# mobileaudit | Mónica Pastor | Knowledge Base | Instagit

Django application that performs SAST and Malware Analysis for Android APKs

GitHub Stars: 224

Repository: https://github.com/mpast/mobileaudit

---

## Articles

### [MobileAudit APK Analysis Process: From File Upload to Security Findings Generation](/mpast/mobileaudit/what-happens-during-the-apk-analysis-process-from-file-upload-to-findings-generation)

Discover the MobileAudit APK analysis process. Learn how file uploads are hashed decompiled and pattern matched to generate security findings in this 15-step static analysis pipeline.

- Tags: how-to-guide
- Published: 2026-03-07

### [How MobileAudit Implements Django Authentication System for User Management](/mpast/mobileaudit/how-does-the-django-authentication-system-handle-user-registration-login-and-profile-management)

Learn how MobileAudit uses Django authentication for secure user registration, login, and profile management. Explore custom models and modular forms for efficient user handling.

- Tags: deep-dive
- Published: 2026-03-07

### [Recommended Settings and Security Considerations for Production Deployment in Mobile Audit](/mpast/mobileaudit/what-are-the-recommended-settings-and-security-considerations-for-production-deployment)

Deploy Mobile Audit to production securely. Learn recommended settings like ENV=PROD and DEBUG=0, plus PostgreSQL, Nginx TLS, secure cookies, and hardened HTTP headers for robust security.

- Tags: best-practices
- Published: 2026-03-07

### [How the Celery Worker Updates Scan Progress State During APK Analysis in MobileAudit](/mpast/mobileaudit/how-does-the-celery-worker-update-scan-progress-state-during-the-analysis-process)

Learn how the Celery worker updates scan progress state in MobileAudit during APK analysis. Discover how task states and meta dictionaries track progress for clear visibility.

- Tags: internals
- Published: 2026-03-07

### [What Logging Framework Is Used in MobileAudit and How Celery Worker Errors Are Tracked](/mpast/mobileaudit/what-logging-framework-is-used-and-how-are-celery-worker-errors-tracked)

Discover how MobileAudit uses the Python logging library and tracks Celery worker errors through explicit exception handling and persistent task state.

- Tags: internals
- Published: 2026-03-07

### [How to Add Custom SAST Patterns in MobileAudit: Complete Guide to the Pattern Engine](/mpast/mobileaudit/how-do-i-add-custom-sast-patterns-or-modify-existing-ones-in-the-pattern-engine)

Learn how to add custom SAST patterns in the MobileAudit pattern engine by modifying the Pattern database model at runtime. Enhance your security analysis today.

- Tags: how-to-guide
- Published: 2026-03-07

### [Data Model Relationships in MobileAudit: Applications, Scans, Findings, and Metadata Explained](/mpast/mobileaudit/what-is-the-data-model-relationship-between-applications-scans-findings-and-their-associated-metadata)

Understand the MobileAudit data model relationships between Applications, Scans, Findings, and metadata. Learn how Django ORM structures this hierarchy for clear data organization.

- Tags: internals
- Published: 2026-03-07

### [How MobileAudit Checks for Malware Domains Using MalwareDB and Maltrail Databases](/mpast/mobileaudit/how-does-mobileaudit-check-for-malware-domains-using-malwaredb-and-maltrail-databases)

Learn how MobileAudit identifies malware domains by checking APK extracted URLs against MalwareDB and Maltrail databases for enhanced security.

- Tags: how-to-guide
- Published: 2026-03-07

### [Mobile Audit REST API Endpoints and Authentication Guide](/mpast/mobileaudit/what-are-the-available-api-endpoints-and-how-do-i-authenticate-using-the-apiv1authtoken-endpoint)

Access Mobile Audit REST API endpoints using token authentication. Learn how to get your auth token and interact with CRUD operations for applications, scans, findings, and permissions.

- Tags: api-reference
- Published: 2026-03-07

### [How to Start MobileAudit Locally Using Docker Compose: Complete Development Setup Guide](/mpast/mobileaudit/how-do-i-start-mobileaudit-locally-using-docker-compose-with-the-development-configuration)

Start MobileAudit locally with Docker Compose. Clone the repo, build images, and run the development setup for instant access to the security scanner dashboard at localhost:8888.

- Tags: getting-started
- Published: 2026-03-07

### [MobileAudit Severity Levels Explained: Critical, High, Medium, Low, and None](/mpast/mobileaudit/what-severity-levels-critical-high-medium-low-none-are-used-for-categorizing-findings)

Understand MobileAudit severity levels Critical High Medium Low and None for classifying security findings. Learn how this Django TextChoices enumeration standardizes vulnerability reports.

- Tags: deep-dive
- Published: 2026-03-07

### [How MobileAudit Extracts and Analyzes APK Components: A Technical Deep Dive](/mpast/mobileaudit/how-does-mobileaudit-extract-and-analyze-apk-components-activities-services-permissions-certificates)

Discover how MobileAudit extracts and analyzes APK components like activities, services, and certificates using Androguard and Celery. Get a technical deep dive into security analysis.

- Tags: deep-dive
- Published: 2026-03-07

### [Understanding the MobileAudit Docker Compose Architecture: Web, Worker, and Service Interactions](/mpast/mobileaudit/what-is-the-docker-compose-architecture-and-how-do-the-web-worker-db-rabbitmq-and-nginx-services-interact)

Explore the MobileAudit Docker Compose architecture. Understand how Nginx, Django web, Celery workers, RabbitMQ, and PostgreSQL services interact to manage audit data and tasks.

- Tags: architecture
- Published: 2026-03-07

### [How to Triage Findings in MobileAudit: Mark False Positives and Adjust Severity Levels](/mpast/mobileaudit/how-do-i-perform-findings-triage-to-mark-false-positives-and-change-severity-levels)

Learn to triage findings in MobileAudit by marking false positives and adjusting severity levels. Use the web interface or Django ORM for efficient management.

- Tags: how-to-guide
- Published: 2026-03-07

### [MobileAudit Environment Variables: Complete Configuration Guide for settings.py](/mpast/mobileaudit/what-environment-variables-are-required-and-how-are-they-loaded-in-appconfigsettings.py)

Master MobileAudit environment variables in settings.py. Learn how this app configures runtime settings via env() for seamless deployment without code changes.

- Tags: how-to-guide
- Published: 2026-03-07

### [How MobileAudit Generates and Exports PDF Scan Reports: A Technical Deep Dive](/mpast/mobileaudit/how-does-mobileaudit-generate-and-export-pdf-scan-reports-from-analysis-results)

Learn how MobileAudit generates and exports PDF scan reports. Discover the technical process involving Django templates, pdfkit, and wkhtmltopdf for seamless report delivery.

- Tags: deep-dive
- Published: 2026-03-07

### [How to Configure TLS/SSL with Nginx Reverse Proxy for Production Deployment in MobileAudit](/mpast/mobileaudit/how-do-i-configure-tls-ssl-with-nginx-reverse-proxy-for-production-deployment)

Secure your MobileAudit production deployment by configuring TLS/SSL with Nginx reverse proxy. Follow our guide to generate certificates and set up secure HTTPS in minutes.

- Tags: how-to-guide
- Published: 2026-03-07

### [How Token-Based REST API Authentication Works in MobileAudit: A Complete Guide](/mpast/mobileaudit/how-does-the-token-based-rest-api-authentication-work-and-what-endpoints-require-authorization)

Explore token-based REST API authentication in MobileAudit. Learn how to get and use auth tokens for secure access to write operations and protected endpoints.

- Tags: api-reference
- Published: 2026-03-07

### [How MobileAudit's Pattern Engine Detects Vulnerabilities and Malicious Code in Decompiled APKs](/mpast/mobileaudit/how-does-mobileaudits-pattern-engine-detect-vulnerabilities-and-malicious-code-in-decompiled-apks)

Discover how MobileAudit's pattern engine effectively detects vulnerabilities and malicious code in decompiled APKs by applying custom regex to source code. Improve your security analysis.

- Tags: deep-dive
- Published: 2026-03-07

### [MobileAudit Database Models: Application, Scan, Finding, Pattern, and Certificate Explained](/mpast/mobileaudit/what-are-the-main-database-models-scan-application-finding-pattern-certificate-and-their-relationships)

Understand the MobileAudit database models: Application, Scan, Finding, Pattern, and Certificate. Learn their relationships and how they form a security assessment workflow.

- Tags: api-reference
- Published: 2026-03-07

### [How to Integrate MobileAudit Findings with DefectDojo Using API v2](/mpast/mobileaudit/how-can-i-integrate-mobileaudit-findings-with-defectdojo-using-api-v2-for-vulnerability-management)

Learn how to integrate MobileAudit findings with DefectDojo using API v2. Streamline vulnerability management by sending findings directly to DefectDojo for efficient tracking and resolution.

- Tags: how-to-guide
- Published: 2026-03-07

### [How MobileAudit Maps Built-In SAST Patterns to CWE and OWASP Mobile Top 10](/mpast/mobileaudit/what-sast-patterns-are-built-into-mobileaudit-and-how-are-they-mapped-to-cwe-and-mobile-top-10)

Discover how MobileAudit maps built-in SAST patterns to CWE and OWASP Mobile Top 10 for automated security finding classification. Understand mobile app vulnerabilities efficiently.

- Tags: deep-dive
- Published: 2026-03-07

### [How MobileAudit Uses Celery Task Queue for Asynchronous APK Analysis with Progress Tracking](/mpast/mobileaudit/how-does-mobileaudits-celery-task-queue-handle-asynchronous-apk-analysis-with-progress-tracking)

Discover how MobileAudit leverages Celery for asynchronous APK analysis, featuring real-time progress tracking through incremental state updates and HTTP polling.

- Tags: internals
- Published: 2026-03-07

