AltMAP brings professional-grade CVE vulnerability scanning to your Android device. Search through 10,000+ attack templates, fingerprint services, and confirm blind exploits via OOB — all from your pocket.
From TCP port scanning to OOB exploit detection — enterprise-grade security tooling, mobile-native.
Scan large networks and IP ranges with thread-optimised engines. Cover entire subnets in seconds with configurable thread pools.
Auto-fetch and fingerprint HTTP pages from discovered hosts. Identify server software, versions, and exposed services.
Search and run 10,000+ mobile HTTP-based CVE templates. Guided assisted mode helps beginners choose the right checks.
Scan devices on your local Wi-Fi or any internet-reachable IP/domain. No VPN or desktop required.
Confirm blind SSRF, command injection, and XXE via secure callbacks to the AltMAP-owned OOB server. Zero data collected.
Define named scan missions and run them simultaneously with isolated thread pools. Full strategic control, zero blocking.
Continuous improvements driven by real-world pentest feedback and community CVE submissions.
Massive library expansion covering every major platform — web servers, frameworks, IoT, and cloud APIs.
Intelligent guided workflow helps new users pick templates, severity levels, and targets step-by-step.
Rich post-scan view with severity breakdowns, CVE timelines, host maps, and exportable reports.
Discover and enumerate internet-facing assets directly in-app using the Fofa search API.
Local WebView + Cloudflare HTML/JS fetch engine for fast, accurate service identification.
Smarter thread scheduling and memory management for long, stable sessions on mobile hardware.
In the field, at the office, or in the lab — AltMAP adapts to your workflow.
Rapid recon, CVE validation, and OOB blind exploit confirmation on client engagements.
Assess your own infrastructure for known vulnerabilities before attackers do.
Quickly identify exposed services and misconfigurations on your local network.
Template-driven CVE testing with deep customisation for controlled research environments.
AltMAP processes all scan data locally on your device. Some advanced CVE checks initiate a minimal, encrypted connection to our OOB server — solely to confirm exploit callbacks. No personal data is ever collected or shared.
Download AltMAP free from Google Play and bring professional vulnerability scanning to your Android device.
Download on Google Play