AppSecNews
Mobile Security Freemium Growing

Ostorlab

by Ostorlab

Mobile application scanner that pairs static binary analysis with instrumented dynamic testing on an extensible agent based engine.

Visit ostorlab.co (leaves AppSecNews, opens in a new tab) Leaves AppSecNews for the vendor's own site.

No endorsements yet

Run Ostorlab in production? A named recommendation helps the next team shortlisting it.

Recommend this tool

Endorsers verify their identity through LinkedIn. Titles and companies are self declared, shown as they were when each person signed, and reviewed by an editor before anything is published. Endorsements are never paid for.

What we still need to verify : 3 points in this profile are not yet confirmed against vendor documentation.
  • Exact CI/CD and ticketing integration list: confirm against vendor docs
  • Self-hosted or on-premise deployment options: confirm
  • Scope of the free tier versus paid tiers: confirm

Treat these points as unconfirmed. They are open items in the catalog's verification queue, and this note stays until each is checked against the vendor's documentation.

What it does

Ostorlab analyzes compiled mobile applications rather than source. You hand it an Android APK or AAB or an iOS IPA and it unpacks the archive, decompiles Dalvik bytecode or parses the Mach-O binary, and reads the manifest and entitlements. Static checks cover exported components and intent handling, insecure transport configuration, weak cryptographic calls, hardcoded credentials, debuggable and backup flags, and known vulnerable libraries shipped inside the bundle. Dynamic analysis installs the build on an instrumented device or emulator, exercises it, and watches network traffic, file writes and inter-process calls to catch cleartext transmission, broken certificate validation and secrets landing in readable storage.

The engine underneath is agent based. Ostorlab publishes OXO, an open source orchestrator in which each analyzer runs as an independent containerized agent and findings flow between agents over a message bus. Agents can wrap external scanners or implement checks directly, so one submitted binary can fan out into backend host discovery and API probing as well as app analysis.

Where it fits

This is a build artifact gate, not an editor plugin. The natural place is the pipeline step that produces a signed APK or IPA, with the CLI submitting the artifact and failing the job above a chosen severity. Security teams also run it out of band against published store builds. It needs a real build, so it says nothing before code compiles, and triage still needs someone who can read decompiled output and judge reachability.

Strengths

  • Works on the shipped artifact, catching issues introduced by build tooling and bundled SDKs that source-only review never sees.
  • The agent architecture is genuinely open, so you can add checks or reuse existing scanners instead of waiting on a vendor roadmap.
  • Covers the app and the backend surface it talks to in one scan rather than treating them as two separate exercises.
  • Store monitoring gives visibility into apps published outside your pipeline.

Limitations

  • Automated dynamic crawling reaches only the screens it can drive, so flows behind login, payment or hardware dependencies stay untested unless you supply credentials and scripting.
  • Findings are reported against decompiled code, which makes remediation guidance less precise than a source scanner pointing at a line in your repo.
  • Smaller vendor than the incumbent mobile testing suites, so enterprise workflow needs such as SSO, ticketing and reporting deserve a close look.

Who it suits

A good fit for teams shipping mobile releases continuously who want an automated check on every release candidate without running a device lab, and for consultancies needing repeatable triage on client binaries. Less suitable if you want source-level remediation guidance inside the developer workflow, or if your real requirement is runtime protection of a shipped app rather than pre-release testing.

Used Ostorlab? Recommend it under your own name and title.

Recommend this tool