[ Applications ]
Mobile Application Penetration Testing
- Typical duration
- 6-10 days
- Starting price
- Scoped
- You provide
- Builds for both platforms, test accounts
[ 01 / The engagement ]
A mobile app is three targets in one: the binary on the device, the transport between it and you, and the backend it talks to. We test all three on real hardware, including jailbroken and rooted devices, against the OWASP MASVS, because the protections that hold on a stock handset often disappear the moment somebody roots one.
[ 02 / Coverage ]
What we test, in practice.
This is the working checklist, not a marketing list. Anything your scope adds gets written into the engagement letter before we start.
Methodology
- 01Static analysis of the binary, hardcoded secrets and API keys
- 02Insecure local storage, keychain and keystore misuse
- 03Certificate pinning strength and bypass under instrumentation
- 04Runtime manipulation with Frida and Objection
- 05Deep link, intent and inter-process communication abuse
- 06Backend API testing with a mobile client's privileges
- 07Root and jailbreak detection resilience
[ 03 / What you get ]
Four things land at the end of every engagement.
Technical report
Every finding with CVSS v4.0 score, evidence, reproduction steps and a specific fix, written for the engineer who has to close it.
Executive summary
Two pages your board can read. Risk in business terms, with the three things that matter most called out.
Letter of attestation
A shareable document proving the test happened and what it covered, for customers and auditors who should not see the full report.
Free retest
Once you have fixed things, the same tester verifies each finding and reissues the report. Included for 90 days.
[ 04 / Questions ]
Before you commit.
No, a TestFlight build or a signed APK is ideal, since it lets us test before your users can reach the flaw.
Yes, and it is cheaper than two separate ones because the backend work is shared. The report separates platform-specific findings clearly.
Often scoped together
All services →Web Application Penetration Testing
Manual testing of the application your customers actually log in to.
API Penetration Testing
REST, GraphQL and gRPC tested at the object level, where the flaws actually are.
Black Box Penetration Testing
We start with your domain name and nothing else, exactly like a real attacker.
Scope a mobile application penetration testing.
Send us the target and the deadline. You get a written scope and a fixed price, usually within one working day.