Mobile apps communicate with APIs that are rarely included in a web-focused security assessment. The API endpoints a mobile app calls are often different from the web application's API: different paths, different rate limits, different authentication schemes, and sometimes different backend services entirely. A comprehensive DDoS resilience assessment has to cover the mobile API surface, not just the web surface visible from a browser.
DDactic's mobile API surface scan uses a combination of static analysis (APK/IPA decompilation to extract hardcoded endpoints), dynamic traffic interception (via mitmproxy on an instrumented device), and DNS-based discovery to enumerate the full set of API hosts and paths that a mobile app contacts. This surface is then tested for rate limit presence and DDoS resilience using the same methodology applied to web APIs.
Why Mobile APIs Are Different
Mobile API endpoints are architected under different assumptions than web APIs. Mobile clients frequently retry on failure (to handle poor connectivity), which means the backend must handle higher burst rates from individual clients without misidentifying them as attackers. Rate limits are often set more permissively for mobile endpoints as a result. Mobile clients also often use long-lived access tokens or API keys embedded in the application binary, which cannot be rotated without a forced app update. These factors combine to create an API surface that is typically less protected than the web API while being equally or more accessible from the public internet.
Static Analysis: Endpoint Extraction
Android APKs can be decompiled with tools like jadx or apktool to extract string constants, including hardcoded API base URLs, endpoint paths, and API keys. DDactic's static analysis stage identifies all string patterns matching URL patterns and cross-references them with DNS resolution to confirm which are live endpoints. iOS IPA binaries require different tooling (class-dump, Hopper) but yield the same result: a list of API endpoints that the application is built to call, before any network traffic is observed.
This static extraction catches endpoints that may not be exercised during a typical dynamic testing session, including error reporting endpoints, analytics beacons, internal admin endpoints accidentally included in the app, and staging or debug endpoints left in production builds. These forgotten endpoints are often completely unprotected because they never appeared in a web-focused WAF review.
Dynamic Traffic Capture
Dynamic capture runs the mobile app through a set of representative user flows while proxying traffic through mitmproxy. This captures the actual HTTP/2 or HTTP/1.1 requests, including all headers, the full URL path, and the response -- giving ground truth for what rate limits are in place (visible in X-RateLimit-* or RateLimit-* response headers), what authentication the endpoint expects, and what the response time is under normal conditions. DDactic's Linux desktop lab runs Discord, Slack, Zoom, and Spotify in a Docker container with mitmproxy to capture real traffic flows for rate limit baseline measurements.
Certificate Pinning
Certificate pinning prevents interception by rejecting certificates not matching the app's pinned certificate or public key hash. DDactic handles pinning bypass at the OS level using Frida to hook the SSL verification functions at runtime, injecting a hook that accepts any valid certificate. This does not require the app's source code and works on both Android and iOS. The bypass is used only for measurement purposes -- the goal is to enumerate the API surface and measure rate limits, not to extract credentials.
Certificate pinning is not a DDoS defense
Pinning prevents casual interception but does not protect against attackers who have extracted the pinned public key from the app binary or who simply replay observed traffic patterns. Do not rely on certificate pinning as a rate-limiting substitute for mobile API endpoints.
What the mobile scan reports
The DDactic mobile scan output lists each discovered endpoint, whether a rate limit header is present, the observed rate limit value (if detectable), and the OPI contribution of each unprotected path based on its estimated backend computation cost.
Include Your Mobile API Surface
DDactic's assessment includes mobile API discovery by default for organizations with public iOS or Android apps. Request a scan to get full coverage of your API attack surface.
Run a Free Scan