Full course

Mobile Application Penetration Testing

This course provides tools and methodology for conducting a security assessment of a mobile application using a "black box" approach, simulating the activities performed by a potential attacker. It includes practical exercises conducted on intentionally vulnerable apps.

Details

Course overview

The objective of this course is to equip participants with the knowledge and skills required to perform effective security assessments of mobile applications. Using a "black box" testing methodology based on the OWASP Mobile Application Security Testing Guide (MASTG), the training will guide participants through the process of evaluating the security posture of mobile apps, without requiring prior access to the underlying source code. Participants will be introduced to a suite of tools and techniques, enabling them to systematically discover and address potential security weaknesses. This course is aimed at auditors and security specialists. This is a foundational course; for a professional assessment of your own systems, see our expert-led application security assessment service.

Requirements

  • Basic knowledge of mobile application architecture and functioning

  • Curiosity about hacking and cybersecurity topics.

Course content

  • Introduction to Application Security: An overview of fundamental concepts in application security.

  • Overview of Mobile Application Testing Methodology: Understanding the methodology for testing mobile applications, based on the OWASP Mobile Application Security Testing Guide (MASTG).

  • Tools and Resources: Introduction to various tools and resources available for conducting mobile application security assessments.


  • Jailbreaking and Rooting Devices: Exploring techniques for bypassing device security mechanisms.

  • Decompiling the Application and Static Code Analysis: Techniques for analyzing the code of a mobile application.

  • Intercepting Network Traffic and testing Communication Security: Strategies for testing the security of communication channels.


  • Analyzing Data stored by the Application on the Device: Techniques for examining data stored locally by the application.

  • Testing Local Authentication Mechanisms: Strategies for assessing the security of local authentication methods.

  • Testing Input Validation: Techniques for evaluating the security of input validation mechanisms.


  • Testing Interaction with third-party Applications: Assessing the security implications of interactions with third-party applications.

  • Testing Improper use of Platform Features: Strategies for identifying and mitigating security risks arising from improper use of platform features.

  • Testing Backend Security (REST APIs and web services): Techniques for assessing the security of backend systems and services.


Your instructor

  • TBD Senior Instructor

Related courses
  • Full course

    Web Application Penetration Testing

    Offensive
    ~32 hours
    Online

    Black-box and gray-box testing of web applications with Burp Suite, based on the OWASP WSTG methodology.

    DISCOVER MORE
  • Full course

    Build Secure Android Applications

    Defensive
    ~24 hours
    Online

    Secure development for native Android apps: data storage, communication and use of the platform APIs.

    DISCOVER MORE
  • Full course

    Build Secure iOS Applications

    Defensive
    ~24 hours
    Online

    Secure development for native iOS apps: data handling, Keychain and the platform's security features.

    DISCOVER MORE
  • Full course

    Ethical Hacking Fundamentals

    Fundamentals
    ~32 hours
    Online

    An introduction to offensive security: reconnaissance, exploitation and how an attacker thinks.

    DISCOVER MORE
  • new

    Full course

    Secure Coding with AI

    Defensive
    ~32 hours
    Online

    Use AI coding assistants securely, with Copilot, Codex, Claude Code and SAST tools, to find and fix vulnerabilities as you write code.

    DISCOVER MORE