Comparison Mobile
Crossfyre vs PCAPdroid
A very good free on-device capture app vs a platform that also gets past pinning.
PCAPdroid is a well-built, free, open-source Android app that captures traffic without root using VpnService, and its mitmproxy addon adds real TLS decryption. For inspecting your own device or an unpinned app, it does the job and costs nothing. Two honest limits: its own documentation is upfront that pinned apps need root, and it is a capture tool rather than a platform. Crossfyre does the same on-device capture, then adds a server-assisted APK repackage so pinned apps open up with no root and no PC, and streams the results into intercept, a node-backed Repeater, and a shared asset graph.
Feature by feature
| Feature | Crossfyre | |
|---|---|---|
| Pricing | Free and open source | Free tier, then from $29/mo |
| No-root capture | yes | yes |
| TLS decryption | mitmproxy addon and a user CA | Built in, with a user CA |
| Pinned apps | Need root, per its own docs | Repackaged, no root, no PC |
| Intercept and modify in flight | no | yes |
| Replay | Not part of it | Repeater, through a node |
| Feeds recon and scanning | no | yes |
Every claim about the other tool is taken from its own documentation and pricing as of mid-2026. Re-check before quoting a number.
Standards
What it covers, and what it will not claim.
Pick a list. Every row that says yes names the class that does the work, and every row that says no says why, because a coverage matrix with no gaps in it is a brochure.
8 covered 1 partly 1 not claimed The list this engine was built against. Eight fully, one partly, and one that nothing on the outside can honestly report.
MITRE ATT&CK is deliberately not here. It describes what an adversary does across a whole intrusion, and almost all of a web scanner collapses into one technique in it. A six-row ATT&CK matrix would look impressive and tell you nothing, which is the opposite of what this section is for.
The honest take
PCAPdroid is a good tool and free, and if you only need to watch traffic from apps that are not pinned, use it. Choose Crossfyre when pinning is the thing standing between you and the request bodies, or when you want the capture to become findings instead of a PCAP file. On-device no-root capture is not our differentiator; getting past pinning without root or a workstation is.
Questions people ask
Is on-device capture without root unique to Crossfyre?
No, and we will not claim it is. PCAPdroid, Reqable, Packet Capture, NetCapture, and HTTP Canary all do VpnService MITM with a user CA. They share the same wall: Android 7 and later distrust user CAs by default, and pinned apps trust only their own certificate.
How does Crossfyre get past pinning if PCAPdroid cannot?
By patching the app rather than the device. The phone uploads the target app’s split APKs plus the session CA, our patch service rewrites and re-signs the app so it trusts your session certificate, and the phone reinstalls the patched splits. Repackaging to defeat pinning is a commodity technique; doing it from the phone with no root and no PC is the part we could find no competitor offering.