Mobile SecurityIntermediate Level55 Hours Live

Mobile Application Penetration Testing (iOS & Android)

Frida dynamic instrumentation, OWASP MASVS audits, SSL pinning bypass, and APK/IPA reverse engineering.

Frida & Objection Dynamic Hooking
OWASP MASVS / MSTG Standards
iOS Keychain & Android Keystore Audits
55 Hours Practical Workload
1 Core Modules
1 Sandboxed Labs
Cryptographic TS-ID Verifiable

Course Overview & Objectives

Learn how to decompile, audit, and instrument Android APKs and iOS IPAs. Master Frida hooking, jailbreak/root detection bypass, local data storage exploitation, and insecure IPC communications.

What You Will Master

  • Decompile Android APKs with JADX-GUI and reverse engineer Dalvik bytecode
  • Bypass SSL certificate pinning dynamically using Frida and Objection scripts
  • Extract sensitive cryptographic keys and session tokens from SQLite and Keychain storage
  • Identify and remediate Android exported component vulnerabilities

Prerequisites

  • Basic Java/Kotlin or Swift familiarity
  • Understanding of client-server APIs

Platforms & Tools Covered

FridaObjectionJADX-GUIMobSFBurp SuiteGhidra

Detailed Curriculum Modules

1 modules structured from foundational theory through complex adversarial execution.

55 Total Workload Hours
MODULE 01

Android Security Internals & Static Analysis

2 Lessons

APK structure, AndroidManifest.xml analysis, and decompilation with JADX.

Analyzing Smali Code and Finding Hardcoded Secrets
45m
Automated Vulnerability Triage with MobSF
50m

Hands-on Virtual Sandbox Labs

Zero local hardware dependencies. Provisioned in cloud containers via browser terminal.

LAB 01~55 mins

Dynamic SSL Pinning Bypass with Frida

Write custom Frida Javascript hooks to override SSLContext trust verification.

Skills Tested:Frida, SSL Pinning

Faculty & Lead Instructor

Direct weekly instruction, live office hours, and code-review feedback.

RM

Rohan Mehta

Thread Security Education

Senior Mobile Security Researcher

Specialist in mobile application vulnerabilities and zero-day discoveries in commercial iOS and Android applications.

Frequently Asked Questions

Everything you need to know about scheduling, cohort admissions, and lab access.

Do I need physical rooted phones?

No, our cloud sandbox provides virtualized pre-rooted Android emulators and jailbroken Corellium iOS instances.

Ready to Master Mobile Application Penetration Testing (iOS & Android)?

Join the upcoming cohort. Seats are limited to maintain a high faculty-to-student ratio and rigorous sandbox feedback.