> For the complete documentation index, see [llms.txt](https://help.aikido.dev/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://help.aikido.dev/docs/docs-ja/pentesuto/configure-a-pentest/android-pentesting.md).

# Androidアプリのペンテスト

ネイティブまたはハイブリッドAndroidアプリをテストするためにAikido Pentestを設定します。

Aikido Pentest は、ネイティブおよびハイブリッド Android アプリを以下を通じて評価できます **ホワイトボックステスト**. Blackbox Android のペネトストはまだサポートされていないため、Android アプリのソースコードを含むリポジトリを接続する必要があります。

以下のウォークスルーを視聴するか、さらに下の手順ガイドに従ってください。

{% embed url="<https://www.youtube.com/watch?v=EGzGZIr2rn4>" %}

{% hint style="warning" %}
本番環境を忠実に再現したテスト環境で評価を実施してください。本番データやアカウントは使用しないでください。
{% endhint %}

{% hint style="info" %}
**ホワイトボックスのみ:** Aikido は現在、APK のみではなく、アプリのソースコードに対して Android ペネトストを実施します。Android アプリのリポジトリを **コードとドキュメント** 評価を開始する前のステップで添付してください。
{% endhint %}

### 前提条件

開始する前に、以下を用意してください:

* **ペンテスト管理** [権限](/docs/docs-ja/hajimeni/automated-user-management/setting-roles-and-permissions.md)
* **十分なクレジット** あなたの [ウォレット内に](/docs/docs-ja/miscellaneous-info/wallet-and-credits.md)
* **Android アプリのソースコード** Aikido に接続できるリポジトリ内にあるもの（ホワイトボックステストでは必須）
* **テスト用 APK** アップロード準備済み（最大 500 MB、証明書ピンニング、root 検出、エミュレーター検出なし）

## Android 評価を作成

{% stepper %}
{% step %}

### Android を選択

その後、Splunk Cloud と Splunk Enterprise の両方でトークンを作成します: **ペンテスト**を開き、 **プロジェクト**をクリックして **評価を作成**。 **何をペネトストしますか？** の手順で、 **Android**.

<div data-with-frame="true"><figure><img src="https://715870456-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FyKbzcQGrx7UtrG0nPZZ7%2Fuploads%2Fgit-blob-08e4b139a10f92abbfa51e2b5161d26bb460864a%2FScreenshot%202026-07-13%20at%2018.01.39.png?alt=media" alt=""><figcaption></figcaption></figure></div>
{% endstep %}

{% step %}

### テスト範囲を定義

次の場所で **スコープ** のステップで、アプリにバックエンド API がある場合は、その URL を追加してください（たとえば、 `https://api.application.com`）Aikido がアプリで使用するエンドポイントをテストし、適切なカバレッジを確保できるようにします。次に APK をアップロードしてください（最大 500 MB）。アプリでは証明書ピンニング、root 検出、エミュレーター検出を使用してはいけません。Aikido はパッケージ名を自動的に抽出します。

選択 **アプリケーション全体をテスト** または **特定の部分のみをテスト**、アプリのどの程度を評価したいかによって異なります。

<div data-with-frame="true"><figure><img src="https://715870456-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FyKbzcQGrx7UtrG0nPZZ7%2Fuploads%2Fgit-blob-8beefa4c0474be9f4c2663520cfe5015a6f24695%2FScreenshot%202026-07-13%20at%2018.02.22.png?alt=media" alt=""><figcaption></figcaption></figure></div>
{% endstep %}

{% step %}

### テストユーザーを追加

Aikido にテストさせたい各ロールごとにテストユーザーを追加してください。たとえば、管理者、標準ユーザー、または別テナントのユーザーです。ユーザー名とパスワードによる認証では、Aikido はログイン URL の代わりに Android アプリのパッケージ名を使用します。

評価を開始する前に、ログインの事前チェックを使用して Aikido がアプリにアクセスできるか確認できます。詳細は [テストユーザーの設定](/docs/docs-ja/pentesuto/configure-a-pentest/setting-up-authenticated-testing.md).

<div data-with-frame="true"><figure><img src="https://715870456-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FyKbzcQGrx7UtrG0nPZZ7%2Fuploads%2Fgit-blob-44377185e5e64dd13e6aa9cfd4fb03b11ccecee2%2FScreenshot%202026-07-13%20at%2018.06.13.png?alt=media" alt=""><figcaption></figcaption></figure></div>
{% endstep %}

{% step %}

### アクセス、コンテキスト、安全性を設定

ウィザードの残りのステップを設定します:

* **許可されたドメイン** – テスト中にアプリがアクセスする必要のあるドメインを許可します。
* **コードとドキュメント** – **必須:** Android アプリのソースコードを含むリポジトリを接続してください。Aikido はホワイトボックス Android ペネトストのみをサポートしているため、コードベースを添付しないと評価を実行できません。バックエンドのリポジトリをリンクし、追加のコンテキストとしてドキュメントを追加することもできます。詳細は [コードとドキュメントの活用](/docs/docs-ja/pentesuto/configure-a-pentest/leveraging-code-and-documentation.md).
* **安全性チェック** – リクエストレートと許可されたテスト時間を設定します。詳細は [安全対策](/docs/docs-ja/pentesuto/configure-a-pentest/safety-measures.md).
* **価格** – 評価プロファイルを選択し、必要クレジット数を確認します。詳細は [ペネトストの料金](/docs/docs-ja/pentesuto/pentest-pricing.md).
  {% endstep %}

{% step %}

### 確認して開始

次の場所で **要約** のステップで、次を確認してください。 **Android アプリ** パッケージ名とその他の設定を確認し、次に **評価を実行**.
{% endstep %}
{% endstepper %}

## 結果を確認

評価を開いて進捗を監視し、その **問題** タブを確認してください。Android の検出結果には、機密データの取り扱い、ネットワークセキュリティ、プラットフォームとの連携、WebView セキュリティ、クライアントサイド認証、暗号化、ビルド構成などが含まれます。

評価が完了したら、評価画面から PDF をダウンロードできます。詳細は [ペンテストレポート](/docs/docs-ja/pentesuto/coverage-and-findings/pentest-reports.md) 利用可能なレポート種類を参照してください。

## ヘルプが必要ですか？

アプリをテストできるかどうか不明な場合、またはアクセス設定のサポートが必要な場合は、次を開いてください。 **Intercomチャット** を右下隅で開いてください。私たちのチームがサポートします！


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://help.aikido.dev/docs/docs-ja/pentesuto/configure-a-pentest/android-pentesting.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
