Skip to content

objection

Runtime mobile exploration toolkit powered by Frida for Android and iOS security testing.

Self-hostedNot yet verified
Report issue
GPL-3.0★ 7000Source project only — not browser-runnable

External Tool

This open-source tool is maintained externally. View the source on GitHub to learn more or run it yourself.

Browse developer tools →

What's next with objection?

Choose how you want to get started.

Use it free

Open the official tool or demo — no account needed.

Free

Self-host it

Run the open-source version on your own infrastructure.

Open

What is objection?

objection is an open-source runtime mobile exploration toolkit designed to assess the security of mobile applications without requiring jailbreak or root access. Built on top of Frida, it enables security researchers, penetration testers, and developers to analyze iOS and Android apps for vulnerabilities such as SSL pinning, keychain leaks, and memory-based exploits. The tool addresses the challenge of evaluating mobile app security in environments where traditional rooting methods are impractical or restricted. By leveraging Frida’s dynamic instrumentation capabilities, objection provides deep insights into app behavior, allowing users to inspect runtime processes, modify code execution, and extract sensitive data. Its primary audience includes cybersecurity professionals seeking to identify weaknesses in mobile applications and developers aiming to harden their apps against reverse engineering and exploitation.

How it works

objection is a runtime mobile exploration toolkit powered by Frida, designed to analyze and manipulate mobile applications during execution. It enables security assessments by inspecting app behavior, bypassing security mechanisms, and extracting critical data such as keychains and memory contents. The tool is primarily used to evaluate the security posture of mobile applications, identify vulnerabilities, and test defenses against common attack vectors like SSL pinning and container file system access. It operates without requiring jailbreak or root privileges, making it suitable for environments where such access is restricted. objection supports advanced features such as bypassing SSL pinning to intercept encrypted traffic, dumping keychain data to extract credentials, and inspecting container file systems to analyze app storage. It also allows memory analysis to detect sensitive data leaks and provides scripting capabilities for automating security assessments.

How to use it

  1. 1Install Frida and objection via pip: `pip install frida-tools objection`. 2. Connect to the target device using Frida’s USB or network interface. 3. Launch the app under analysis and use objection commands like `spaghetti` or `lief` to inspect processes. 4. Execute scripts or commands to bypass security measures, such as `ssl-pinning-bypass` for SSL pinning evasion. Practical tips include using Python for custom scripting, ensuring the target device is compatible with Frida, and leveraging objection’s built-in plugins for specific tasks like keychain extraction or memory dumping.

What it can do

  • mobile runtime explorer

Use cases

Assumptions and limitations

Assumptions

  • source: https://github.com/sensepost/objection
  • license: GPL-3.0 — free to use
  • privacy: Self-hosted — you control your data

Limitations

  • Requires Frida-compatible devices, limiting support for newer iOS versions
  • Depends on Frida’s stability, which may have compatibility issues with updated OS versions
  • Cannot bypass advanced anti-debugging or anti-tampering measures in apps
  • Limited GUI interface may require advanced scripting knowledge for automation
  • Potential detection by anti-cheat systems in gaming environments

Understanding the result

Runtime mobile exploration toolkit powered by Frida for Android and iOS security testing.

Tool details

  • Clearly flagged when a network request is needed.
  • No account, no sign-up, and no tracking of your content.
  • Powered by (GPL-3.0).
Built with
(sensepost/objection)
License
GPL-3.0
Runs locally
No — requires a network request
Verification
Not yet verified
Input
Query
Output
Text
Open-source source & license

Built with sensepost/objection. OpenToolVault provides the discovery and browser interface while crediting the original project maintainers.

Built with
License
GPL-3.0
View source on GitHub

Open-source project

License: GPL-3.0Source: this project

OpenToolVault is an independent directory. We are not affiliated with or endorsed by this project.

References

Frequently asked

What is objection and what problems does it solve?

objection is a runtime mobile exploration toolkit that solves security assessment challenges for iOS and Android apps without requiring jailbreak. It addresses issues like SSL pinning, keychain leaks, and memory-based vulnerabilities by providing dynamic instrumentation capabilities through Frida. It enables researchers to analyze app behavior, extract sensitive data, and test defenses against common attack vectors.

How does objection integrate with Frida?

objection leverages Frida’s dynamic code instrumentation to hook into running processes, allowing real-time modification of app behavior. Frida provides low-level access to system calls and memory, while objection abstracts these capabilities into high-level commands and plugins. For example, objection uses Frida’s SSL pinning bypass modules to intercept HTTPS traffic, enabling analysis of encrypted communications without requiring app modifications.

How do I bypass SSL pinning using objection?

To bypass SSL pinning, use the `ssl-pinning-bypass` plugin. First, connect to the target device with Frida, then run `objection -g <package_name> ssl-pinning-bypass`. This injects a Frida script that intercepts SSL handshake operations, allowing interception of unencrypted traffic. Note that this requires the app to be running in a debuggable state and may fail if the app uses advanced pinning techniques like certificate pinning with custom trust stores.

How does objection compare to Frida or other mobile analysis tools?

objection extends Frida’s capabilities with higher-level plugins and automation for common security tasks. Unlike Frida, which requires manual scripting, objection provides pre-built modules for tasks like keychain extraction or memory dumping. It differs from tools like MobSF (Mobile Security Framework) by focusing on runtime analysis rather than static code analysis. Alternatives like Fridump or iHaxor offer similar functionality but lack objection’s integrated plugin ecosystem.

How do I troubleshoot connection issues with objection?

Connection issues often stem from incompatible Frida versions or device compatibility. Verify that the Frida version matches the target OS (e.g., iOS 14.4 requires Frida 12.12.11). Ensure the device is in developer mode and USB debugging is enabled. If using a network connection, check that the device’s IP address is correctly configured and that Frida’s server is running. Use `frida-ps -U` to list active processes and confirm the target app is accessible.

Spotted something wrong with objection, or want to maintain it? See how to help.