KnoxSpy


Subho Halder 



From GitHub - appknox/knoxspy :

Breaking the Proxy Barrier: Advanced Network Traffic Interception for MDM Applications

A cutting-edge Frida-based tool for bypassing certificate pinning and intercepting network traffic from mobile applications that resist traditional proxy methods.

KnoxSpy solves interception for MDM applications, certificate pinning, custom security protocols, and TLS/SSL bypass restrictions by hooking directly into popular network libraries at runtime (OkHttp3, Flutter HTTP/DIO on Android; Alamofire/AFNetworking on iOS). It provides real-time traffic capture, request replay, a repeater for modifying and replaying requests, and supports Android work profiles and secondary users. Developed by Appknox. Licensed under Apache-2.0.

Presented at Black Hat Europe 2025 Arsenal and DEF CON 31.

List of Sessions