Pentesting Android Apps

Mobile application security testing

4.6 rating 1.8k learners 7 lessons 22 hours English
Free lesson

Preview this course

Watch an introductory lesson before you enroll. No account is required.

What you will be able to do

  • Unpack and read an APK: manifest, smali, resources
  • Find insecure data storage and hardcoded secrets
  • Intercept and analyse app traffic, including pinned TLS
  • Hook runtime behaviour with Frida
  • Test against the OWASP MASVS

About this course

Static and dynamic analysis of Android applications: APK internals, insecure storage, traffic interception, and the MASVS checklist — on apps you own.

Curriculum

3 modules · 7 lessons · 22 hours · 1 free preview

Android internals 2 lessons
  • The APK, inside out Watch preview 20:15
  • Permissions and the manifest 17:02
Static analysis 2 lessons
  • Decompiling and reading smali 25:38
  • Hunting hardcoded secrets 19:44
Dynamic analysis 3 lessons
  • Proxying app traffic 23:11
  • Defeating pinning in your lab 26:07
  • Frida hooks 28:49

Requirements

  • Comfortable on a Linux command line
  • Test only apps you own or are authorised to assess

Who this course is for

  • Security testers adding mobile applications to their toolkit
  • Android developers who want to ship safer applications
  • Advanced learners comfortable with Linux and proxy tooling

Projects you will build

Project 1

Static APK review mapped to the application attack surface

Project 2

Controlled traffic-interception and runtime-analysis lab

Project 3

OWASP MASVS assessment with reproducible evidence

Career paths this course supports

The course builds practical foundations for roles like these. Job outcomes still depend on your portfolio, practice and interview performance.

  • Mobile Security Tester
  • Application Security Analyst
  • Android Security Engineer
Simple by design

How your learning journey works

Preview first, learn at your pace, and leave with work you can show.

01

Try the teaching style

Watch the free preview and scan every module before deciding.

02

Learn by building

Follow focused lessons, complete practical projects, and revisit any topic whenever needed.

03

Prove the skill

Finish the curriculum and claim a certificate with a publicly verifiable ID.

Learners also took

Intermediate

Ethical Hacking

Learn how attackers think so you can defend properly. Recon, web exploitation, network attacks and reporting — practis…

10 lessons 34 hours English
4.8 (5.2k) Lifetime
Beginner

Python 3 Bootcamp

A crisp, complete path through Python 3 — syntax, data structures, files, OOP, and the standard library — built around…

16 lessons 20 hours English
4.8 (4.1k) Lifetime
Beginner to Intermediate

Fullstack Web Development

Build and deploy a complete product: semantic HTML, modern CSS layout, JavaScript, a REST API, a database, auth, and a…

17 lessons 46 hours English
4.9 (6.4k) Lifetime