Pentesting Android Apps
Mobile application security testing
Preview this course
Watch an introductory lesson before you enroll. No account is required.
What you will be able to do
- Unpack and read an APK: manifest, smali, resources
- Find insecure data storage and hardcoded secrets
- Intercept and analyse app traffic, including pinned TLS
- Hook runtime behaviour with Frida
- Test against the OWASP MASVS
About this course
Static and dynamic analysis of Android applications: APK internals, insecure storage, traffic interception, and the MASVS checklist — on apps you own.
Curriculum
3 modules · 7 lessons · 22 hours · 1 free preview
Android internals 2 lessons
- The APK, inside out Watch preview 20:15
- Permissions and the manifest 17:02
Static analysis 2 lessons
- Decompiling and reading smali 25:38
- Hunting hardcoded secrets 19:44
Dynamic analysis 3 lessons
- Proxying app traffic 23:11
- Defeating pinning in your lab 26:07
- Frida hooks 28:49
Requirements
- Comfortable on a Linux command line
- Test only apps you own or are authorised to assess
Who this course is for
- Security testers adding mobile applications to their toolkit
- Android developers who want to ship safer applications
- Advanced learners comfortable with Linux and proxy tooling
Projects you will build
Controlled traffic-interception and runtime-analysis lab
OWASP MASVS assessment with reproducible evidence
Career paths this course supports
The course builds practical foundations for roles like these. Job outcomes still depend on your portfolio, practice and interview performance.
- Mobile Security Tester
- Application Security Analyst
- Android Security Engineer
How your learning journey works
Preview first, learn at your pace, and leave with work you can show.
Try the teaching style
Watch the free preview and scan every module before deciding.
Learn by building
Follow focused lessons, complete practical projects, and revisit any topic whenever needed.
Prove the skill
Finish the curriculum and claim a certificate with a publicly verifiable ID.
Learners also took
Ethical Hacking
Learn how attackers think so you can defend properly. Recon, web exploitation, network attacks and reporting — practis…
Python 3 Bootcamp
A crisp, complete path through Python 3 — syntax, data structures, files, OOP, and the standard library — built around…
Fullstack Web Development
Build and deploy a complete product: semantic HTML, modern CSS layout, JavaScript, a REST API, a database, auth, and a…