Mobile Application Security
Practical Android and iOS assessments that uncover weaknesses before they become product risk.
- SSL pinning and traffic controls
- Root and jailbreak detection
- Signature and integrity validation
Mobile Application Security Consultant
I help product and security teams assess Android and iOS applications, reverse complex protections, analyze encrypted traffic, and build custom testing automation.
Based in Bangladesh · Working with teams worldwide
Services
From focused research to repeatable testing tools, I help teams understand how their mobile products behave under real scrutiny.
Practical Android and iOS assessments that uncover weaknesses before they become product risk.
Deep application analysis for teams that need to understand protected, obfuscated, or undocumented behavior.
Custom tooling that turns repeatable security checks into faster, more reliable workflows.
Focused investigation of mobile traffic, suspicious behavior, and artifacts across the application stack.
Technical capabilities
Tools and disciplines developed through consulting, independent research, and open-source development.
Selected work
Open-source work covering Android integrity, Frida automation, root detection, and encrypted traffic analysis.
View GitHub profileAdvanced bypass technique for Android security mechanisms including signature verification and integrity checks. Tested on latest Android SDK versions with full hook implementation.
Automated Frida script generation tool for bypassing signature verification in Android applications. Supports multiple certificate formats and custom hook generation.
Comprehensive Frida script for bypassing root detection mechanisms in Android apps. Intercepts native and Java-based checks with system property spoofing.
SSL pinning bypass techniques using Frida for security testing. Includes anti-Frida detection bypass and YouTube tutorial demonstrations.
Platform research
Transport security, client attestation, and automation research presented with the same technical depth as the wider toolset.
2 research projects
Network Security
Frida script and pre-patched APK bypassing SSL/TLS certificate pinning in the Snapchat Android app, covering OkHttp, Android TrustManager, and native OpenSSL validation.
Reverse Engineering
Reverse engineering research into Snapchat's Argos client-attestation system (the x-snapchat-att-token/x-snapchat-att-sign headers), tracing the Java-to-native JNI bridge through to the gRPC backend. Educational research only — not a working token generator.
2 research projects
Automation
Automation tool for Tinder profile management and API interaction. Built for research purposes in social media automation.
Network Security
Frida script bypassing SSL certificate pinning, proxy detection, and anti-debugging checks in the Tinder Android app across OkHttp3, Volley, and custom trust-manager implementations.
Project archive
Filter the remaining projects by discipline, then expand an entry for the complete details.
3 projects shown
DEX file extraction and dumping utility using Frida for Android reverse engineering and analysis.
Frida-based iOS SSL bypass with real-time traffic monitoring capabilities for mobile security testing.
Python tool for extracting Protocol Buffer schemas from iOS IPA files for reverse engineering analysis.
Experience
Independent research, client consulting, community education, and open-source development since 2018.
Created comprehensive mobile security research platform. Developed tutorials and tools for Android security testing, SSL bypass techniques, and reverse engineering. Built community of security researchers through YouTube, Telegram, and Reddit.
Provided specialized mobile application security testing services. Conducted penetration testing on Android and iOS applications. Developed custom automation tools for security testing and digital forensics.
Developed and maintained multiple open-source security tools including Frida scripts for Android bypasses, DEX analysis tools, and signature verification bypass utilities. Active contributor to mobile security research community.
About
As a cybersecurity specialist with deep expertise in mobile security and reverse engineering, I focus on identifying vulnerabilities in mobile applications and developing robust security solutions. My work involves analyzing malware, bypassing security mechanisms, and ensuring the integrity of mobile ecosystems.
I have extensive experience with ARM assembly analysis, Android APK dissection, and iOS binary analysis. My passion lies in understanding how systems work at the lowest level and finding creative ways to enhance their security.
I also create open-source security tools and share mobile security research and reverse-engineering tutorials through Reversesio, YouTube, Telegram, and Reddit.
Start a conversation
I’m available for focused assessments, reverse-engineering research, custom security tooling, and technical collaborations. Telegram is the fastest way to reach me.