Skip to main content
Q

Quokka

Quokka provides automated, agent‑less security analysis for iOS, Android, and Android firmware apps, scanning compiled binaries to uncover vulnerabilities, privacy issues, and compliance gaps without requiring source code.

San JoseFounded 2011482K+ followers
Updated 2 months ago

Funding

Funding not disclosed

Funding rounds are not available yet.

Founders

Founder details are not available yet.

Product

Problem

Enterprises and government agencies struggle to detect security, privacy, and compliance risks in mobile applications and device firmware because traditional tools require source code, agent installation, or manual testing, leaving a blind spot in the mobile attack surface.

Solution

Quokka delivers automated, agentless security analysis for iOS, Android, and Android firmware without needing source code. Its Q‑mast platform scans compiled app binaries using static, dynamic, interactive, and forced‑path execution techniques to uncover vulnerabilities, risky third‑party components, and compliance gaps in minutes with less than 1 % false positives. Q‑scout extends this capability to the mobile workforce by vetting any app—obfuscated or protected—in the cloud, integrating with MDM solutions such as Microsoft Intune, Hexnode UEM, and Ivanti Neurons to provide risk scores, behavioral insights, and audit‑ready reports that can be enforced as policies. Q‑firm adds firmware security testing for Android devices, analyzing pre‑installed and privileged system apps to detect privilege‑escalation flaws, data leaks, and supply‑chain threats before devices ship. All findings are mapped to standards like NIST, NIAP, OWASP MASVS, and GDPR, enabling security teams to prioritize real threats, reduce false positives, and demonstrate a defensible mobile security posture.

Target Audience

Primary customers are security and compliance teams in large enterprises, government agencies, and regulated industries that manage mobile device fleets and develop or distribute iOS/Android applications and Android firmware.

Features

  • Multi‑layer analysis engine (static, dynamic, interactive, forced‑path) that works on compiled binaries, including heavily obfuscated or signed builds
  • Cloud‑based scanning completes in under 60 minutes and generates version‑precise SBOMs and compliance mappings
  • Agentless integration with major MDM platforms (Microsoft Intune, Hexnode UEM, Ivanti Neurons, Omnissa Workspace ONE) for automated app vetting at scale
  • Real‑time behavioral analysis in sandboxed environments to detect zero‑day malware, SDK data exfiltration, over‑broad permissions, and supply‑chain compromises
  • Firmware security testing (Q‑firm) that inspects hidden and privileged Android system apps, using flow‑based vulnerability scanning to uncover privilege‑escalation and privacy leaks
  • CI/CD connectors for GitHub, GitLab, Jenkins, Azure DevOps and DevSecOps tools (Appium, Snyk) to embed security checks directly into development pipelines
  • Audit‑ready reporting aligned with NIST, NIAP, OWASP MASVS, GDPR, and industry‑specific regulations, with risk scores and actionable remediation guidance
This profile is AI-generated and may contain inaccuracies.