missing proxy traffic analysis

When Burp shows no useful request, we identify the real network stack and capture the data where the app creates it.

First find which layer rejected the connection

Android Network Security Configuration can set trust anchors and certificate pins for the whole app or one domain. OkHttp can also pin certificates in code with CertificatePinner. An app may use a custom trust manager, native TLS, Cronet or a protection SDK instead. Each path fails at a different point.

We inspect the manifest, network security XML, HTTP client setup and native libraries. Runtime errors show whether the failure came from certificate trust, hostname checks, pin matching, client certificates or a later application response.

A proxy can miss traffic without pinning

The app may ignore the system proxy, use QUIC, open a raw socket or send traffic from native code. Android apps targeting newer platform rules also do not trust user-added certificate authorities by default. We check routing and protocol before treating every empty Burp history as a pinning problem.

Capture at the request boundary

The useful point is where the app has finished building the request and before the network stack encrypts it. Depending on the APK, that can be an OkHttp interceptor, a serializer, a JNI call or a socket write. We join this runtime evidence with static code so every field has a source and every response has a parser.

What you receive

The full APK becomes a callable API in Python and JavaScript/TypeScript with an importable Postman collection. We include every discovered host and workflow, along with authentication, signatures, encryption and decryption, sessions and protocol handling.

Reviewed 30 August 2026 · SReverse research desk

One full APK. One complete delivery.

Projects start at $120. Most are delivered in 24 to 72 hours.

Every format included

Python, JavaScript/TypeScript, Postman and complete API documentation cover the same full endpoint set. Your team runs the clients in its own server or system.

Ready in 24–72 hours

The delivery window starts after we receive the APK and any account access needed to run it. The fixed quote states the deadline. Most projects finish sooner.

Deployment checked before the quote

The package includes signing, encryption, decryption and session handling. We verify device-bound keys and server integrity checks during review and document runtime requirements before you commit.

30 days of fixes

Report a defect within 30 days of delivery. We fix any delivered call that does not match the tested APK at no extra cost.

Start your full APK reconstruction

Send the full APK

Projects start at $120. Choose WhatsApp or email, then attach the APK in the app that opens. We reply within one hour with the next step and send the fixed quote after review.

Want us to contact you?