Offensive Security, Defensive Security

CA203: Mobile Penetration Testing

Course authored by:

Perparim Mjeku, Rinor Shehu, Altin Gashi

15 Hours of Instruction

Includes lectures, guest speakers, and Q&A sessions

Hands-on
labs

12 Labs

Live Online or On-Demand Access

Join weekly synchronous sessions or access all material and recorded lectures anytime

Beginner to Intermediate Level

Building foundational skills toward practical application and competency

Course Materials

Available after purchase

Course Overview

Every app installed on a device is an attack surface — and most organizations have no visibility into what that exposure looks like. This course builds practical capability in assessing Android and iOS applications across the full penetration testing process. You work through static and dynamic analysis, traffic interception, and exploitation using Android Debug Bridge, Burp Suite, and Frida. By the end, you can identify and exploit mobile application vulnerabilities to professional standards.

What You’ll Learn

* Understand Android and iOS architectures and their attack surfaces
* Identify common vulnerabilities including insecure storage and weak cryptography
* Conduct static analysis through reverse engineering and code inspection
* Perform dynamic analysis and network traffic interception using Frida and Burp Suite
* Exploit vulnerabilities and validate security weaknesses in real mobile applications

Business Takeaways

* Minimize exposure to data breaches caused by mobile vulnerabilities
* Strengthen protection of user data across Android and iOS platforms
* Support compliance with mobile security standards and regulations
* Reduce financial and reputational impact of mobile-targeted incidents

Syllabus: 3 Sections to Transformation

The CA203 program immerses you in the world of mobile security, where applications, devices, and operating systems become your attack surface. It spans everything from understanding platform internals to building testing environments and executing real-world analysis and exploitation techniques.

syllabus overview

Justify Training to Your Manager

section 1

FOUNDATIONS: MOBILE SECURITY & PLATFORM ARCHITECTURE

Establish a strong understanding of mobile security concepts and threat models across devices. Explore Android and iOS internals to see how architecture decisions influence vulnerabilities.

TOPICS COVERED

  • Mobile pentesting concepts and attack surface (device, app, network).
  • Data at rest vs data in motion risks.
  • Android architecture (layers, Dalvik VM, HAL, kernel).
  • Android security model (sandboxing, UID isolation).
  • iOS architecture (Cocoa Touch, Core OS layers).
  • Jailbreaking vs rooting and security implications.

LABS

  • Insecure Data Storage
  • Manually Sign APKs
  • Jailbraking & Rooting

section 2

ENVIRONMENT: SETUP, TOOLING & TESTING METHODOLOGY

Transition into building a complete mobile testing lab and workflow. Learn how testers intercept, analyze, and evaluate mobile application behavior.

TOPICS COVERED

  • Setting up lab (Genymotion, Android SDK).
  • ADB usage and device interaction.
  • Application deployment and debugging.
  • Mobile pentesting methodology and workflow.
  • Network traffic analysis and Burp Suite integration.
  • OWASP Mobile Top 10 vulnerabilities.

LABS

  • Setting up Genymotion with Burp Suite
  • Setting up Frida
  • Drozer
  • Mobile App Traffic Analysis

section 3

EXECUTION: ANALYSIS, INSTRUMENTATION & EXPLOITATION

Move into hands-on analysis techniques used by real mobile testers. Break applications through static, dynamic, and exploitation-driven approaches.

TOPICS COVERED

  • Static analysis (JADX, APKTool, reverse engineering).
  • Identifying hardcoded secrets and weak logic.
  • Dynamic analysis (Frida, Logcat, runtime inspection).
  • Network traffic capture and manipulation.
  • Mobile attack vectors and real-world exploits.
  • Malware case studies and exploitation techniques.

LABS

  • Static Analysis with jd-gui
  • Static analysis with MobSF
  • Frida Memory Dump
  • Exploit the Android through PhoneSploit
  • Android Payload with Metasploit

Course Schedule
& Pricing

Looking for Group Purchase Options? See below

Next Start Date

March 5, 2026

Duration

14 Weeks Intensive

Format

Live with Zoom Meeting

What's Included

499€

Seats Filling Fast for January 2026

Location

Start Date

Start Time

Prishtina, Kosovo

March 20, 2026

10:30 AM (CEST)

Prishtina, Kosovo

April 15, 2026

4:30 PM (CEST)

Prishtina, Kosovo

May 10, 2026

11:00 AM (CEST)

Next Start Date

March 5, 2026

Duration

14 Weeks Intensive

Format

Live with Zoom Meeting

What's Included

499€

Seats Filling Fast for January 2026

Location

Start Date

Start Time

Prishtina, Kosovo

March 20, 2026

10:30 AM (CEST)

Prishtina, Kosovo

April 15, 2026

4:30 PM (CEST)

Prishtina, Kosovo

May 10, 2026

11:00 AM (CEST)

Next Start Date

March 5, 2026

Duration

14 Weeks Intensive

Format

Live with Zoom Meeting

What's Included

499€

Seats Filling Fast for January 2026

Location

Start Date

Start Time

Prishtina, Kosovo

March 20, 2026

10:30 AM (CEST)

Prishtina, Kosovo

April 15, 2026

4:30 PM (CEST)

Prishtina, Kosovo

May 10, 2026

11:00 AM (CEST)

Frequently Asked Questions

Mission-critical information for prospective operatives

Why are mobile applications considered a high-risk attack surface?

Mobile applications operate on user devices, connect over untrusted networks, and interact with multiple services such as APIs, sensors, and third-party integrations. This combination creates a wide attack surface where sensitive data can be exposed both on the device and during transmission.

Mobile security focuses on protecting data stored on the device (data at rest) and data transmitted over networks (data in motion). Each presents different risks, such as local data extraction from a stolen device or interception of traffic through man-in-the-middle attacks.

Mobile apps interact with multiple input sources like Bluetooth, SMS, camera, and NFC, and communicate with backend services. These additional entry points introduce more opportunities for attackers to inject data, manipulate behavior, or extract sensitive information.

Typical issues include insecure data storage, lack of encryption, improper input validation, hardcoded credentials, and insufficient protection against reverse engineering. These weaknesses often result from poor security design or misconfigurations.

Mobile penetration testing simulates real attack scenarios to identify vulnerabilities before attackers do. It helps organizations understand how their applications can be compromised and provides actionable insights to fix weaknesses and strengthen overall security.

0
    Your Cart
    Your cart is empty