Objection
Objection is a runtime mobile-exploration toolkit that wraps Frida into a friendly REPL. It saves you from writing custom hooks for the common cases: SSL pinning, jailbreak detection, app storage browsing, and memory patching.
Install and Connect
pip3 install objection
objection --help
Connect to a running app by name or bundle ID:
# Attach to a process on a USB device
objection -g com.example.app explore
# Attach by PID
objection -g 1234 explore
# Spawn a new instance (simulator or via gadget)
objection -g com.example.app --startup-command "ios jailbreak disable" explore
For the simulator, target the process the same way (no -U device flag needed):
objection -g "ExampleApp" explore
SSL Pinning Bypass
The single most-used command in an iOS test:
(objection) ios sslpinning disable
This hooks the common SSL verification methods so the app trusts Burp's CA. Confirm it worked by reloading the app's HTTPS traffic in Burp — you should now see decrypted requests in HTTP history.
If the app uses a custom pinning library, ios sslpinning disable may fail; fall back to Frida with a targeted script.
Jailbreak Detection Bypass
(objection) ios jailbreak disable
Objection neutralizes a set of common jailbreak checks. This is usually enough to get the app running in "clean" mode on a jailbroken test device. For stubborn checks, layer a Frida hook on top.
Exploring App Storage
Objection exposes the app sandbox and its databases without digging through the filesystem manually.
# Browse the app container like a shell
(objection) ls
(objection) cd Documents
(objection) cat plist/Config.plist
# Enumerate files, dirs, databases
(objection) ios storage list
# Interact with SQLite databases found in the sandbox
(objection) ios sqlite dump Documents/db.sqlite
(objection) ios sqlite sql Documents/db.sqlite "SELECT * FROM users"
Dump the whole data directory for offline review:
(objection) ios storage download all
Hooking and Method Exploration
# List methods on a class (heavily used during enumeration)
(objection) ios hooking list classes | grep -i api
(objection) ios hooking list class_methods NSURLSession
(objection) ios hooking list methods com.example.app.APIClient
# Live hook a method and log arguments/return values
(objection) ios hooking watch class NSURLSession
(objection) ios hooking watch class com.example.app.APIClient --dump-args --dump-return
# Search loaded classes for a string (great for finding interesting logic)
(objection) ios hooking search classes NSURLCache
(objection) ios hooking search classes api
# Watch all methods on a class
(objection) ios hooking watch class ViewController
Memory search and patch:
# Search the app's memory for a string
(objection) memory search "secret_token"
# Patch a string in memory (e.g., change an endpoint or a debug flag)
(objection) memory patch 0x16d9b3a8 "https://attacker" "https://legit"
# List modules and symbols to find function addresses
(objection) memory list modules
(objection) memory list exports libapp.dylib
App Environment Info
(objection) ios info binary # binary info, entitlements
(objection) ios info plist # the app's Info.plist
(objection) ios info app # bundle id, version, container paths
(objection) ios info cookies # the app's cookies
(objection) ios info keychain # keychain items
(objection) ios info preferences # NSUserDefaults
Non-Jailbroken Devices
Objection needs Frida to run. On stock iOS you inject FridaGadget.dylib into the IPA and launch the patched app:
# Download a prebuilt gadget (matches your frida version)
# https://github.com/frida/frida/releases (frida-gadget-<ver>-ios-universal.dylib)
# Inject into the binary (requires a decrypted IPA for App Store apps)
# Then launch via idevicedebug and attach with objection
objection -g com.example.app explore
ios jailbreak disable and other hooks work through the gadget as well, which is why this is the standard path on non-jailbroken test devices.
Report-Ready Output
Every hook you enable can be logged. Keep a clean transcript for the report:
(objection) ios hooking watch class NSURLSession --dump-args --dump-return
Then reproduce the traffic and capture the log. Combine with Burp history and MobSF output for a complete evidence set.
Gotchas
ios sslpinning disabledoes not disable ATS; if the app refuses plain HTTP, patchInfo.plist(see the Burp Suite page).- Pin methods in
SecTrustEvaluateand friends are covered by objection, but custom-pinned stacks may need a manual Frida hook. - Objection attaches to the running app; if the app crashes on attach, spawn with the gadget and
--startup-command. - On iOS 16+, ensure Developer Mode is enabled before attaching Frida/objection to a physical device.