Core Service
FILE · OIU-SVC

The Device Belongs to the Attacker.

We test iOS and Android with the phone fully under our control: local storage and keychain, runtime instrumentation, IPC abuse, and the backend APIs your mobile client talks to once the client itself can no longer be trusted.

Definition Mobile application penetration testing is manual adversarial testing of iOS and Android applications covering OWASP MASVS categories, runtime behavior, IPC, local storage, transport security, and backend API integration.

Last reviewed:

File 01 · Definition

What It Is

Mobile pentesting is more than static analysis. It is runtime instrumentation, dynamic IPC abuse, and end-to-end exercise of the backend APIs the mobile client talks to.

We test against OWASP MASVS, exercise local storage and keychain handling, and probe the backend assuming the client is fully under adversary control.

Reports are mapped to MASVS and to PCI DSS, HIPAA, and SOC 2 evidence where applicable.

A shipped app runs on hardware you do not control, so anything the client enforces an adversary can disable: certificate pinning, jailbreak detection, and client-side validation are speed bumps, not controls. The findings that hurt cluster where the device meets the backend: tokens left in insecure local storage and endpoints that trust an authorization decision the phone made.

File 02 · Threat Model

Why Companies Need This

  • 01 Your app holds regulated data. Healthcare, finance, and payment apps put PHI, card data, and tokens on a device the user can root and the attacker can clone.
  • 02 Your backend trusts the client. Most do by accident, honoring an authorization decision the phone made, which is exactly the decision an instrumented app rewrites.
  • 03 You shipped a major rewrite. Rewrites are where a pinning check gets dropped or a debug flag ships, and that does not surface until someone tests the build on a hostile device.
  • 04 App store review is not a security review. It checks policy compliance, not your authorization logic.

File 03 · Deliverables

What You Get

Unlimited remediation validation included. No time cap, no per-finding charge. How it works

Detailed technical report

CVSS scoring, attack narratives, and proof-of-concept evidence

Executive summary

Findings translated into business risk, not CVSS noise.

Remediation guidance

Prioritized, actionable fixes, not just a list of CVEs

Real-time comms

Dedicated Slack channel for the engagement.

Compliance documentation

Mapped to SOC 2, PCI DSS, HIPAA, ISO 27001, and CMMC

File 04 · Methodology

Our Process

01 RECON

Static & Recon

Binary inspection, manifest review, hardcoded secret discovery, transport configuration analysis.

02 LOCAL

Local Storage & Crypto

Keychain and keystore handling, local database analysis, file-system permission abuse.

03 RUNTIME

Runtime & IPC

Frida and objection instrumentation, deeplink and intent abuse, IPC misconfiguration.

04 ABUSE

Backend API Abuse

Authentication and authorization testing of the mobile API surface assuming hostile client.

05 VALIDATE

Reporting & Retest

MASVS-mapped findings, attack paths, retest included.

File 05 · Intel Brief

Frequently Asked Questions

Q1 Do you cover both iOS and Android?

Yes. Most engagements cover both unless scoped otherwise.

Q2 Do we need to provide a jailbroken or rooted device?

No. We use our own controlled instrumentation environments.

Q3 How long does a mobile pentest take?

Typical engagements run two to four weeks per platform.

Talk to an Operator

The Surface Is Already Exposed. Test It First.

Tell us the platforms you ship and what the app stores. The operator who runs the test scopes it with you on the call.