AltMap turns your Android phone into a web application security scanner — no laptop required. Scan targets against 10,000+ CVE templates, write custom YAML templates in-app, and let Smart Target Profiling match the exact vulnerabilities relevant to your target. Built for bug bounty hunters and security researchers who don't want their workflow tied to a desk. Hunt from anywhere. 🔐
Hey Product Hunt! 👋 Maker here.
The idea for AltMap was born out of pure frustration.
I do bug bounty hunting on the side — and like a lot of researchers, I don't always have my laptop with me. I'd be somewhere, spot an interesting target, and just... have to wait. Every tool I needed — vulnerability scanners, SQLi engines, XSS testers — was locked behind a desktop. Your phone was basically useless for real security work.
So I asked myself: why does it have to be this way?
The Problem I Set Out to Solve
Web application security testing has a serious accessibility gap. The tools are powerful but they assume you're sitting at a workstation. Bug bounty hunters, students, and researchers in emerging markets — people who often work entirely from mobile — are left with watered-down alternatives that can't do anything meaningful.
AltMap's core mission is simple: put a real, desktop-grade web pentesting suite in your pocket.
How It Evolved
It started small — just a basic CVE template scanner. But the more I used it in real hunts, the more I hit walls. Modern web apps are JavaScript-heavy. Traditional scanners were blind to AJAX calls, dynamically loaded forms, hidden API endpoints. I was missing vulnerabilities that a real browser would catch.
That pushed me to build the JS Crawl engine — a hidden WebView that actually executes JavaScript during scans and intercepts background network requests. That was the turning point. Suddenly, parameters that no static scanner would ever touch were getting tested.
From there, the SQL injection engine grew to include WAF bypass tamper scripts. The XSS module got a live floating browser for manual payload testing. The template library crossed 10,000+ CVEs. Version 1.6 is honestly a completely different product from where it started.
What's Next
I'm actively working on improving scan accuracy (squashing false positives in the SQL engine is a priority right now) and hardening the vulnerability scanner flows. The goal is for every result AltMap reports to be something you can confidently put in a bug bounty report.
Would love to hear from anyone doing bug bounty hunting — what features would make your mobile workflow faster? 🙏
Happy to answer any questions below! 🔐