'Use when intercepts and analyzes HTTP/HTTPS traffic from mobile applications
Scanned 9/8/2026
Install to Claude Code
npx -y skills add oyi77/1ai-skills --skill intercepting-mobile-traffic-with-burpsuite --agent claude-codeInstalls into .claude/skills of the current project.
Are you the author of Intercepting Mobile Traffic With Burpsuite?
Add the live security badge to your README — it updates automatically with every re-scan.
[](https://www.skillsdirectory.com/skills/oyi77-intercepting-mobile-traffic-with-burpsuite)More formats (shields.io, HTML) on the badges page.
---
name: intercepting-mobile-traffic-with-burpsuite
description: 'Use when intercepts and analyzes HTTP/HTTPS traffic from mobile applications
using Burp Suite proxy to identify insecure API communications, authentication flaws,
data leakage, and server-side vulnerabilities. Use when performing mobile application
penetration testing, assessing API security, or evaluating client-server communication
patterns. Activates for requests involving mobile traffic interception, Burp Suite
mobile proxy, API security testing, or mobile HTTPS analysis.
'
domain: cybersecurity
tags:
- mobile-security
- android
- ios
- burp-suite
- traffic-interception
- penetration-testing
subdomain: mobile-security
author: oyi77
version: 1.0.0
license: Apache-2.0
nist_csf:
- PR.PS-01
- PR.AA-05
- ID.RA-01
- DE.CM-09
category: cybersecurity
---
# Intercepting Mobile Traffic With Burpsuite
## Overview
Cybersecurity skill for intercepting mobile traffic with burpsuite. Follows industry best practices and security standards.
## When to Use
**Trigger phrases:**
- "intercepting mobile traffic with burpsuite"
- "Testing mobile application API endpoints for authentication, authorization, and"
- "Analyzing data transmitted between mobile apps and backend servers during penetr"
- "Evaluating certificate pinning implementations and their bypass difficulty"
Use this skill when:
- Testing mobile application API endpoints for authentication, authorization, and injection vulnerabilities
- Analyzing data transmitted between mobile apps and backend servers during penetration tests
- Evaluating certificate pinning implementations and their bypass difficulty
- Identifying sensitive data leakage in mobile network traffic
**Do not use** this skill to intercept traffic from applications you are not authorized to test -- traffic interception without authorization violates computer fraud laws.
## When NOT to Use
- When you lack proper authorization for testing
- For production systems without change management
- When the task requires legal or compliance expertise beyond technical scope
## Prerequisites
- Burp Suite Professional or Community Edition installed on testing workstation
- Android device/emulator or iOS device on the same network as Burp Suite host
- Burp Suite CA certificate installed on the target device
- For Android 7+: Network security config modification or Magisk module for system CA trust
- For SSL pinning bypass: Frida + Objection or custom Frida scripts
- Wi-Fi network where proxy configuration is possible
## Workflow
```python
# Example: IOC detection
import re
IOC_PATTERNS = {
"ip": r"\b(?:\d{1,3}\.){3}\d{1,3}\b",
"domain": r"\b[a-z0-9-]+\.[a-z]{2,}\b",
"hash_md5": r"\b[a-f0-9]{32}\b",
"hash_sha256": r"\b[a-f0-9]{64}\b",
}
def extract_iocs(text: str) -> dict:
return {k: re.findall(v, text) for k, v in IOC_PATTERNS.items()}
```
1. **Define Objectives** — Clarify the goals and scope for mobile traffic.
2. **Gather Resources** — Collect tools, data, and access needed for mobile traffic.
3. **Execute Process** — Carry out mobile traffic operations methodically.
4. **Verify Quality** — Check results against acceptance criteria.
5. **Document Outcomes** — Record findings, decisions, and next steps.
## Tools
- **burpsuite** — Primary tool for this skill
- **Analysis Platform** — Data processing and visualization
- **Collaboration Tools** — Team coordination and knowledge sharing
## Process
1. **Prepare** — Gather requirements, verify prerequisites, set up environment
1. **Execute** — Run intercepting mobile traffic with burpsuite workflow with configured parameters
1. **Verify** — Validate output meets requirements, document results
## Verification
- [ ] All mobile traffic procedures executed completely and documented
- [ ] Findings validated against multiple data sources
- [ ] False positives identified and filtered
- [ ] Results documented with evidence and timestamps
- [ ] Recommendations provided with risk-based prioritization
## Anti-Rationalization Table
| Rationalization | Reality |
|---|---|
| "We are too small to be targeted" | Automated attacks target everyone. Size does not matter. |
| "Security slows us down" | A breach slows you down 100x more. Build security in from the start. |
| "We will fix it after launch" | Vulnerabilities in production are exploited within hours. Fix before deploy. |Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.
No comments yet. Be the first to comment!