AltMap: Bug Bounty & Pentest

Contains adsIn-app purchases
Content rating
Everyone
100+
Downloads
Content rating
Everyone
Learn more
Screenshot image
Screenshot image
Screenshot image
Screenshot image
Screenshot image
Screenshot image
Screenshot image
Screenshot image
Screenshot image
Screenshot image
Screenshot image
Screenshot image
Screenshot image
Screenshot image
Screenshot image
Screenshot image
Screenshot image
Screenshot image
Screenshot image
Screenshot image
Screenshot image
Screenshot image
Screenshot image
Screenshot image

About this app

AltMap: Web Pentesting in Your Pocket

Transform your Android device into a desktop-grade web application vulnerability scanner. Designed specifically for ethical hackers, bug bounty hunters, and security researchers, AltMap automates the heavy lifting of web security auditing so you can hunt for bounties from anywhere.

With our massive Version 1.6 update, AltMap introduces advanced SQL Injection and XSS engines capable of bypassing WAFs and intercepting background network traffic to find web vulnerabilities that traditional scanners miss.

🔥 KEY FEATURES 🔥

📚 10,000+ Vulnerability Templates (CVEs) • Instantly scan web targets against a massive, constantly updated database of over 10,000 known vulnerabilities, exposures, and misconfigurations. • Custom Templates: Write and edit your own custom YAML templates directly in the app to test for proprietary vulnerabilities and zero-days.

🛡️ Advanced SQL Injection Engine • Deep-scan URL parameters and POST data with highly customizable risk, level, and depth settings. • Equip 12 built-in tamper scripts to bypass Web Application Firewalls (WAFs), including space2comment, apostrophemask, base64encode, randomcase, and more. • Configure scans to stop on the first vulnerability found, or silently collect all vulnerabilities for a comprehensive bug bounty report.

👾 Live XSS Scanner & Auto-Crawler • Manual Mode: Test payloads directly inside a live, floating browser. Inject payloads with a single tap and verify JS execution on the fly! • Auto Mode: Set your crawl depth and let the scanner automatically traverse links and inject Cross-Site Scripting (XSS) payloads across the entire target application.

🤖 Smarter "JS Crawl" with WebView Interception Traditional scanners miss modern web apps. AltMap utilizes a hidden WebView engine during automated SQL and XSS scans to execute JavaScript, intercept background AJAX/Fetch network requests, and extract hidden forms—ensuring no parameter goes untested.

⚡ Assisted Scans & Automation Orchestration • Smart Target Profiling: Automatically extracts keywords and technologies from your target URL/Domain to instantly find the exact CVE templates you need. • Orchestrate massive Full Scans from a single dialog: run your matched templates, SQL injection, and XSS scans simultaneously! • Granular control over your bulk scans with customizable thread counts, rate limits, import from csv, batch processing and campaign defined bullk scans.


## Upcoming / TODOs
- [ ] **SQL Scanner Engine**: Investigate and fix false positive results reported by the SQL scanner.
- [ ] **Vuln Scanner Flows**: Fix and improve the flow templates for the Vulnerability Scanner to ensure robust payload execution and detection.


⚠️ LEGAL DISCLAIMER & TERMS OF USE AltMap is a professional network auditing and penetration testing tool designed exclusively for ethical hackers, bug bounty hunters, and system administrators. You may only use this tool on networks, web applications, and infrastructure that you own, or where you have been granted explicit, documented permission to test. Unauthorized access or scanning of third-party networks is strictly prohibited and illegal. The developers of AltMap assume no liability and are not responsible for any misuse, damage, or legal consequences caused by this application.
Advanced web vulnerability, SQLi, and XSS scanner for bug bounty hunters.
Updated on
Aug 27, 2026

Data safety

Safety starts with understanding how developers collect and share your data. Data privacy and security practices may vary based on your use, region, and age. The developer provided this information and may update it over time.
  • This app may share these data types with third parties
    Personal info
  • This app may collect these data types
    Personal info
  • Data is encrypted in transit

What’s new

Fixed union sql injection false positive case.
Added Bug Reporting.
Fixed errors in assisted scan.
Content rating
Everyone
Learn more

App support

About the developer
Mohammed Ahmed Mohammed Gabr
dev.3agamy@gmail.com
7 Ahmed Balegh Ain Shams القاهرة 4541473 Egypt