Capture and Analyze Android Network Traffic Using a Local Proxy

13 min read Step‑by‑step guide to set up a local proxy (mitmproxy) on your PC, configure Android, install the certificate, and analyze network traffic safely and effectively. September 27, 2026 15:00 How to Capture and Analyze Android Network Traffic with a Local Proxy

When an app behaves oddly, shows unexpected ads, or leaks data, the most direct way to understand what it is doing is to look at the network traffic it generates. Android does not expose raw packets to the user, but you can route the device’s traffic through a local proxy running on a computer, capture the HTTP/HTTPS requests, and inspect them with tools such as mitmproxy. This tutorial walks you through the entire process – from installing the proxy, configuring the Android device, installing the trusted certificate, to analyzing the captured data – while keeping security and privacy in mind.

Why a Local Proxy Works

Most Android apps communicate over HTTP or HTTPS. By pointing the device’s Wi‑Fi proxy settings to a machine that runs a man‑in‑the‑middle (MITM) proxy, you force every request to pass through that machine. The proxy can then log the request URL, headers, body, and response data. For HTTPS, the proxy generates a temporary certificate for each domain; installing the proxy’s root certificate on the device tells Android to trust those certificates, allowing decryption without triggering security warnings.

Before You Start

  • Computer requirements: A Windows, macOS, or Linux PC with Python 3 installed.
  • Network: Both the Android device and the PC must be on the same Wi‑Fi network.
  • Battery: Keep the phone plugged in or ensure at least 50 % battery – the proxy setup can take several minutes.
  • Permissions: You will need to enable Developer options and USB debugging only if you plan to use adb for installing the certificate automatically. The tutorial covers a manual method that works without adb.
  • Legal note: Capture traffic only for apps you own or have permission to inspect. Intercepting traffic from other users or services may violate terms of service or law.

Step 1 – Install mitmproxy on Your PC

  1. Open a terminal (Command Prompt, PowerShell, or macOS/Linux terminal).
  2. Install mitmproxy via pip:
    pip install mitmproxy
    If you do not have pip, install it from pip's official site.
  3. Verify the installation:
    mitmproxy --version
    You should see a version string like mitmproxy 10.0.0.
  4. Start the proxy on the default port 8080:
    mitmproxy
    A console UI will appear, showing live traffic as it passes through.

If the default port 8080 is already used (e.g., by another service), you can start mitmproxy on a different port with mitmproxy -p 8888. Remember the chosen port for the next steps.

Step 2 – Find Your PC’s Local IP Address

  1. On Windows, run ipconfig in Command Prompt and look for the IPv4 address of the Wi‑Fi adapter (e.g., 192.168.1.42).
  2. On macOS/Linux, run ifconfig or ip addr show and locate the address associated with en0 or wlan0.
  3. Write down this address – you will enter it on the Android device.

Step 3 – Configure Android’s Wi‑Fi Proxy Settings

The exact menu names differ slightly between manufacturers, but the path is generally the same.

  1. Open Settings → Network & Internet (or Wi‑Fi on older Android versions).
  2. Tap the name of the Wi‑Fi network you are currently connected to.
  3. Find Advanced or a gear icon, then select Proxy.
    • On Pixel/Android stock: Settings > Network & Internet > Wi‑Fi > [Network] > Advanced > Proxy.
    • On Samsung One UI: Settings > Connections > Wi‑Fi > [Network] > Modify network > Advanced options > Proxy.
  4. Choose Manual.
    • Proxy hostname: enter the PC’s IP address from Step 2.
    • Proxy port: enter 8080 (or the custom port you used).
    • Leave “Bypass proxy for” empty unless you need to exclude local addresses.
  5. Save the settings. Android will now route all HTTP/HTTPS traffic through the proxy.

To verify the proxy is active, open a browser on the phone and navigate to http://mitm.it. You should see a page generated by mitmproxy offering certificate downloads.

Step 4 – Install the mitmproxy Root Certificate on Android

Without the certificate, HTTPS connections will fail with “Your connection is not private” errors because the proxy’s generated certificates are not trusted.

  1. On the phone’s browser, go to http://mitm.it. The page lists download links for Android, Windows, macOS, and Linux.
  2. Tap the Android link. The file mitmproxy-ca-cert.cer will download to the Downloads folder.
  3. Open Settings → Security → Encryption & credentials → Install a certificate → CA certificate (the wording may be Install from storage on some OEM skins).
  4. Select the downloaded mitmproxy-ca-cert.cer. Android will ask you to name the certificate – you can keep the default or call it “mitmproxy”.
    • On Android 9+ the certificate will be stored in the “User” section and will be trusted by browsers and apps that use the system trust store.
    • Some apps (e.g., banking apps) employ certificate pinning and will still reject the proxy. Those apps cannot be inspected without additional steps such as patching the app, which is beyond the scope of this guide.
  5. After installation, you should see a confirmation toast like “Certificate installed”.

Warning: The mitmproxy certificate grants the proxy the ability to read all encrypted traffic from the device. Remove it when you are finished (Settings → Security → Trusted credentials → User → mitmproxy → Disable/Remove) to restore normal security posture.

Step 5 – Capture Traffic with mitmproxy

With the proxy running and the certificate installed, any app that respects the system proxy will have its traffic logged.

  1. On your PC, ensure mitmproxy is still running. The console UI shows each request line by line.
  2. Open an app on the Android device – for example, a news app, a social media client, or a simple web browser.
  3. Observe the traffic appearing in the mitmproxy console. Each entry shows:
    • Request method (GET/POST), URL, and headers.
    • Response status code and headers.
    • Optionally, the request/response body if you press Enter on a line to expand it.
  4. To filter only the traffic of a specific app, you can use the host filter. For example, to see only requests to example.com:
    mitmproxy -p 8080 -R "~d example.com"
    
    (Replace -R with --filter in newer versions.)

If you prefer a graphical interface, you can launch mitmweb instead of mitmproxy. It opens a browser‑based UI at http://127.0.0.1:8081 where you can search, replay, and export flows.

Step 6 – Analyzing Captured Data

Depending on what you are looking for, you might want to extract URLs, API endpoints, or JSON payloads.

  1. In the console UI, press h to open the help screen. Use f to apply a filter, e.g., ~u /api/v1/ to show only URLs containing that path.
  2. To save a session for later analysis, press s and choose a filename (e.g., session.mitm).
  3. Later you can replay the session with:
    mitmproxy -r session.mitm
    This is useful for debugging intermittent bugs.
  4. For deeper inspection, export flows to a HAR file (HTTP Archive) by pressing e and selecting “Export HAR”. The HAR can be opened in Chrome DevTools (Network tab → Import HAR) for a familiar UI.

Step 7 – Common Troubleshooting Scenarios

7.1 No Traffic Appears in mitmproxy

  • Check proxy settings: Re‑open the Wi‑Fi network’s proxy configuration and confirm the IP/port match the PC.
  • Firewall blockage: On Windows, ensure that the firewall allows inbound connections on the proxy port (8080). Add a rule if necessary.
  • App bypasses system proxy: Some apps use their own networking stack (e.g., OkHttp with a hard‑coded proxy). In that case, the traffic will not pass through mitmproxy unless you use a VPN‑based approach like Packet Capture (requires root or a VPN service).

7.2 HTTPS Errors – “Your connection is not private”

  • Make sure the mitmproxy certificate is installed under User credentials, not just the system store.
  • On Android 10+, apps that target API 29+ may require the certificate to be in the Network Security Config. If an app still refuses, it likely uses certificate pinning.

7.3 Proxy Interferes with Other Devices on the Same Network

  • The proxy settings are per‑Wi‑Fi network on the phone, so other devices remain unaffected. However, if you set the PC as a network-wide proxy (e.g., via router), all devices will be routed through it.

7.4 Unexpected Slowdowns

  • Running mitmproxy on a low‑spec laptop can introduce latency. Reduce the amount of logged data by applying filters or using --quiet mode.

Step 8 – Clean Up After Your Session

  • On Android, return to the Wi‑Fi proxy settings and set Proxy to None.
  • Remove the mitmproxy certificate: Settings → Security → Trusted credentials → User → mitmproxy → Disable/Remove.
  • Stop the proxy on the PC by pressing Ctrl+C in the terminal.
  • If you opened any firewall ports, you can close them now.

Cleaning up ensures your device returns to its normal security posture and prevents accidental traffic interception in the future.

Advanced Tips and Alternatives

  • Use a VPN‑based MITM tool: If you need to capture traffic from apps that ignore the system proxy, consider Packet Capture (no root) or tPacketCapture. These create a local VPN on the device and forward traffic through a built‑in proxy.
  • Automate certificate installation with ADB: For bulk testing, you can push the certificate to the device and enable it via adb shell settings put global http_proxy "IP:PORT" and adb root commands. This method is faster but requires USB debugging.
  • Filter by app UID: mitmproxy can be extended with a Python script that reads the Android UID from the X-Android-Package header (if the app adds it). This helps isolate traffic per app.
  • Export to CSV: Use mitmproxy -r session.mitm -w output.csv with a custom script to extract fields like URL, method, response code, and timing for reporting.

With the steps above you now have a reliable, repeatable workflow for intercepting and analyzing Android network traffic. Whether you are debugging an app you develop, checking for unwanted trackers, or verifying that a privacy‑focused VPN is actually routing traffic, a local proxy gives you visibility that the device’s UI alone cannot provide. Remember to always remove the proxy and its certificate when you are done – keeping the device’s security posture intact is as important as the insights you gain.

User Comments (0)

Add Comment
We'll never share your email with anyone else.