Chip & System Security Testing 
Mobile & Backend Security Testing 
Our Company 
Contact us
Our Solutions

esChecker: Mobile Application Security Testing (MAST)

Don't compromise your digitalisation, leverage your mobile application security with automated testing within your CI/CD process. With a unique dynamic analysis feature, esChecker automatically executes the mobile application binary on unsafe devices and gives immediate feedback on your protections.
Request your free trial
Download our brochure
Mobile Application Security Testing MAST tool solution

What is Mobile Application Security Testing (MAST) ?

Mobile Application Security Testing (MAST) tools scan (SAST) and run (DAST, IAST) mobile applications for testing the effectiveness of their protections against hacking. Like any other IT system component, mobile apps must be designed, developed, and maintained with security in mind. They are the entry point to the system and require special attention.

Compared to pentesting, a MAST tool enables a shorter, quicker, and more efficient security testing process to better control the application's code as it progresses. It’s about code verification and it gives immediate feedback, allows compliance and it can be integrated in a DevSecOps process. Complement with pentesting for investigating vulnerabilities in the system.

MAST binary esChecker Security Mobile app

Why you should test your app's binary?

Most mobile application security testing tools on the market today focus on code verification, however, it is simply not enough. From a risk management perspective, it is important to assume the worst once the application is released, considering that it will be accessible to anyone with no way of controlling the device on which the app will be executed.

esChecker performs mobile application security testing at the binary level, where all the resources of the app are compiled and packaged, including 3rd parties SDK which source code review doesn’t take into consideration.

esChecker MAST tools Record and Replay

Unique Record and Replay feature

Our unique mobile IAST feature records and replays the app execution which allows it to go a step further in the dynamic security testing. Launch your test campaign, record the testing sequence and target critical user journeys for an assessment of the security protections where they matter, reducing the risk of false positives.

Replay the test evidence as many times as necessary and see for yourself how the app behaved in different attack scenarios. In the blink of an eye, monitor your application's progression, identify its weak spots and get guidance through improving your app regarding resilience to hacking. After the testing is done, you will get immediate feedback with an exhaustive and graphical report to demonstrate your app’s compliance with your chosen policy or a standard.

OWASP MSVS Protections Top10 Mobile App Sec

Don’t say it, prove it

To help organizations efficiently develop and secure their mobile apps, the OWASP has provided highly valuable resources. Of these, OWASP MASVS (Mobile Application Security Verification Standard) should be your reference when setting a Mobile App Security Policy.

Once you’ve set your security policy, esChecker is an OWASP tool generating a testing report and checking the compliance with the OWASP MASVS, helping you identify where your application needs more work to be properly protected. Additionally, you can understand the strength of your application in terms of Application Reverse Engineering Protection, Application Misconfiguration, and Application Vulnerabilities.

MAST tool automation

Automate Security Testing with DevSecOps

As you and your team work, your code evolves. To ensure security quality, you need to continuously test every new build and avoid protection regressions.

However, we understand that you're faced with aggressive time-to-market and multiple app releases. That is why to meet these demands, you must adopt an agile process and automate.

To implement a virtuous cycle of security quality without hindering your development cycle, transform your DevOps into DevSecOps with continuous integration. To help automate security testing during the SDLC, esChecker supports popular CI/CD frameworks such as Bitrise, Jenkins, CircleCI, Gitlab, and Github.

Garner Hype Cycle MAST App Security

Recognized by Gartner©

In July 2022, Gartner released its yearly Hype Cycles™ which “provide a graphic representation of the maturity and adoption of technologies and applications, and how they are potentially relevant to solving real business problems and exploiting new opportunities”.

In its recent report "Hype Cycle for Application Security", Gartner lists esChecker as a solution for Mobile Application Security Testing.

Automate your Security Testing

No source code needed. Test your Android or iOS binary in less than an hour and get immediate feedback.

Test you app in real conditions

esChecker executes the app on unsafe conditions and triggers protections

Go beyond basic checks

Combine both static an dynamic testing. Avoid any protection code regression

Extend the code coverage

Record a test sequence and test your app’s protections on critical user journeys

Tune your test campaign

Select your test campaign and set the success criteria

Get a test evidence

esChecker provides a video recording of the test sequence to visually verify your app’s behavior


Record and replay implements an Interactive Application Security Testing feature. Testing is done on code in motion.

Gartner Peer Insight Reviews


"[...] Using their tool esChecker at each step of your app development helps you make a 360 review of the security of your app in a few minutes. Just need to adjust your evaluation criteria on a self-made basis, creating scenarios as required, depending on your context or your security objectives, and you're ready to run the tool.

No doubt: a powerful tool for customers, and an amazing help for developpers!"



"eShard MAST turned out to be a nice complement to our mobile offering.

Our customers were enthusiastic about the technology and how much they learnt about mobile app security by using eShard's tool.

The DAST is particularly above any other solution, as far as we know. And it seems that more is about to come"



"I've been in contact with eShard for almost a year and I have been really impressed with their solution.

It is simple to use but the technology behind the scene is brillant and efficient. Moreover, since the beginning of our conversation, the solution has evolved quickly and I'm sure they will be able to help more companies to evaluate their app against the different issue a mobile app can face."



"We were impressed by the state-of-the-art technologies and techniques that eShard's consultants used when conducting penetration testing on our products.

[...] Within esChecker, the eShard team has included their years of experience in mobile application vulnerability testing in an automated testing package that is easy to use and provides detailed vulnerability information."


Blog Articles

Mobile App & Software

Cyber Resilience Act: what it means for Mobile Application Security

7 min read
Edit by Valentine Puig • Feb 21, 2023
CopyRights eShard 2023.
All rights reserved
Privacy policy | Legal Notice
Side Channel AnalysisLaser & EM Fault InjectionFirmware Security AnalysisSecurity Failure AnalysisVulnerability ResearchMAST: Mobile Application Security Testing