Mobile Application Penetration Testing (iOS & Android)
Frida dynamic instrumentation, OWASP MASVS audits, SSL pinning bypass, and APK/IPA reverse engineering.
Course Overview & Objectives
Learn how to decompile, audit, and instrument Android APKs and iOS IPAs. Master Frida hooking, jailbreak/root detection bypass, local data storage exploitation, and insecure IPC communications.
What You Will Master
- Decompile Android APKs with JADX-GUI and reverse engineer Dalvik bytecode
- Bypass SSL certificate pinning dynamically using Frida and Objection scripts
- Extract sensitive cryptographic keys and session tokens from SQLite and Keychain storage
- Identify and remediate Android exported component vulnerabilities
Prerequisites
- Basic Java/Kotlin or Swift familiarity
- Understanding of client-server APIs
Platforms & Tools Covered
Detailed Curriculum Modules
1 modules structured from foundational theory through complex adversarial execution.
Android Security Internals & Static Analysis
APK structure, AndroidManifest.xml analysis, and decompilation with JADX.
Hands-on Virtual Sandbox Labs
Zero local hardware dependencies. Provisioned in cloud containers via browser terminal.
Dynamic SSL Pinning Bypass with Frida
Write custom Frida Javascript hooks to override SSLContext trust verification.
Faculty & Lead Instructor
Direct weekly instruction, live office hours, and code-review feedback.
Rohan Mehta
Thread Security EducationSenior Mobile Security Researcher
Specialist in mobile application vulnerabilities and zero-day discoveries in commercial iOS and Android applications.
Frequently Asked Questions
Everything you need to know about scheduling, cohort admissions, and lab access.
Do I need physical rooted phones?
No, our cloud sandbox provides virtualized pre-rooted Android emulators and jailbroken Corellium iOS instances.
Ready to Master Mobile Application Penetration Testing (iOS & Android)?
Join the upcoming cohort. Seats are limited to maintain a high faculty-to-student ratio and rigorous sandbox feedback.