BeVigil - The internet's first and only security search engine for mobile apps

Instantly find the risk score of any app

Search over app metadata

We extract and show the most pertinent data points about a mobile application. Instantly see the risk score of an app. Discover mobile applications with specific that match a specific category, framework package name, developer email, etc. Find permissions, number of downloads, and other metadata about the app.

View and browse through the application code

You will be able to analyze code at scale and easily search for API keys, regexes, etc to see the matches in different files of an application. Analyze quality, patterns, and security bugs in code. Investigate other parts of the application using our application file browser.

Security Report and Risk Score

Find vulnerabilities/ secrets in applications from the APK scanner report. Enable app developers and organizations to be proactive by tracking security issues and repackaging their applications. Find vulnerabilities / secrets in applications.

APK Scanning on demand

Mitigate the risk of irrelevant results for those wishing to discover vulnerabilities within a specific application. Choose to directly upload your application files to the platform.

BeVigil Asset Explorer
Search over millions of digital assets to find valuable insights
Domains: 1M+Subdomains: 987K+IPs: 700K+Mobile Apps: 2M+S3 Buckets: 2M+
Are you looking to find unique subdomains from mobile apps to increase your attack surface coverage?
Use BeVigil Asset Explorer's subdomain finder service to discover over 1.3 million subdomains extracted from nearly 1 million mobile apps.
asset explorer
BeVigil Asset Explorer is helping engineers and researchers from top organizations discover hidden assets.
BeVigil CLI
BeVigil Asset Explorer is also available as a CLI option, allowing users to use and access it from their command line.

Features included with any BeVigil Asset Explorer plan
Discover all domains from mobile apps.
Discover all subdomains from domains.
Discover all S3 buckets from mobile apps.
Discover URL parameters from mobile apps.
Discover security reports of mobile apps.
Discover wordlists from mobile apps.
Discover all assets from mobile apps.
Discover URLs from domains
Discover all mobile apps from domains.