Skip to content
normSight — Cyber Security

Offensive Trainings

Mobile Application Security and Penetration Testing

The MASPT course builds the skills to find vulnerabilities in Android and iOS applications, reverse engineer them and test their back-end APIs.

MASPT comes with lifetime access to course materials and exercises covering mobile application security.

Highly Practical

Perform mobile application security testing and penetration testing against a set of real-world mobile applications you can download and work with at any time.

The Course at a Glance

  • Start from the fundamentals of the iOS and Android architectures
  • Uncover Android and iOS vulnerabilities in depth
  • Covers the security mechanisms and implementations of mobile operating systems
  • Covers reverse engineering of mobile applications
  • In-depth static and dynamic analysis of mobile applications
  • Practise on real-world mobile applications
  • Build your own home lab for mobile application security
  • Provides the skills required to carry out penetration tests of mobile applications
  • Packages: APKTool, Dex2Jar, GDB Debugger, Cycript and others
  • Earning the eMAPT certification qualifies you for 40 CPE credits

Course Material

  • 4 hours of video training material
  • 21 highly technical modules
  • 26 applications to practise on

Course Delivery

  • Set your own pace
  • Offline access available
  • Access from PC, tablet and smartphone

Curriculum

  • Section: Android

  • Module 1: Android: Android Architectures

  • Module 2: Android: Setting Up the Test Environment

  • Module 3: Android: The Android Build Process

  • Module 4: Android: Reversing APKs

  • Module 5: Android: Rooting Devices

  • Module 6: Android: Android Application Fundamentals

  • Module 7: Android: Network Traffic

  • Module 8: Android: Device and Data Security

  • Module 9: Android: Tapjacking

  • Module 10: Android: Static Code Analysis

  • Module 11: Android: Dynamic Code Analysis

Section: iOS

  • Module 1: iOS: iOS Architecture
  • Module 2: iOS: Jailbreaking Devices
  • Module 3: iOS: Setting Up the Test Environment
  • Module 4: iOS: The iOS Build Process
  • Module 5: iOS: Reversing iOS Applications
  • Module 6: iOS: iOS Application Fundamentals
  • Module 7: iOS: iOS Testing Fundamentals
  • Module 8: iOS: Network Traffic
  • Module 9: iOS: Device Management
  • Module 10: iOS: Dynamic Analysis

Prerequisites

  • Basic programming knowledge
  • Basic knowledge of programming languages such as Java and Objective-C / Swift
  • Some iOS topics require OSX El Capitan and an iOS device such as an iPod, iPhone or iPad
  • Knowledge of basic security concepts such as cryptography, reverse engineering, SQL injection, and web tools such as Wireshark and OWASP ZAP (or Burp)

Who Can Attend

  • Penetration testers
  • Forensic investigators
  • Mobile application developers
  • IT staff

Frequently Asked Questions

Are both Android and iOS in scope?

Yes. The application structure, data storage mechanisms and security controls of both platforms are addressed separately.

Is mobile development knowledge required?

It is not mandatory. The application architecture and platform knowledge you need is provided within the course; programming experience makes the process easier.

Is back-end API testing covered?

Yes. Because a significant proportion of critical findings in mobile applications originate in back-end services, API security is an integral part of the course.

See the real risks in your systems.

Talk to our team about a penetration test or training plan that fits your scope.