AppSecNews
Mobile Security Open source Established

Objection

by SensePost

Runtime mobile exploration toolkit built on dynamic instrumentation, offering common iOS and Android assessment tasks as ready made commands.

Visit github.com (leaves AppSecNews, opens in a new tab) Leaves AppSecNews for the vendor's own site.

No endorsements yet

Run Objection in production? A named recommendation helps the next team shortlisting it.

Recommend this tool

Endorsers verify their identity through LinkedIn. Titles and companies are self declared, shown as they were when each person signed, and reviewed by an editor before anything is published. Endorsements are never paid for.

What we still need to verify : 1 point in this profile is not yet confirmed against vendor documentation.
  • Current command coverage on recent iOS and Android releases: confirm against project docs

Treat these points as unconfirmed. They are open items in the catalog's verification queue, and this note stays until each is checked against the vendor's documentation.

What it does

Objection is a command driven front end over a dynamic instrumentation engine. Everything it does is instrumentation of a running process, but instead of asking you to write hooking scripts it packages the tasks a mobile assessor repeats into an interactive shell with tab completion and filesystem style navigation. You attach to a running application and issue commands.

The command set follows the standard assessment path. On Android it lists activities, services and receivers, starts exported components directly, dumps sandboxed storage, reads shared preferences and SQLite databases, and disables root detection and certificate pinning with bundled hooks covering common libraries. On iOS it dumps the keychain, inspects property lists and the application bundle, walks the filesystem, enumerates Objective C classes and methods, and applies its own pinning bypass. Both platforms support memory dumping and hooking a method to watch or change arguments and return values. The other significant capability is patching: Objection repackages an APK or IPA with an instrumentation gadget embedded, so you can do runtime work on a device that is not rooted or jailbroken.

Where it fits

This runs on a tester's workstation against a test device or emulator, during hands on assessment. It is the tool you reach for immediately after decompiling an app statically, to confirm what the code suggested: whether that database really is unencrypted, whether pinning really is enforced, whether an exported activity really is reachable. Because it exposes ready commands rather than an API, it also lowers the barrier for developers who want to check their own app's runtime behavior without learning instrumentation programming.

Strengths

  • Turns routine assessment tasks into single commands, removing repetitive scripting from every engagement.
  • Bundled pinning and root detection bypasses handle the common library cases immediately, which unblocks traffic interception fast.
  • Application patching with an embedded gadget means runtime analysis on non rooted devices, and one command vocabulary covers both platforms.

Limitations

  • It inherits every weakness of the instrumentation layer beneath it. Applications that detect hooking detect Objection faster, because its behavior is well known and easy to fingerprint.
  • The bundled bypasses cover common implementations only. Custom or hardened pinning defeats them and pushes you back to writing your own hooks.
  • Convenience commands lag platform changes. New operating system releases break parts of the command set until the project catches up, and failures are not always clearly reported.

Who it suits

Mobile penetration testers moving quickly through routine runtime checks, and developers validating their own app's storage and transport behavior. Anyone doing novel research or facing a hardened target will write custom instrumentation anyway and should treat Objection as a starting point.

Used Objection? Recommend it under your own name and title.

Recommend this tool