Quickly identify vulnerabilities and mitigate risks, keeping your business and client’s data secure
Mobile development teams are under tremendous amount of stress. This can result in applications being released with security flaws and vulnerabilities that can have an enormous impact on both the company and the consumers of the application. Identifying these vulnerabilities can be time consuming and expensive.
Seecra AppScanner performs fully automated application analysis of Android & iOS apps in order to detect vulnerabilities to hacking, data leaks, malicious code and other weaknesses
Fully automated, Quick & Efficient
Seecra AppScanner is a powerful security analysis tool designed to automatically scan applications to detect vulnerability to hacking, data leaks, malicious code, and other weaknesses. Both internally developed and external applications (used in BYOD) can be analyzed, allowing organizations to protect their employees and IT assets from external threats.
Seecra AppScaner fast and accurate scans enable organizations to analyze every new version of all applications that they distribute to their customers. Modules developed by subcontractors and 3rd party libraries can also be scanned to detect any potential security issues that could affect their customers. By scanning all new revisions, Seecra AppScanner lets you identify possible regressions on time, which also saves development costs and resources.
Its fully automated scan process means that Seecra AppScanner can be used to aid the application vetting of internal and public app stores. It provides a comprehensive yet simple overview of all scanned applications that could be used to integrate with existing solutions. It does not require any deep and costly expertise to conduct scans and interpret their results.
All kinds of apps can be analyzed, the source code is not required
Multiple in-depth analysis of the latest mobile security vulnerabilities
No deep expertise required, Seecra AppScanner can be scaled up to x000 scans/year
Seecra AppScanner is available via cloud or can be installed on your premise
Seecra AppScaner combines bleeding-edge static and dynamic analysis techniques developed by World leading research. It operates on Android bytecode and does not require the source code of an application. Users can choose whether they want to manually interact with the application in the test environment or whether the analysis should run fully automatically and unassisted.
In a first preparatory step, an app’s meta data is assessed, revealing information about the application’s permissions, components, and structure. Information gathered in this step sets the scope for the following static analysis.
Static analysis investigates the bytecode and structure of an application withouth executing it. Seecra AppScanner features a highly efficient bidirectional data flow tracing, revealing unwanted data flows which can impose violations of security and privacy requirements. Threats to data integrity and secrecy such as SQL injections or unprotected Intents will be identified in this step.
Static analysis investigates the bytecode and structure of an application withouth executing it. Seecra AppScanner features a highly efficient bidirectional data flow tracing, revealing unwanted data flows which can impose violations of security and privacy requirements. Threats to data integrity and secrecy such as SQL injections or unprotected Intents will be identified in this step.
Instrumentation makes slight modification to the app in order to extract specific information from it in a hybrid static/dynamic analysis. Guided by potential findings from the static analysis step, specific versions of the app are crafted which automatically jump to relevant parts and provide meaningful information when executed.
Guided by knowledge gained from static analysis and modifications injected by instrumentation, World leading hybrid analysis engine investigates the app’s runtime behavior under specific security-relevant conditions and ensures that critical parts of the app are executed and observed. Tracing of individual function calls and register values allow deep insights into the app’s behavior. The hybrid engine attempts to provoke execution of vulnerable code fragments and records encrypted traffic in plaintext, allowing inspection for private information.
Seecra AppScaner presents its most relevant findings in a clearly structured overview. A drill-down into detailed analysis results and raw data of the analysis is possible. All analysis results are stored in Seecra AppScanner and can be retrieved at a later time. In addition, a signed report document can be downloaded.