Android Application Penetration Testing
Static analysis, runtime testing and actionable reporting
Assess a mock Android application using static and dynamic techniques, validate findings and produce a clear mitigation-focused report.
Why this course
This five-day course develops Android application security-testing skills through a prepared mock application and isolated training devices or emulators. It covers architecture, static analysis, runtime behaviour, network traffic, instrumentation, vulnerability validation and reporting.
Exercises use explicitly authorised training targets and fictional data. Tool results need manual validation, and individual test coverage does not prove an application is free of vulnerabilities. The course is independent training: it does not claim a certification award, provider affiliation or guaranteed exam or professional success.
Learning outcomes
The course teaches participants to:
- Explain Android components, permissions and relevant mobile security risks.
- Prepare a compatible Android security-testing environment.
- Inspect an APK, manifest and decompiled code for selected risks.
- Observe runtime behaviour, logs and network traffic in the mock application.
- Use selected instrumentation to evaluate a training app’s root/integrity and certificate-pinning controls and their limitations.
- Validate storage, component, WebView, cryptographic and logic findings.
- Document reproducible evidence, impact, limitations and practical mitigations.
- Perform a scoped assessment of the supplied mock application.
Prerequisites
- Have a basic understanding of mobile applications and Android architecture.
- Be familiar with penetration testing concepts and techniques.
- Have a working knowledge of Linux commands and networking basics.
A prepared laptop/toolchain and permission to install supplied tools; isolated authorised training apps, emulator images or dedicated test devices are provided or agreed in advance.
5 modules
01Day 1 — Android Security Foundations1 topics
Architecture
- Android OS structure: Kernel, Libraries, Framework, Applications
- Android application lifecycle and components
- Android permission model and security policies
Security and Assessment Context
- Key threats to mobile applications
- Overview of the OWASP Mobile Top 10 and how risk awareness relates to MASVS controls and MASTG test guidance; a Top 10 list is not a complete test plan.
- Secure software development lifecycle (SDLC) for Android
Training Environment
- Configuring Android Studio and ADB
- Use a compatible prepared emulator or dedicated training device; do not assume every tool works on every Android release.
- Inspect a tested training toolset: JADX, apktool, ADB, a proxy such as Burp Suite, Frida and MobSF; versions, device architecture and optional paid features affect availability.
02Day 2 — Static Analysis1 topics
APK Structure and Decompilation
- APK structure and components
- Decompiling APKs using JADX and apktool
Reverse Engineering
- Dissecting AndroidManifest.xml
- Identify sensitive-data exposure and permission/component risks; distinguish necessary permissions from vulnerabilities.
- Introductory smali inspection where useful; avoid claiming exhaustive reverse-engineering expertise.
Selected Static Risks
- Hardcoded sensitive data
- Misconfigured permissions and intents
- Use of outdated libraries and components
03Day 3 — Dynamic Analysis and Instrumentation1 topics
Runtime Behaviour
- Monitoring application behavior during execution
- Analyzing runtime logs using Logcat
Traffic Analysis
- Setting up a proxy with Burp Suite
- Analyse traffic generated by the supplied mock application and its training endpoint.
- TLS/certificate-validation weaknesses and relevant network configuration.
Instrumentation
- Introduction to Frida and Objection
- Instrument and modify selected mock-app behaviour to test a hypothesis.
- Evaluate root-detection and certificate-pinning bypasses in the deliberately testable application; bypassability depends on implementation and environment and is not universal.
04Day 4 — Vulnerability Validation1 topics
Storage and Platform Components
- Assess inappropriate sensitive-data use in SharedPreferences, SQLite and external storage; these mechanisms are not intrinsically vulnerabilities in every context.
- Improper use of WebView and JavaScript bridges
- Misconfigurations in activities and content providers
Logic and Runtime Behaviour
- Validate a selected logic flaw and document a bounded proof of concept on the mock app.
- Debugging applications for hidden behaviors
Security Misconfiguration
- Weak encryption and cryptography practices
- Debuggable apps in production
05Day 5 — Reporting, Mitigation and Assessment1 topics
Evidence and Reporting
- Writing detailed and actionable reports
- Provide reproducible, minimal mock-app proofs of concept with evidence and limitations.
Mitigation Review
- Secure coding guidelines
- Implementing defense-in-depth strategies
Scoped Mock-App Assessment
- Scoped penetration-test exercise on the supplied mock application, not a guarantee of exhaustive coverage.
- Applying learned techniques to identify and report vulnerabilities
Review
- Review of key concepts
- Q&A and next learning steps; no certification award or exam-success promise.
A programme built around your team.
Share your training goals and requirements.