objection: runtime mobile exploration without a jailbreak
📱 objection - runtime mobile exploration
At a glance
- What is it?
- SensePost's objection wraps Frida into a Python CLI for inspecting iOS and Android apps at runtime. It is a pentest instrument, not a general reverse engineering suite, and its value depends on the Frida agent it injects.
- Who is it for?
- Adopt objection if you already use Frida and want a scripted, repeatable way to inspect iOS or Android apps at runtime during an authorised assessment. Do not adopt it if you need static analysis, if your target has no Frida support, or if you cannot run code on the device.
- Can I use it commercially?
- Yes, with conditions. GPL-3.0 is a copyleft licence: if you distribute software that includes it, you must release that software's source code under the same licence. Running it internally without distributing it does not trigger that obligation.
- Is it still maintained?
- Yes. The repository last received commits 13 days ago.
- What is it written in?
- Mainly Python, according to GitHub's language statistics.
Answers come from the project's GitHub data, last synced on September 30, 2026, and from our analysis. They are not legal advice.
Editorial analysis
What objection solves for mobile pentesters
objection is a runtime mobile exploration toolkit built on Frida, and the README states it is designed to help assess the security posture of mobile applications without needing a jailbreak. That last clause is the whole point. Traditional iOS assessment assumed a jailbroken device before you could attach to a running process; objection moves the workflow to Frida's injection model, which the project uses for both iOS and Android.
The audience is narrow and specific: mobile penetration testers and security engineers who are already comfortable with instrumentation. The README lists the capability set as inspecting and interacting with container file systems, bypassing SSL pinning, dumping keychains, memory related tasks such as dumping and patching, and exploring and manipulating objects on the heap. Each of those is an interactive operation against a live process, not a static scan.
If your question is what an app's binary contains, objection is the wrong shape of tool. It answers what an app does while it runs, and what you can change about that while it runs.
How the Frida agent and the Python CLI fit together
The repository layout makes the architecture legible. There is a top-level agent/ directory, and the Makefile builds it with a Node toolchain:
frida-agent:
cd agent && npm run buildThat agent is the JavaScript payload that runs inside the target process. The Python side lives in objection/, and pyproject.toml declares the console entry point as objection = "objection.console.cli:cli", so the objection command is a thin CLI over that package. The package data section ships agent.js alongside helpfiles, keystores, JavaScript assets and XML assets, which confirms the agent is bundled into the installed Python package rather than fetched at runtime.
The dependency list tells you what the CLI delegates to: frida>=16.0.0 and frida-tools>=10.0.0 for the instrumentation channel, click for argument parsing, prompt-toolkit for the interactive shell, flask for the HTTP surface, litecli for SQLite work, and tabulate for output formatting. So the data flow is: you type a command in the objection REPL, the Python layer translates it into an agent message, the injected agent executes it in the target process, and results come back to your terminal. Every capability the README lists is an agent-side action surfaced through that channel.
Installing objection and running a first session
The README is explicit that installation is a matter of one pip command, and that the same command with --upgrade updates an existing install. The package requires Python 3.11 or newer according to pyproject.toml, and it pulls Frida 16 or newer as a dependency.
pip3 install objectionAfter that, the objection command should be on your PATH. The README points to the wiki Installation page for more detailed update and installation instructions, so if the pip route fails on your platform, that page is the documented next stop rather than anything in the README itself.
For a first real use, the workflow is to have a target application running on a connected device or emulator, then start the interactive session and attach. The README does not print a canonical attach command, but it does describe the operations you would reach for once attached: container file system inspection, SSL pinning bypass, keychain dumping, memory dumping and patching, and heap object exploration. A session therefore looks less like a one-shot command and more like a REPL where you issue those operations in sequence against the live process. The wiki Features page is where the project says the full command list lives.
Where the jailbreak-free promise gets thin
The README's headline claim is assessment without a jailbreak, and that is a real reduction in setup friction. It is not the same as needing nothing. objection depends on Frida, and Frida depends on getting code into the target process. On a stock, non-jailbroken iOS device that generally means a repackaged application or a developer-signed build, which is a materially different engagement model from attaching to whatever is already installed on a test device. The README does not walk through that constraint, and the wiki Installation page is the documented place to look.
The second limitation is version coupling. pyproject.toml pins frida>=16.0.0 and frida-tools>=10.0.0, and the agent is compiled from the agent/ directory with an npm build step. That means a Frida release that changes its injection behaviour can break the bundled agent until the project rebuilds and ships it. If you are building from source rather than installing the published package, you own that build step yourself.
Third, the tool is interactive by design. There is no batch mode described in the README, and the CLI is built around prompt-toolkit. If you need something that runs unattended in CI against a fleet of apps, you are looking at the Flask surface or at driving Frida directly, not at the objection REPL.
objection against using Frida directly
The honest alternative is Frida itself. objection is a wrapper: frida and frida-tools are both dependencies, and the objection agent is JavaScript that Frida injects. Nothing objection does is impossible from a Frida script, and a competent Frida user can write a targeted hook for one specific pinning implementation in less time than it takes to learn the objection command set.
The difference in approach is abstraction versus precision. objection gives you a broad, pre-built set of operations (keychain dump, container file system access, heap exploration) behind a stable CLI, which is useful when you are moving fast across several apps and do not want to rewrite hooks each time. Frida gives you raw control over exactly which class or symbol you hook, which matters when the app uses a custom pinning scheme that objection's generic bypass does not cover. objection is the faster default; Frida is the escape hatch when the default misses.
Maintenance, release cadence and the GPL question
The repository is not archived, and the last push was on 2026-09-17. Recent releases are 1.12.5 on 2026-06-02, 1.12.4 on 2026-03-25, and 1.12.3 on 2026-01-27, so the project has shipped roughly quarterly through 2026 and the version in pyproject.toml matches the latest release at 1.12.5.
Upgrade cost is low if you installed from PyPI, since the README documents pip3 install --upgrade objection as the update path. Building from source is heavier: the Makefile default target runs clean, frida-agent and sdist, the agent build needs Node and npm, and the sdist step uses uv build. Contributors also get pytest via uv run pytest, with the test configuration in pyproject.toml pointing at the tests/ directory.
The licence is GPL-3.0-or-later. The README notes that permissions beyond the scope of that licence may be available through SensePost's contact page. For practical purposes: if you are using objection as a tool during an assessment, the copyleft obligations attach to distribution, not to running it. If you plan to ship objection inside a commercial product, or to link it into proprietary tooling, the GPL terms and the stated contact route for extended permissions are the two things to read before you build. That is a summary of what the repository states, not legal advice.
Editorial conclusion
Adopt objection if you already use Frida and want a scripted, repeatable way to inspect iOS or Android apps at runtime during an authorised assessment. Do not adopt it if you need static analysis, if your target has no Frida support, or if you cannot run code on the device. Before committing, verify that your Python is 3.11 or newer, that frida>=16.0.0 resolves on your platform, and that the GPL-3.0-or-later terms fit how you plan to redistribute anything you build on top of it.
Frequently asked questions
How do I install objection?
The README states that installation is a matter of running pip3 install objection, which provides the objection command. The package requires Python 3.11 or newer and depends on Frida 16 or newer. The README points to the wiki Installation page for more detailed instructions.
How do I install objection on Windows?
The README gives a single platform-independent install command, pip3 install objection, and describes the package as Operating System :: OS Independent in its classifiers. It does not document Windows-specific steps; the wiki Installation page is the documented place for more detail.
How do I use the objection tool?
objection runs as an interactive CLI over a Frida agent injected into a running iOS or Android app. Once attached, the README lists operations such as inspecting the container file system, bypassing SSL pinning, dumping keychains, memory dumping and patching, and exploring heap objects. The wiki Features page holds the full command list.
How do I use objection with Frida?
Frida is the instrumentation layer objection is built on: frida>=16.0.0 and frida-tools>=10.0.0 are declared dependencies, and the agent built from the agent/ directory is the JavaScript payload Frida injects into the target process. You do not invoke Frida separately; the objection CLI drives it.
Official sources
Add this badge to your README
If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.
[](https://hysenlabs.com/projects/sensepost-objection)