TrustRadius: an HG Insights company

Mobile Security Framework (MobSF)

Score8 out of 10

1 Reviews and Ratings

What is Mobile Security Framework (MobSF)?

Mobile Security Framework (MobSF) is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis. MobSF support mobile app binaries (APK, IPA & APPX) along with zipped source code and provides REST APIs for integration with CI/CD or DevSecOps pipeline. The Dynamic Analyzer helps you to perform runtime security assessment and interactive instrumented testing.

MobSF gives you piece of mind for a price that can't be beat

Use Cases and Deployment Scope

We have a staff app that we use to scan and redeem electronic vouchers that our members earn through casino gameplay. This scanning is deployed through payment devices that are managed by a third party. They require that our app pass through a stringent security check. MobSF is one of the few accepted penetration testing software.

Pros

  • Scan for vulnerabilities
  • Scan for bad coding
  • Give suggestions on fixes for security issues

Cons

  • The UI is not that user friendly
  • The documentation could be easier to understand
  • An easier method of deploying MobSF would be appreciated

Most Important Features

  • Security scan of the app code
  • Suggestions on the fixes in the vulnerabilities in the code
  • The detailed downloadable report that it generates after the scan

Return on Investment

  • It has allowed our apps to pass a security vetting requirement of a third party to deploy our app
  • We can see where we can improve on the development of our app
  • The deployment can take a while, especially with teams not familiar with the software

Alternatives Considered

SonarQube

Other Software Used

SonarQube, Adobe Acrobat Reader DC, Android Studio