Android Pentest Container¶
The Android pentest container provides a pre-configured environment for testing Android applications with Sable.
The container runs an Android emulator along with specialized pentesting tools that allow the Sable agent to load your APK and attack it dynamically. This enables man-in-the-middle (MITM) attacks and other runtime analysis techniques against the running application.
Prerequisites¶
- Docker installed
- KVM available at
/dev/kvmon the Docker host - An Android APK file to test
- A Sable account at app.vulnetic.ai
Recommended hosting¶
We recommend running the Android pentest container on an Amazon EC2 m8i.4xlarge instance with 16 vCPUs and 64 GiB of RAM. Ensure /dev/kvm is available to Docker for emulator hardware acceleration and the instance has outbound internet access.
Running the container¶
You must use the Android-specific image
ghcr.io/vulnetic-inc/shell-container:latest-mobile for Android assessments. The
regular shell container does not include the emulator or mobile pentesting tools.
Note
macOS is not supported for the Android pentest container as a local Docker host. Use Linux, Windows (Docker Desktop), WSL, or a remote environment such as an AWS instance or virtual machine with outbound internet access.
Start the Android pentest container in relay mode:
docker run --rm --pull always --user root --device=/dev/kvm -it ghcr.io/vulnetic-inc/shell-container:latest-mobile --relay
You can run the relay command anywhere Docker is available, including an AWS instance or virtual machine, as long as the environment exposes /dev/kvm to Docker and has outbound internet access.
When the container starts, open the temporary Sable pairing URL printed in its logs to connect it to your account.
Configuring the assessment¶
- Create an assessment in Sable and select Android App as the target type
- Upload your APK file
- Start the Android pentest container and open the pairing URL it prints
- Launch the assessment
Troubleshooting¶
Container not connecting
- Verify the container is running with docker ps
- Confirm you opened the latest pairing URL printed by the container
- Pairing codes regenerate automatically. If a code expires, use the next pairing URL printed by the container