When an app behaves oddly, shows unexpected ads, or leaks data, the most direct way to understand what it is doing is to look at the network traffic it generates. Android does not expose raw packets to the user, but you can route the device’s traffic through a local proxy running on a computer, capture the HTTP/HTTPS requests, and inspect them with tools such as mitmproxy. This tutorial walks you through the entire process – from installing the proxy, configuring the Android device, installing the trusted certificate, to analyzing the captured data – while keeping security and privacy in mind.
Most Android apps communicate over HTTP or HTTPS. By pointing the device’s Wi‑Fi proxy settings to a machine that runs a man‑in‑the‑middle (MITM) proxy, you force every request to pass through that machine. The proxy can then log the request URL, headers, body, and response data. For HTTPS, the proxy generates a temporary certificate for each domain; installing the proxy’s root certificate on the device tells Android to trust those certificates, allowing decryption without triggering security warnings.
Python 3 installed.adb for installing the certificate automatically. The tutorial covers a manual method that works without adb.mitmproxy via pip:
pip install mitmproxy
If you do not have pip, install it from pip's official site.mitmproxy --version
You should see a version string like mitmproxy 10.0.0.mitmproxy
A console UI will appear, showing live traffic as it passes through.If the default port 8080 is already used (e.g., by another service), you can start mitmproxy on a different port with mitmproxy -p 8888. Remember the chosen port for the next steps.
ipconfig in Command Prompt and look for the IPv4 address of the Wi‑Fi adapter (e.g., 192.168.1.42).ifconfig or ip addr show and locate the address associated with en0 or wlan0.The exact menu names differ slightly between manufacturers, but the path is generally the same.
Settings > Network & Internet > Wi‑Fi > [Network] > Advanced > Proxy.Settings > Connections > Wi‑Fi > [Network] > Modify network > Advanced options > Proxy.8080 (or the custom port you used).To verify the proxy is active, open a browser on the phone and navigate to http://mitm.it. You should see a page generated by mitmproxy offering certificate downloads.
Without the certificate, HTTPS connections will fail with “Your connection is not private” errors because the proxy’s generated certificates are not trusted.
http://mitm.it. The page lists download links for Android, Windows, macOS, and Linux.mitmproxy-ca-cert.cer will download to the Downloads folder.mitmproxy-ca-cert.cer. Android will ask you to name the certificate – you can keep the default or call it “mitmproxy”.
Warning: The mitmproxy certificate grants the proxy the ability to read all encrypted traffic from the device. Remove it when you are finished (Settings → Security → Trusted credentials → User → mitmproxy → Disable/Remove) to restore normal security posture.
With the proxy running and the certificate installed, any app that respects the system proxy will have its traffic logged.
mitmproxy is still running. The console UI shows each request line by line.Enter on a line to expand it.example.com:
mitmproxy -p 8080 -R "~d example.com"
(Replace -R with --filter in newer versions.)If you prefer a graphical interface, you can launch mitmweb instead of mitmproxy. It opens a browser‑based UI at http://127.0.0.1:8081 where you can search, replay, and export flows.
Depending on what you are looking for, you might want to extract URLs, API endpoints, or JSON payloads.
h to open the help screen. Use f to apply a filter, e.g., ~u /api/v1/ to show only URLs containing that path.s and choose a filename (e.g., session.mitm).mitmproxy -r session.mitm
This is useful for debugging intermittent bugs.e and selecting “Export HAR”. The HAR can be opened in Chrome DevTools (Network tab → Import HAR) for a familiar UI.Packet Capture (requires root or a VPN service).Network Security Config. If an app still refuses, it likely uses certificate pinning.--quiet mode.Ctrl+C in the terminal.Cleaning up ensures your device returns to its normal security posture and prevents accidental traffic interception in the future.
Packet Capture (no root) or tPacketCapture. These create a local VPN on the device and forward traffic through a built‑in proxy.adb shell settings put global http_proxy "IP:PORT" and adb root commands. This method is faster but requires USB debugging.X-Android-Package header (if the app adds it). This helps isolate traffic per app.mitmproxy -r session.mitm -w output.csv with a custom script to extract fields like URL, method, response code, and timing for reporting.With the steps above you now have a reliable, repeatable workflow for intercepting and analyzing Android network traffic. Whether you are debugging an app you develop, checking for unwanted trackers, or verifying that a privacy‑focused VPN is actually routing traffic, a local proxy gives you visibility that the device’s UI alone cannot provide. Remember to always remove the proxy and its certificate when you are done – keeping the device’s security posture intact is as important as the insights you gain.









