Mobile Application Pentesting
Mobile apps often store sensitive data insecurely. We test your iOS and Android apps for exploitable weaknesses in the binary, the runtime and the backend they talk to.
Who this is for
Engineering and security teams preparing for a release, a customer security review, or a procurement questionnaire — and anyone who needs to know what an attacker could actually reach.
Methodology
What We Test
- iOS and Android application binaries (IPA/APK)
- Insecure data storage (Keychain, Keystore, Logs, DBs)
- Communication security (Certificate Pinning, SSL/TLS)
- Runtime manipulation and jailbreak/root detection
- Backend API vulnerabilities (Authentication, Logic)
- Reverse engineering resistance and obfuscation
How We Test
We use static analysis (SAST) to review code and configs, and dynamic analysis (DAST) using tools like Frida and Objection to hook into running processes, bypass checks, and tamper with logic. We intercept traffic to test the API layer thoroughly.
What You Receive
- Findings on binary, data, and network security
- Guidance on implementing secure storage and comms
- Recommendations for hardening against tampering
- Retest and written verification of the fixes you apply, in a form you can attach to a store review
How an engagement runs
-
Scope & authorisation
We agree exactly what is in scope, what is explicitly out, and the conditions under which we stop. Nothing starts without written authorisation from someone able to give it. NDA first if you want one.
-
Access & prerequisites
We tell you up front what we need — test accounts at each privilege level, a non-production environment where that applies, documentation, and a named technical contact. Missing prerequisites are the usual reason assessments slip.
-
Reconnaissance & threat modelling
We map the real attack surface and decide which paths are worth the time, based on how your system is actually built rather than a generic checklist.
-
Manual testing & validated exploitation
Testing is hands-on. Findings are reproduced before they are written up, so you are not sent unverified scanner output. Critical issues are raised as soon as we confirm them rather than held for the report.
-
Report & walkthrough
You get an executive summary your board can read and technical detail your engineers can act on — including reproduction steps, what we tested that held, and what was out of scope. We walk your team through it.
-
Retest
Once you have fixed the findings we retest them and confirm in writing what is closed. Retest scope and window are agreed in your scope document before the engagement begins.
Toolkit
- Frida
- Objection
- MobSF
- Burp Suite
- ADB
