← Back to the catalogueMobile Security
Intermediate to Advanced
Level
Classroom . Online . Hybrid
Mode
Course overview
A mobile application security course covering Android and iOS assessment against OWASP MASVS. Learners set up instrumented devices and emulators, decompile and review applications, intercept and manipulate traffic, examine insecure storage and authentication, and test platform-specific controls.
Each learner completes an assessment of a deliberately vulnerable application and reports findings.
Who it is for
- Mobile developers
- Application security analysts
- Penetration testers extending to mobile
- QA engineers on mobile products
Prerequisites
Basic Android or iOS development awareness, networking and Linux command line.
How it runs
Learn → Practise → Build → Experience → Demonstrate, ending in a capstone. Delivered by practitioners from the engineering bench, in Madurai, Coimbatore and online.
Final project
Mobile App Security Assessment Report
Programme sheet
The printed sheet carries the full module breakdown, labs, project work and certification path. Fees, dates and formats for the next intake are confirmed by the education team on enquiry.
Learning outcomes
01
Set up a mobile testing environment with proxying.
02
Decompile and review Android and iOS applications.
03
Find insecure data storage and logging.
04
Intercept and modify API traffic despite pinning.
05
Test authentication, session and biometric flows.
06
Assess platform permissions and IPC surfaces.
07
Report findings against OWASP MASVS.
Module structure
8 modulesModule 01
Mobile Threat Model
Platform architectures . Permission models . OWASP Mobile Top 10 . Sandboxing . Threats and attackers
Module 02
Test Environment
Emulators and real devices . Proxy setup . Rooting and jailbreaking basics
Tools — Burp Suite, Frida, Certificate Installation
Module 03
Android Static Analysis
APK structure . Decompilation . Third-party SDKs . Manifest review . Hardcoded secrets
Tools — jadx, Apktool
Module 04
Android Dynamic Analysis
Runtime hooking . Insecure storage . Deep links and exported components . Logcat . WebView issues
Lab
Vulnerable App Assessment
IPA structure . Plist and cache data . Runtime instrumentation . Keychain
Module 06
API and Traffic Security
TLS validation . Authentication tokens . Rate limiting . Backend authorisation
Module 07
Hardening and Defence
Secure storage APIs . Obfuscation . Root and tamper detection . Secure update paths . Play Integrity and DeviceCheck
Severity rating . Evidence capture . Developer-ready remediation . Retesting . MASVS mapping
Assessment & certification
Module assignments and labs
25%
Final project and review
40%
Learners who complete all modules, submit the final project and clear the review receive a course completion certificate from Kaizen Infinities Private Limited. Project work is documented for the learner's portfolio, and interview preparation is included in the closing sessions.
Career outcomes . Roles this programme prepares for
Mobile Security AnalystApplication Security EngineerPenetration Tester (mobile)Secure Mobile DeveloperProduct Security Engineer