Quokka (formerly Kryptowire)
Mobile Security, Solved.
Overview
Quokka, formerly known as Kryptowire, provides an automated mobile app security testing (MAST) platform. It analyzes compiled mobile app binaries (without needing source code) to discover security, privacy, and compliance vulnerabilities. The platform is trusted by government agencies and enterprises to vet mobile apps and ensure they meet stringent security standards.
✨ Key Features
- Automated binary analysis (SAST/DAST)
- No source code required
- Compliance testing (NIAP, OWASP MASVS)
- Continuous monitoring of app store apps
- Software Bill of Materials (SBOM) generation
🎯 Key Differentiators
- Analyzes compiled binaries without needing source code
- Strong focus and expertise in government and defense standards (NIAP)
- AI-powered engine for deep vulnerability discovery
Unique Value: Provides the highest-standard, automated mobile app security analysis directly from the compiled binary, ensuring security and compliance without requiring access to source code.
🎯 Use Cases (5)
💡 Check With Vendor
Verify these considerations match your specific requirements:
- Organizations needing on-device runtime protection (MTD)
- Companies looking for web application security scanning
🏆 Alternatives
Its 'black-box' binary analysis approach is ideal for vetting third-party applications where source code is unavailable, a use case not well-covered by traditional SAST tools.
💻 Platforms
🔌 Integrations
🛟 Support Options
- ✓ Email Support
- ✓ Phone Support
- ✓ Dedicated Support (Enterprise tier)
🔒 Compliance & Security
💰 Pricing
✓ 14-day free trial
🔄 Similar Tools in Mobile App Security
Zimperium
Provides real-time, on-device threat defense for mobile devices against known and unknown threats....
Data Theorem
Automated security for mobile, API, cloud, and web applications....
Guardsquare
Provides multi-layered mobile app protection and threat monitoring solutions....
NowSecure
Automated mobile app security testing designed for developers....
Checkmarx
A comprehensive AppSec platform offering SAST, DAST, IAST, SCA, and API security....
Veracode
A cloud-native application security platform for the entire SDLC....