Mobile application Penetration Testing

Mobile application Penetration Testing

Master Android application penetration testing from scratch. Start with the fundamentals (Android architecture, sandbox, permissions model), then dive deep into static and dynamic analysis. Learn to decompile APKs, read Smali code, reverse engineer app logic, intercept traffic, and manipulate apps at runtime. Get hands-on with every major tool: MobSF, Frida, Medusa, and Drozer, plus native hooking and Smali patching. A practical course aligned with OWASP Mobile Top 10 and eMAPT preparation.

This course takes you through mobile application penetration testing from the ground up, covering both Android and iOS platforms. You will start with environment setup and APK/IPA structure, then move into static analysis: decompiling, reverse engineering, hardcoded secrets, insecure storage, and manifest misconfigurations. From there, you will shift to dynamic analysis, intercepting traffic with Burp Suite, bypassing SSL pinning using multiple techniques, and analyzing runtime behavior. The course then dives deep into hooking and instrumentation: you will learn how to use Frida for JavaScript-based hooking, Objection for rapid automated assessments, and Medusa for modular hook injection. We also cover native hooking (hooking into native libraries and JNI calls), root/jailbreak detection bypass, biometric bypass, and token manipulation. By the end, you will be able to perform a full mobile penetration test, from recon to exploitation to reporting.

Topics covered:

  • APK/IPA structure and reverse engineering
  • Static analysis (jadx, apktool, MobSF)
  • Dynamic analysis and traffic interception
  • SSL pinning bypass (multiple methods)
  • Frida scripting and hooking (Java and Native layers)
  • Objection runtime exploration
  • Medusa modular hooking framework
  • Native hooks and JNI interception
  • Root/Jailbreak detection bypass
  • Insecure data storage and token analysis
  • Reporting and documentation

Curriculum

Student Feedback

5 based on 2 reviews
Latest Reviews
Hazem ElNaggar
2026-10-08 06:45:19

Excellent course with clear explanations and practical hands-on labs that provided valuable real-world skills in Mobile Penetration Testing. Highly recommended!

Jana Ahmed
2026-10-08 09:07:43

Good, all of techniques of Static analysis

Mobile Application Penetration Testing
Course Duration
30h 41m
Enrolled Students
17
Course Level
Intermediate
Course Pricing
One-Time Payment
4,000 L.E
8,000 L.E 50 % OFF
4,000 L.E Coupon Applied

Lifetime access to all course content

Have a coupon?
Coupon Applied
Course Tags
public
Enroll Now via WhatsApp

Hossam Shady is the founder of Red Nexus, an expert in cybersecurity and penetration testing.
His passion for the field and real-world experience led him to establish the academy to provide high-quality Arabic content and simplify entering the cybersecurity job market. He focuses on direct, practical training that bridges the gap between learning and applying skills in real scenarios.