First find which layer rejected the connection
Android Network Security Configuration can set trust anchors and certificate pins for the whole app or one domain. OkHttp can also pin certificates in code with CertificatePinner. An app may use a custom trust manager, native TLS, Cronet or a protection SDK instead. Each path fails at a different point.
We inspect the manifest, network security XML, HTTP client setup and native libraries. Runtime errors show whether the failure came from certificate trust, hostname checks, pin matching, client certificates or a later application response.
A proxy can miss traffic without pinning
The app may ignore the system proxy, use QUIC, open a raw socket or send traffic from native code. Android apps targeting newer platform rules also do not trust user-added certificate authorities by default. We check routing and protocol before treating every empty Burp history as a pinning problem.
Capture at the request boundary
The useful point is where the app has finished building the request and before the network stack encrypts it. Depending on the APK, that can be an OkHttp interceptor, a serializer, a JNI call or a socket write. We join this runtime evidence with static code so every field has a source and every response has a parser.
What you receive
The full APK becomes a callable API in Python and JavaScript/TypeScript with an importable Postman collection. We include every discovered host and workflow, along with authentication, signatures, encryption and decryption, sessions and protocol handling.
Sources
Reviewed 30 August 2026 · SReverse research desk