Home / Services

Mobile Application Pentest

Technical diagram of a mobile application, showing on-device key storage and communication with the backend across the trust boundary

Mobile Application Pentest

Mobile applications have become a fundamental part of operations across many industries, being used for banking, e-commerce, healthcare, logistics, communication, authentication, corporate management and countless other activities.

As the use of mobile devices grows, so does the interest of criminals in exploiting vulnerabilities in those applications to gain improper access to sensitive information, user accounts and company resources.

Beyond the application itself, a mobile app usually interacts with APIs, cloud services, databases, authentication mechanisms and several other components, making its attack surface considerably wider.

The goal of a Mobile Application Pentest is to identify vulnerabilities before they can be exploited, allowing fixes to be applied during the development cycle or before the application is released to users.

What is assessed in a Mobile Application Pentest

Depending on the agreed scope, the assessment may include:

  • Insecure storage of information on the device;
  • Authentication and session management;
  • Access control and authorisation;
  • Certificate validation and protection against Man-in-the-Middle (MitM) attacks;
  • Communication between the application and APIs;
  • Encryption of stored and transmitted data;
  • Application security configuration;
  • Reverse engineering and code protection;
  • Root and Jailbreak detection mechanisms;
  • Protection against dynamic instrumentation (Frida, Objection and similar);
  • Exposure of sensitive information in logs;
  • Storage of credentials, tokens and keys;
  • Improperly exported Android components;
  • Insecure AndroidManifest.xml and Info.plist configuration;
  • Business logic vulnerabilities;
  • Other vulnerabilities covered by the OWASP Mobile Application Security Testing Guide (MASTG) and the OWASP Mobile Top 10.

Methodology

Tests are carried out using internationally recognised methodologies such as the OWASP Mobile Application Security Testing Guide (MASTG) and the OWASP Mobile Top 10, adapted to the characteristics of the application and the agreed scope.

Most of the assessment is carried out manually by specialists, with automated tools used only to support reconnaissance, static analysis and dynamic analysis.

During the tests we may analyse the application installed on the device, network traffic, communication with APIs, local storage, authentication mechanisms and the protections implemented against reverse engineering and instrumentation.

All tests are executed in a controlled manner, within the scope authorised by the company, seeking to minimise impact on normal operation of the application and related services.

Professional Report with Results

At the end of the assessment we deliver a technical report and an executive report containing everything needed to support the remediation of the vulnerabilities identified.

The report includes:

  • All vulnerabilities identified;
  • Severity rating (Critical, High, Medium, Low or Informational);
  • Technical evidence of the exploitation of each vulnerability found;
  • Description of the business impact;
  • Clear remediation recommendations;
  • References to security best practices.

Alongside the technical report we also provide a Penetration Test Attestation Letter, a document that certifies the tests were carried out and can be used as evidence in audits, compliance processes, vendor approval and with clients and business partners.