Intelligence tagged Breaking Down Breach Logic

Cyber Intelligence Weekly
Join Echelon’s 31K+ subscribers and stay current on cybersecurity trends and insights.
iOS App Pentest: Dumping certificate and private key from Keychain
iOS App Pentest: Dumping certificate and private key from Keychain
Diego Pérez Barrueta, Senior Offensive Security Consultant at Echelon, walks through how to intercept mTLS traffic on an iOS app pentest when SSLKillSwitch isn't enough, extracting the client certificate and private key from the Keychain using Frida, and importing them into Burp Suite as a PKCS#12 file to establish full mTLS communication.
Posted on Mar 31 / 2026
Are you ready to get started?