Setting up Burpsuite for Android Pentesting

Everyone knows that when it comes to penetration testing, Burpsuite by PortSwigger is our best friend. While there are tons of tutorials out there that guides one through the process of configuring their go-to browser to play well with Burpsuite, what about mobile applications? How does one get Burpsuite to intercept requests from an Android APK of their choosing?

As someone new to mobile audits, this was a question that stumped me too. So here’s a quick and dirty guide on how to set up Burpsuite for mobile penetration testing purposes!

Step 1: Install Prerequisite Tools

Step 2: Configure Android Emulator and Burpsuite

Step 3: Install Frida into rooted Emulator

Step 4: Download and Install APK