> For the complete documentation index, see [llms.txt](https://help.aikido.dev/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://help.aikido.dev/docs/docs-ja/pentesuto/configure-a-pentest/android-pentesting.md).

# Android アプリのペンテスト

Aikido Pentest はネイティブおよびハイブリッドの Android アプリを次の方法で評価できます **ホワイトボックステスト**。ブラックボックスの Android ペンテストはまだサポートされていないため、Android アプリのソースコードを含むリポジトリを接続する必要があります。

下のウォークスルーを見るか、さらに下の手順ガイドに従ってください。

{% embed url="<https://www.youtube.com/watch?v=EGzGZIr2rn4>" %}

{% hint style="warning" %}
本番環境にできるだけ近いテスト環境でアセスメントを実行してください。本番データや本番アカウントは使用しないでください。
{% endhint %}

{% hint style="info" %}
**ホワイトボックスのみ：** Aikido は現在、APK 単体ではなくアプリのソースコードに対して Android ペンテストを実行します。Android アプリのリポジトリを次の場所で添付してください： **コードとドキュメント** アセスメントを開始する前の手順で。
{% endhint %}

### 前提条件

開始する前に、以下を確認してください：

* **ペンテストを管理** [権限](/docs/docs-ja/hajimeni/automated-user-management/setting-roles-and-permissions.md)
* **十分なクレジット** あなたの [ウォレット](/docs/docs-ja/miscellaneous-info/wallet-and-credits.md)
* **Android アプリのソースコード** Aikido に接続できるリポジトリ内にあること（ホワイトボックステストに必須）
* **テスト用 APK** アップロード可能な状態であること（最大 500 MB、証明書ピニング、ルート検出、エミュレーター検出なし）

## Android アセスメントを作成

{% stepper %}
{% step %}

### Android を選択

に移動し **ペンテスト**、次を開いてください： **プロジェクト**、次にクリックします: **アセスメントを作成**。次の **何をペンテストしますか？** 手順で、次を選択してください： **Android**.

<div data-with-frame="true"><figure><img src="/files/26d4b9141d8c136cf8ff75cebc5bcc62b9088e09" alt=""><figcaption></figcaption></figure></div>
{% endstep %}

{% step %}

### テスト範囲を定義

次の **スコープ** 手順で、アプリにバックエンド API がある場合は、その URL を追加してください（例： `https://api.application.com`）これにより、Aikido はアプリが使用するエンドポイントをテストし、適切なカバレッジを確保できます。その後、APK をアップロードしてください（最大 500 MB）。アプリは証明書ピニング、ルート検出、エミュレーター検出を使用していてはいけません。Aikido はパッケージ名を自動的に抽出します。

選択 **アプリ全体をテスト** または **特定の部分のみをテスト**、アプリのどの程度をアセスメントするかによります。

<div data-with-frame="true"><figure><img src="/files/27b10fe20d0d367de0ed6ea7f0df3d31c8ead9ec" alt=""><figcaption></figcaption></figure></div>
{% endstep %}

{% step %}

### テストユーザーを追加

管理者、一般ユーザー、別テナントのユーザーなど、Aikido にテストさせたい各役割のテストユーザーを追加してください。ユーザー名とパスワードによる認証では、Aikido はログイン URL の代わりに Android アプリのパッケージ名を使用します。

アセスメントを開始する前に、ログイン事前チェックを使用して Aikido がアプリにアクセスできることを確認できます。詳細な手順については、次を参照してください： [テストユーザーの設定](/docs/docs-ja/pentesuto/configure-a-pentest/setting-up-authenticated-testing.md).

<div data-with-frame="true"><figure><img src="/files/328bd7c435b4f3555b5227ca4485018197afc8e8" alt=""><figcaption></figcaption></figure></div>
{% endstep %}

{% step %}

### アクセス、コンテキスト、安全性を設定

ウィザードの残りの手順を設定してください：

* **許可ドメイン** – テスト中にアプリがアクセスする必要のあるドメインを許可します。
* **コードとドキュメント** – **必須：** Android アプリのソースコードを含むリポジトリを接続してください。Aikido はホワイトボックスの Android ペンテストのみをサポートしているため、コードベースを添付しないとアセスメントは実行できません。バックエンドのリポジトリをリンクしたり、追加のコンテキストとしてドキュメントを追加したりすることもできます。次を参照してください： [コードとドキュメントの活用](/docs/docs-ja/pentesuto/configure-a-pentest/leveraging-code-and-documentation.md).
* **安全性チェック** – リクエスト頻度と許可されたテスト時間を設定します。次を参照してください： [安全対策](/docs/docs-ja/pentesuto/configure-a-pentest/safety-measures.md).
* **料金** – アセスメントプロファイルを選択し、必要クレジットを確認します。次を参照してください： [ペンテストの料金](/docs/docs-ja/pentesuto/pentest-pricing.md).
  {% endstep %}

{% step %}

### 確認して開始

次の **要約** 手順で、次を確認してください： **Android アプリ** パッケージ名とその他の設定を確認し、次をクリックしてください： **アセスメントを実行**.
{% endstep %}
{% endstepper %}

## 結果を確認

アセスメントを開いて進捗を監視し、その **課題** タブを確認してください。Android の検出結果には、機密データの取り扱い、ネットワークセキュリティ、プラットフォームとの連携、WebView のセキュリティ、クライアント側認証、暗号化、ビルド構成などが含まれる場合があります。

アセスメントが完了すると、アセスメントから PDF をダウンロードできます。次を参照してください： [ペンテストレポート](/docs/docs-ja/pentesuto/coverage-and-findings/pentest-reports.md) 利用可能なレポート種類について。

## お困りですか？

アプリをテストできるか不明な場合や、アクセス設定の सहायताが必要な場合は、次を開いてください： **Intercomチャット** 右下隅にある。私たちのチームがお手伝いします！


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://help.aikido.dev/docs/docs-ja/pentesuto/configure-a-pentest/android-pentesting.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
