Nicheloom

Market intelligence for builders — see what's gaining traction before it's crowded.

I built Exfault, agentic mobile app pentesting tool

Details

External ID
48719261
Source
HN
Company
—
Product
I built Exfault, agentic mobile app pentesting tool
Website domain
exfault.com
Launched
June 29, 2026
Cohort
—
Upvotes
6
Upvotes percentile
0.31420765027322406
Tags
—
Fetched at
Sept. 7, 2026, 9:26 p.m.
Updated at
Sept. 7, 2026, 9:26 p.m.

Description

Hi HN, I am the creator of Exfault. I am building autonomous AI agents that find vulnerabilities in Android apps.I have noticed there are growing number of AI native pentesting tools for web apps but very few for mobile or Android. With more mobile apps being shipped quickly due to vibe coding, I wanted to build an AI native security tool specifically for Android apps.Exfault combines static and dynamic analysis with AI agents using tools like adb,jadx, apktool for static analysis and reverse engineering, frida for dynamic analysis, hermes-dec for React native decompilation. The AI agents have access to real Android emulators to peform navigation, explore functionality and validate vulnerabilities before reporting them improving both the quality of reports and also the rate of false positives.Instead of uploading an apk or aab, you can simply enter an Android package name (com.example.app), Our backend automatically acquires a compatible build, installs it in an emulator so the agents can test your app.For authenticated testing, you can provide test credentials and the agent will automatically sign in and continue exploring the authenticated attack surface. I'm also working on a human-in-the-loop login helper for more complex authentication flows involving MFA, Email verification etc.There's a free demo available if you'd like to try it on your own app.I'd really appreciate your thoughts and feedback!https://exfault.com

Enrichment

Theme
ai cybersecurity and penetration testing
Vertical
Security
Function
Agent / copilot
Audience
Developer
AI stance
AI-native
Project type
Commercial product
Normalized one-liner
agentic mobile app penetration testing tool
Manually corrected
False

Could you build this?

Partial Building the UI dashboard and prompting LLMs to analyze decompiled Android code is straightforward, but orchestrating cloud-hosted Android emulators with dynamic instrumentation and automated security scanning is complex.

What it would actually take: The architecture requires a farm of containerized Android emulators (e.g., Redroid or AWS EC2 bare-metal instances), automated dynamic instrumentation frameworks (Frida, ADB), and static analysis tools (JADX, Apktool). Specialized mobile security engineering is needed to bypass certificate pinning, anti-tampering, and emulator detection while reliably reproducing valid exploits.

Discussion

No comments on this launch.

Competitors

Other products that read as similar to this one — 101 launches clear the similarity bar, closest 8 shown.

Attention rank: #64 of 102 (itself plus its competitors, highest first — normalized so YC and Product Hunt are compared fairly).

Launched 216 days after the earliest competitor.

Other launches for this product

Same idea, different domain

Nobody's really built a agent / copilot tool for Agriculture yet.