

Grant Douglas
Mobile Reverser

Grant has over 15 years of mobile security specialism and has built and contributed to open source mobile security tooling. Grant has worked in both engineering and red team roles and has worked on multiple SAST & DAST mobile security products.
Grant now spends most of his time reversing advanced mobile anti-tamper, and building robust mobile anti-tamper defences.
The Runtime Strikes Back
Dynamic instrumentation is one of the most powerful techniques in mobile app reversing, but modern apps are no longer passive targets. Through RASP, anti-tamper checks, environmental detection, integrity monitoring, and runtime self-defence, apps are increasingly aware of when they are being observed.
This talk explores the cat-and-mouse game between mobile analysts and applications that actively resist inspection. We will look at the broad categories of anti-instrumentation techniques used in real-world iOS and Android apps, how they affect the reversing workflow, and how analysts can adapt without relying on brittle one-off bypasses.
We will also discuss the role of newer tooling, lower-level visibility, custom instrumentation strategies, and LLMs in helping triage noisy traces, explain unfamiliar code paths, identify suspicious patterns, and accelerate the loop between observation and hypothesis.
