Back to the registry
Agent passport

MobSF Mobile Security Framework

ATH Infosystems · Cybersecurity & IT

Virtual MachinesNo attestation published

Certification per Microsoft Marketplace.

Provenance reach3 of 12 layers traced

Evidence tier Source Confirmed · 7 captures on record

User ratingNot rated0 reviews on the listing
Runs onVirtual MachinesVirtual machine
ProvenanceUnknown33% of the provenance layers this product can disclose
Evidence riskHighSign in to see the basis for this band.

What the publisher says

As described on Microsoft Marketplace.

MobSF (Mobile Security Framework) is a free and open-source automated mobile application security testing framework designed to analyze Android, iOS, and Windows applications. MobSF provides static and dynamic analysis capabilities to identify security vulnerabilities, insecure configurations, exposed secrets, and other potential security issues. It includes a web-based interface and supports automated security assessment, making it useful for mobile application developers, security researchers, penetration testers, and DevSecOps teams.

Key Features of MobSF:

Show the rest of the publisher’s description (30 more lines)
  • Free and open-source mobile application security testing framework.
  • Supports static analysis of Android, iOS, and Windows applications.
  • Provides dynamic analysis capabilities for supported mobile platforms.
  • Detects security vulnerabilities and insecure application configurations.
  • Identifies exposed secrets, sensitive information, and insecure code patterns.
  • Provides automated security assessment and detailed analysis reports.
  • Includes a web-based interface for managing and reviewing security tests.
  • Supports APK, IPA, and other supported mobile application formats.
  • Can be deployed using Docker for simplified installation and management.
  • Suitable for mobile application security testing, research, and DevSecOps workflows.

MobSF Usage:

$ sudo su

$ apt update

$ cd /opt/mobsf

# Check MobSF Container:

$ docker ps | grep mobsf

# Check MobSF Version:

$ docker exec mobsf python manage.py --version

# Show MobSF Docker Image:

$ docker images | grep mobsf

# Check MobSF Logs:

$ docker logs mobsf

# Check MobSF Web Port:

$ ss -tulpn | grep 8000

# Access MobSF Web Interface:

$ hostname -I

MobSF can typically be accessed through a web browser using

http://SERVER-IP:8000 after the Docker container has been started.

Disclaimer:

MobSF (Mobile Security Framework) is an independent open-source security testing project developed and maintained by its open-source contributors. It is not affiliated with or endorsed by Android, Apple, Microsoft, Docker, or any other third-party software or service mentioned for compatibility or deployment purposes.

Agent build and provenance

See the full provenance

The layer-by-layer build, the evidence behind each claim, the risk basis and the cross-marketplace links are open to any account. Some rows are disclosed, some the source leaves Unknown; a free account shows you which.

Compliance

Government
  • FedRAMPConfirmedNot listed90%, registry-checkedNo FedRAMP Marketplace entry matched this vendor's domain, checked 2026-08-27registry recordas observed 2026-08-27

Confirmed means matched to a public authoritative registry. Claimed means the vendor or its listing states it, not yet cross-checked. A framework not shown was not found in any source we hold, which is not evidence against it. Not listed means a scoped registry check found no match for this vendor's domain: a No is a scoped registry check, not a compliance judgment. Confidence bands: 95% domain-verified, 90% registry-checked, 80% self-attested, 70% weak signal. Self-attested items marked “vendor's site” are gathered from the vendor's own website and are not verified by us.

Vendor

External enrichment · as of 2026-08-29

CompanyATH Infosystems Pvt. Ltd.Verified
HQUnited States of AmericaVerified
IndustryTechnologyAutomated
Websitehttps://www.athinfosys.com/

Reconciled on 9/3/2026

Sources

Marketplace listingmarketplace.microsoft.comSource
Privacy PolicyPrivacy PolicySource

Publisher resources

1 link

Linked repositories

RepositoriesUnknownUnknown

Unknown means this listing does not publish a repository. It is not a statement that the code is closed, and a linked repository is not a claim that the publisher wrote it: the registry computes that relationship privately and does not publish it.

Pricing
Unknown
Not stated
Delivery
Virtual machine
https://www.athinfosys.com/Default.aspx
Open the source listing ↗

Evidence risk is the share of the build you cannot see before you deploy, not a security rating. Sign in to see the layer-by-layer basis for this band.