Corellium Falcon
Mobile Vulnerability
Research Solutions

Provides government organizations and researchers with the mobile vulnerability research, exploit introspection, and malware analysis not possible on physical iOS and Android devices.

Corellium Falcon

Capabilities

On-Demand Access

Spin up iOS, iPadOS and Android devices across supported OS versions and device models, including the latest releases. Get root and kernel access with built-in research tools designed for advanced security testing and mobile research.

Powerful Introspection

See what is happening across the OS kernel, processes and subsystem I/O. Inspect logs, file systems, system calls and network traffic in real time. Run scripts and use debugging tools through the integrated Frida console.

Kernel Debugging

Perform advanced security research with deep control over the kernel and boot process. Modify patches, device identifiers, trust caches and device trees. Use kernel hooking, program flow tracing and coverage tracing to investigate system behavior and vulnerabilities.

Snapshots & Cloning

Capture and clone device states at any point in your research. Pause and resume firmware and application activity, then restore previous states to reproduce findings and repeat testing. Share consistent environments across teams to simplify validation and collaboration.

Falcon Mirror Add-On

Start with a Device State Your Research Requires

A clean device gives you a controlled baseline. But some research depends on the context created through real app use, configuration and activity.

Falcon Mirror Add-on lets researchers import supported Inseyets extractions into Falcon, giving them a faster starting point for advanced analysis without rebuilding that device context manually.

Move Beyond Pristine Device States

Start from a clean device or begin with apps, configurations, files and activity already created through your team’s exercised devices and accounts.

Corellium Falcon

Solutions

Mobile Vulnerability
Research Solutions

Research vulnerabilities across iOS, iPadOS and Android with deep system visibility and introspection. Use high-fidelity virtual devices to investigate vulnerabilities, analyze system behavior and validate exploits in a controlled and repeatable environment.

Malware Analysis

Analyze suspicious applications and mobile threats across iOS, iPadOS and Android. Detonate malware in a controlled environment, collect indicators of compromise, inspect runtime behavior and investigate how threats interact with the operating system.

App Pentesting

Perform static and dynamic testing without relying on physical device labs. Give security teams repeatable access to mobile environments for application analysis, pentesting and verification across distributed teams.

Operational Training

Deliver hands-on mobile security training in consistent, repeatable environments. Give instructors and participants browser-based access to the same device configurations without managing or shipping physical devices.

CORELLIUM FALCON

Editions

Falcon Essentials Security Research
Malware & Threat Research
App Pentesting
Falcon Premium Vulnerability Research
Introspection & Reversing
Exploit Analysis & Verification
Team & workspace management
Jailbreak/root any OS
App & file system tools
Frida and Cydia integration
Snapshot & cloning
CoreTrace process tracing
HTTPS Network Monitor
MATRIX test automation
MATRIX AppSec reports
Snapshot Sharing
Advanced Network Monitor
OS kernel and filesystem tools
Run self-signed binaries
Kernel debugging
Kernel patch management
Boot control and modification
Device tree configuration
KASLR configuration
Trust cache modification
OS Beta support
Kernel hooking
Program flow & coverage tracing
MicroSnapshots
IMEI, IMSI, and SN modification
Virtual MMIO
SEP debugging
iBoot/BootROM debugging

Corellium Falcon

Deployments

Onsite Appliances

Corellium server and desktop appliances use the latest Arm processors and are air-gapped for use in high-security environments.

Cloud Services

The Corellium cloud service runs on AWS using the latest Amazon Graviton servers. (Not offered for Corellium Falcon Premium Edition)

Private Servers

Customers can host Corellium servers in their own AWS cloud, or we can host them in our AWS cloud. (Not offered for Corellium Falcon Premium Edition)

Corellium Virtual Hardware Platform

Corellium Falcon is built upon our revolutionary virtual hardware platform. It’s designed to provide your R&D teams with the powerful tooling they need to stay ahead at the cybersecurity battlefront.

We’re here to help you revolutionize your security and development practices with pioneering technology