Certificate pinning bypass
SkillMonitoring & opsBypass TLS certificate pinning so you can proxy a mobile app's traffic. Load when a proxy shows no/broken traffic, you see SSL handshake failures in logs, OkHttp CertificatePinner, TrustKit, or "the app won't connect through Burp". Android/iOS.
Instructions available. Your AI can read the instructions. Execution depends on the setup they require.
Account requirements not reviewed. Check the skill instructions before use; ahel provides instructions and does not run this skill.
Add ahel to your AI once: Claude, ChatGPT, Cursor, Claude Code or Codex. Then ask it to use this.
Then ask your AI: use the Certificate pinning bypass skill
What this skill tells your AI
The instructions your AI receives, as published by noorqureshi/sploitagent in skills/mobile/mobile-cert-pinning-bypass/SKILL.md and read by ahel’s review.
When it applies
The app pins its server cert, so a normal MITM proxy (Burp/mitmproxy) can't decrypt its traffic — you get handshake errors and empty history. You need to test the backend, so the pin has to go.
Why it works
Pinning is enforced in the client you control. At runtime you can replace/neutralize the verification routine; statically you can patch it out. Either way the app then trusts your proxy's CA.
Method
- Install your CA first: add Burp/mitmproxy CA to the device (Android 7+ needs it as a
system cert, or use a
network_security_configon a repackaged app). - Runtime (fastest):
objection -g <pkg> explorethenandroid sslpinning disable(iOS:ios sslpinning disable), or a Frida script (frida-multiple-unpinning). - Static patch (when Frida is blocked):
apktool d, remove/patch theCertificatePinner/ TrustManager checks or swapnetwork_security_configto trust user CAs, rebuild + resign (apktool b,uber-apk-signer). - Confirm: traffic now appears decrypted in the proxy; proceed to backend testing.
Gotchas
- No traffic at all (not just pinning) can mean the app uses a non-HTTP protocol or a VPN — check.
- Some apps double-pin or detect Frida/root — combine root-detection bypass, or use static patching.
- iOS on a non-jailbroken device needs a repackaged/sideloaded app or a jailbroken test device.
Verify success
The proxy shows plaintext requests/responses from the app; you can now replay/modify them.
References
OWASP MASTG (network); objection & frida-multiple-unpinning; TrustKit/OkHttp docs.
Signals
- GitHub stars
- 20
- Forks
- 7
- Last commit
- Sep 2026
Advanced
- Item type
- skill
- Key
mobile-cert-pinning-bypass- Source
- github.com/noorqureshi/sploitagent
github.com/noorqureshi/sploitagent
Related picks
Skill · davila7
The pick for Web (OWASP)owasp-web
Skill · nahid-sparktales
The pick for Web (OWASP)internal-comms
Skill · anthropics
More in Monitoring & opsagent-eval
Skill · affaan-m
More in Monitoring & opsarchitecture-decision-records
Skill · affaan-m
More in Monitoring & opsbabysit
Skill · thedotmack
More in Monitoring & ops