I built Exfault, agentic mobile app pentesting tool
Details
- External ID
- 48719261
- Source
- HN
- Company
- —
- Product
- I built Exfault, agentic mobile app pentesting tool
- Website domain
- exfault.com
- Launched
- June 29, 2026
- Cohort
- —
- Upvotes
- 6
- Upvotes percentile
- 0.31420765027322406
- Tags
- —
- Fetched at
- Sept. 7, 2026, 9:26 p.m.
- Updated at
- Sept. 7, 2026, 9:26 p.m.
Description
Hi HN, I am the creator of Exfault. I am building autonomous AI agents that find vulnerabilities in Android apps.I have noticed there are growing number of AI native pentesting tools for web apps but very few for mobile or Android. With more mobile apps being shipped quickly due to vibe coding, I wanted to build an AI native security tool specifically for Android apps.Exfault combines static and dynamic analysis with AI agents using tools like adb,jadx, apktool for static analysis and reverse engineering, frida for dynamic analysis, hermes-dec for React native decompilation. The AI agents have access to real Android emulators to peform navigation, explore functionality and validate vulnerabilities before reporting them improving both the quality of reports and also the rate of false positives.Instead of uploading an apk or aab, you can simply enter an Android package name (com.example.app), Our backend automatically acquires a compatible build, installs it in an emulator so the agents can test your app.For authenticated testing, you can provide test credentials and the agent will automatically sign in and continue exploring the authenticated attack surface. I'm also working on a human-in-the-loop login helper for more complex authentication flows involving MFA, Email verification etc.There's a free demo available if you'd like to try it on your own app.I'd really appreciate your thoughts and feedback!https://exfault.com
Enrichment
- Theme
- ai cybersecurity and penetration testing
- Vertical
- Security
- Function
- Agent / copilot
- Audience
- Developer
- AI stance
- AI-native
- Project type
- Commercial product
- Normalized one-liner
- agentic mobile app penetration testing tool
- Manually corrected
- False
Could you build this?
Partial Building the UI dashboard and prompting LLMs to analyze decompiled Android code is straightforward, but orchestrating cloud-hosted Android emulators with dynamic instrumentation and automated security scanning is complex.
What it would actually take: The architecture requires a farm of containerized Android emulators (e.g., Redroid or AWS EC2 bare-metal instances), automated dynamic instrumentation frameworks (Frida, ADB), and static analysis tools (JADX, Apktool). Specialized mobile security engineering is needed to bypass certificate pinning, anti-tampering, and emulator detection while reliably reproducing valid exploits.
Discussion
No comments on this launch.
Competitors
Other products that read as similar to this one — 101 launches clear the similarity bar, closest 8 shown.
Attention rank: #64 of 102 (itself plus its competitors, highest first — normalized so YC and Product Hunt are compared fairly).
Launched 216 days after the earliest competitor.
- Xalgorix · hn · 2026-07-06 · 5 upvotes · similarity 0.48
- SanityCheck · ph · 2026-09-10 · 7 upvotes · similarity 0.43
- Ceraph · ph · 2026-09-28 · 1 upvotes · similarity 0.43
- Agent Arena · hn · 2026-02-06 · 47 upvotes · similarity 0.41
- heimdall-pentest · github · 2026-09-14 · 67 upvotes · similarity 0.41
- PentestPi · github · 2026-09-09 · 15 upvotes · similarity 0.41
- Agent Passport · hn · 2026-02-21 · 14 upvotes · similarity 0.41
- Xalgorix · hn · 2026-08-19 · 9 upvotes · similarity 0.40
Other launches for this product
- No other launches for this product.
Same idea, different domain
Nobody's really built a agent / copilot tool for Agriculture yet.