Chip & System Security Testing 
Mobile & Backend Security Testing 
Our Company 
Contact us
Our Solutions

esChecker Mobile Application Security Testing (MAST)

Don't compromise your digital transformation. Mobile applications are an entry point to your system and you’re accountable for the security of the services you provide. To avoid any point of failure and better control the mobile application security, continuous security testing needs to be integrated within the development cycle. Built on years of penetration testing experience and constantly updated to reflect the latest hacking techniques, esChecker is a SaaS solution relying on a unique and groundbreaking “record and replay” mobile IAST technology. Thanks to a combination of both Static (SAST) and Dynamic (DAST) test technologies and its use of real and untrusted devices, esChecker performs automated security testing on both Android and iOS mobile apps, in real conditions, at the binary level. As the application is running, it watches out for both code vulnerabilities AND resiliency to attacks.
Request your free trial
Download our brochure
Mobile Application Security Testing MAST tool solution

What is Mobile Application Security Testing (MAST) ?

Mobile Application Security Testing (MAST) tools scan (SAST) and run (DAST, IAST) mobile applications for testing the effectiveness of their protections against hacking. Like any other IT system component, mobile apps must be designed, developed, and maintained with security in mind. They are the entry point to the system and require special attention.

Compared to pentesting, a MAST tool enables a shorter, quicker, and more efficient security testing process to better control the application's code as it progresses. It’s about code verification and it gives immediate feedback, allows compliance and it can be integrated in a DevSecOps process. Complement with pentesting for investigating vulnerabilities in the system.

MAST binary esChecker Security Mobile app

Why test the mobile app binary ?

Most mobile application security testing tools on the market today focus on code verification, however, it is simply not enough. From a risk management perspective, it is important to assume the worst once the application is released, considering that it will be accessible to anyone with no way of controlling the device on which the app will be executed.

esChecker performs mobile application security testing at the binary level, where all the resources of the app are compiled and packaged, including 3rd parties SDK which source code review doesn’t take into consideration.

esChecker MAST tools Record and Replay

Why use a DAST?

Dynamic Application Security Testing DAST tests the application as it is being executed. This becomes mandatory to check mobile apps behaviour on real conditions. This is particularly valuable when SAST is limited due to a specific code framework (Flutter, React, Xamarin) or a code obfuscation.

We chose to turn our DAST into a Mobile Application Security Testing IAST. Our unique mobile IAST feature records and replays the app execution which allows it to go a step further in the dynamic security testing. Testing is carried out on a chosen sequence: the user journey.

Before launching your test campaign, our MAST tool lets you record a custom testing sequence to target critical user journeys. That way, you get an assessment of the security protections where they matter, thus reducing the risk of false positives.

Replay the test evidence as many times as necessary and see for yourself how the app behaved in different attack scenarios. In the blink of an eye, monitor your application's progression, identify its weak spots and get guidance through improving your app regarding resilience to hacking.

OWASP MSVS Protections Top10 Mobile App Sec

Don’t say it, prove it

To help organizations efficiently develop and secure their mobile apps, the OWASP has provided highly valuable resources. Of these, OWASP MASVS (Mobile Application Security Verification Standard) should be your reference when setting a Mobile App Security Policy.

Once you’ve set your security policy, esChecker is an OWASP tool generating a testing report and checking the compliance with the OWASP MASVS, helping you identify where your application needs more work to be properly protected. Additionally, you can understand the strength of your application in terms of Application Reverse Engineering Protection, Application Misconfiguration, and Application Vulnerabilities.

MAST tool automation

How to implement DevSecOps?

As you and your team work, your code evolves. To ensure security quality, you need to continuously test every new build and avoid protection regressions.

However, we understand that you're faced with aggressive time-to-market and multiple app releases. That is why to meet these demands, you must adopt an agile process and automate.

To implement a virtuous cycle of security quality without hindering your development cycle, transform your DevOps into DevSecOps with continuous integration. To help automate security testing during the SDLC, esChecker supports popular CI/CD frameworks such as Bitrise, Jenkins, CircleCI, Gitlab, and Github.

Garner Hype Cycle MAST App Security

Recognized by Gartner©

In July 2022, Gartner released its yearly Hype Cycles™ which “provide a graphic representation of the maturity and adoption of technologies and applications, and how they are potentially relevant to solving real business problems and exploiting new opportunities”.

In its recent report "Hype Cycle for Application Security", Gartner lists esChecker as a solution for Mobile Application Security Testing.

With esChecker MAST, security testing is fast and easy.

No source code needed. Test your Android or iOS binary in less than an hour and get immediate feedback.

Test you app in real conditions

esChecker executes the app on unsafe conditions and triggers protections

Go beyond basic checks

Combine both static an dynamic testing. Avoid any protection code regression

Extend the code coverage

Record a test sequence and test your app’s protections on critical user journeys

Tune your test campaign

Select your test campaign and set the success criteria

Get a test evidence

esChecker provides a video recording of the test sequence to visually verify your app’s behavior


Record and replay implements an Interactive Application Security Testing feature. Testing is done on code in motion.

Fields of application


Integrate Security QA early in your Development Process. Don’t wait until your application is live to make the relevant security checks.

Chief Information Security Officer

Take control of the risk management by enforcing a security policy for all mobile app development.

Thought leader

Explore the good practices in a given market and the related technological trends in mobile app security.

Regulation authority

Leverage a MAST tool to request a demonstration of compliance within your ecosystem.

Gartner Peer Insight Reviews


"[...] Using their tool esChecker at each step of your app development helps you make a 360 review of the security of your app in a few minutes. Just need to adjust your evaluation criteria on a self-made basis, creating scenarios as required, depending on your context or your security objectives, and you're ready to run the tool.

No doubt: a powerful tool for customers, and an amazing help for developpers!"



"eShard MAST turned out to be a nice complement to our mobile offering.

Our customers were enthusiastic about the technology and how much they learnt about mobile app security by using eShard's tool.

The DAST is particularly above any other solution, as far as we know. And it seems that more is about to come"



"I've been in contact with eShard for almost a year and I have been really impressed with their solution.

It is simple to use but the technology behind the scene is brillant and efficient. Moreover, since the beginning of our conversation, the solution has evolved quickly and I'm sure they will be able to help more companies to evaluate their app against the different issue a mobile app can face."



"We were impressed by the state-of-the-art technologies and techniques that eShard's consultants used when conducting penetration testing on our products.

[...] Within esChecker, the eShard team has included their years of experience in mobile application vulnerability testing in an automated testing package that is easy to use and provides detailed vulnerability information."


Blog Articles

Mobile App & Software

About mobile application security

14 min read
Edit by Hugues Thiebeauld • Dec 30, 2022
CopyRights eShard 2023.
All rights reserved
Privacy policy | Legal Notice
Side Channel AnalysisLaser & EM Fault InjectionFirmware Security AnalysisSecurity Failure AnalysisVulnerability ResearchMAST: Mobile Application Security Testing