Test device-side exposure
Assess local storage, logs, screenshots, backups, permissions and secrets that can expose sensitive information.
Damocles Mobile Application Penetration Testing assesses authentication, local storage, transport security, platform permissions, deep links, application behaviour and supporting APIs across approved iOS or Android applications.
Mobile applications create security boundaries on both the device and the server. Sensitive information can be exposed locally, tokens can be mishandled, platform features can be abused, and server APIs can trust client behaviour they should independently enforce.
Damocles assesses the mobile package and runtime behaviour together with approved supporting interfaces so the customer can distinguish client-side weaknesses from server-side control failures.
Assess local storage, logs, screenshots, backups, permissions and secrets that can expose sensitive information.
Review deep links, inter-process behaviour, certificate handling and assumptions the app makes about the device or caller.
Validate that the server still enforces identity, object ownership and privilege independently of the mobile client.
The scope identifies application builds, platforms, test accounts, supporting APIs and whether source or debug builds are available.
Sensitive files, databases, preferences, caches, logs, screenshots and backup behaviour.
Login, MFA integration, token storage, refresh, logout and account transition behaviour.
TLS validation, certificate handling and network security controls used by the client.
Requested permissions, platform capability use and unintended access to device resources.
URL schemes, deep links, exported components and other external invocation paths.
Approved API calls, authorisation, object access and business operations used by the mobile client.
Test the application package, device behaviour and supporting API interactions to expose weaknesses in storage, transport, platform integration and business workflows.
Build settings, embedded material and exposed components.
Sensitive information in storage, logs, backups and caches.
Login, token storage, lifecycle and device-binding controls.
Permissions, deep links, inter-process communication and web views.
Certificate validation and protection of data in transit.
Object, function and role controls behind the mobile client.
Resistance to tampering and unsafe reliance on client decisions.
Replay, sequence bypass and misuse of legitimate functions.
These are governed procedures from the service assurance profile—not generic marketing categories. The complete matrix below records applicability, access requirements and limitations for every coverage area.
Damocles records package identifier, version, signing information, source channel and build hash for the exact application artefact tested.
Damocles inspects application files, databases, preferences, caches and platform-protected storage for sensitive data and access controls.
Damocles reviews application logs, screenshots, task snapshots and backup or restore behaviour on the supplied device.
Damocles follows token and credential creation, device storage, use, renewal, logout and revocation across representative accounts.
Damocles observes certificate and protocol behaviour for application traffic and tests transport enforcement through an authorised interception setup.
Damocles compares requested platform permissions with feature use and tests behaviour when representative permissions are denied or revoked.
Showing 6 representative areas. The full governed matrix contains 13 coverage areas.
References are shown according to the role they play in the engagement. Methodologies guide testing, taxonomies classify findings, severity methods support consistent scoring, and control mappings connect scoped evidence to broader assurance work.
Approved methodology, verification and testing guidance used to select and structure relevant procedures within the authorised scope.
Approved risk, weakness and severity references provide a consistent language for confirmed findings without replacing customer-specific business impact.
Mobile application behaviours mapped to agreed MASVS areas.
A prioritised mobile report with device and API evidence, affected data or functions, remediation guidance and retest results.
What this means: technical evidence may support risk, compliance and audit activity where the mapping is applicable. It does not by itself certify the organisation, establish complete compliance or assess controls outside the authorised scope.
Damocles inspects the supplied build on agreed devices, observes local and network behaviour, and correlates findings with architecture and supporting-API evidence. Static review and runtime validation are reported separately; device, build and root or jailbreak constraints bound conclusions.
Directly assessed means the engagement tests the relevant behaviour. Supporting evidence means the result can contribute to a broader control assessment. Contextual references explain relevance without claiming that the control was tested.
Installs and uses the supplied build as an ordinary user while observing storage, permissions, links and network behaviour.
Examines files, logs, IPC, runtime state and protection behaviour on an authorised instrumented or rooted test device.
Correlates device observations with mobile design, cryptographic decisions and approved supporting API behaviour.
| Coverage area | What Damocles tests | Perspective and access | Evidence produced | References and limits |
|---|---|---|---|---|
| Application package and build provenance | Damocles records package identifier, version, signing information, source channel and build hash for the exact application artefact tested. | Black-box mobile application user Assessment requires the exact application build, agreed device state, test accounts, representative data and supporting evidence, selected specifically for application package and build provenance. | Evidence records the package, device file, log, permission, IPC, deep-link, network or runtime observation relevant to application package and build provenance. | Mobile Application Security Testing Guide 2.0.0 Applicability: Applies to Application package and build provenance when the behaviour exists in the supplied build and agreed device configuration. Limit: The conclusion is limited to the sampled application package and build provenance; conclusions are build and device specific; unsafe device, data and supporting-service effects are excluded. |
| Local storage | Damocles inspects application files, databases, preferences, caches and platform-protected storage for sensitive data and access controls. | Black-box mobile application user Assessment requires the exact application build, agreed device state, test accounts, representative data and supporting evidence, selected specifically for local storage. | Evidence records the package, device file, log, permission, IPC, deep-link, network or runtime observation relevant to local storage. | Mobile Application Security Testing Guide 2.0.0 Applicability: Applies to Local storage when the behaviour exists in the supplied build and agreed device configuration. Limit: The conclusion is limited to the sampled local storage; conclusions are build and device specific; unsafe device, data and supporting-service effects are excluded. |
| Logs and backups | Damocles reviews application logs, screenshots, task snapshots and backup or restore behaviour on the supplied device. | Black-box mobile application user Assessment requires the exact application build, agreed device state, test accounts, representative data and supporting evidence, selected specifically for logs and backups. | Evidence records the package, device file, log, permission, IPC, deep-link, network or runtime observation relevant to logs and backups. | Mobile Application Security Testing Guide 2.0.0 Applicability: Applies to Logs and backups when the behaviour exists in the supplied build and agreed device configuration. Limit: The conclusion is limited to the sampled logs and backups; conclusions are build and device specific; unsafe device, data and supporting-service effects are excluded. |
| Tokens and credentials | Damocles follows token and credential creation, device storage, use, renewal, logout and revocation across representative accounts. | Black-box mobile application user Assessment requires the exact application build, agreed device state, test accounts, representative data and supporting evidence, selected specifically for tokens and credentials. | Evidence records the package, device file, log, permission, IPC, deep-link, network or runtime observation relevant to tokens and credentials. | Mobile Application Security Testing Guide 2.0.0 Applicability: Applies to Tokens and credentials when the behaviour exists in the supplied build and agreed device configuration. Limit: The conclusion is limited to the sampled tokens and credentials; conclusions are build and device specific; unsafe device, data and supporting-service effects are excluded. |
| Transport security | Damocles observes certificate and protocol behaviour for application traffic and tests transport enforcement through an authorised interception setup. | Black-box mobile application user Assessment requires the exact application build, agreed device state, test accounts, representative data and supporting evidence, selected specifically for transport security. | Evidence records the package, device file, log, permission, IPC, deep-link, network or runtime observation relevant to transport security. | Mobile Application Security Testing Guide 2.0.0 Applicability: Applies to Transport security when the behaviour exists in the supplied build and agreed device configuration. Limit: The conclusion is limited to the sampled transport security; conclusions are build and device specific; unsafe device, data and supporting-service effects are excluded. |
| Platform permissions | Damocles compares requested platform permissions with feature use and tests behaviour when representative permissions are denied or revoked. | Black-box mobile application user Assessment requires the exact application build, agreed device state, test accounts, representative data and supporting evidence, selected specifically for platform permissions. | Evidence records the package, device file, log, permission, IPC, deep-link, network or runtime observation relevant to platform permissions. | Mobile Application Security Testing Guide 2.0.0 Applicability: Applies to Platform permissions when the behaviour exists in the supplied build and agreed device configuration. Limit: The conclusion is limited to the sampled platform permissions; conclusions are build and device specific; unsafe device, data and supporting-service effects are excluded. |
| Exported components and inter-process interaction | Damocles enumerates exported components and approved inter-process entry points and invokes them with controlled intents or messages. | Black-box mobile application user Assessment requires the exact application build, agreed device state, test accounts, representative data and supporting evidence, selected specifically for exported components and inter-process interaction. | Evidence records the package, device file, log, permission, IPC, deep-link, network or runtime observation relevant to exported components and inter-process interaction. | Mobile Application Security Testing Guide 2.0.0 Applicability: Applies to Exported components and inter-process interaction when the behaviour exists in the supplied build and agreed device configuration. Limit: The conclusion is limited to the sampled exported components and inter-process interaction; conclusions are build and device specific; unsafe device, data and supporting-service effects are excluded. |
| Deep links | Damocles opens approved deep links with valid and manipulated routes, parameters and calling contexts and observes destination and authorisation handling. | Black-box mobile application user Assessment requires the exact application build, agreed device state, test accounts, representative data and supporting evidence, selected specifically for deep links. | Evidence records the package, device file, log, permission, IPC, deep-link, network or runtime observation relevant to deep links. | Mobile Application Security Testing Guide 2.0.0 Applicability: Applies to Deep links when the behaviour exists in the supplied build and agreed device configuration. Limit: The conclusion is limited to the sampled deep links; conclusions are build and device specific; unsafe device, data and supporting-service effects are excluded. |
| Cryptographic use | Damocles traces application use of cryptographic APIs, keys, randomness and protected storage using runtime and supplied design evidence. | Black-box mobile application user Current configuration export or read-only access, diagrams, owners and representative validation endpoints. | Configuration excerpts, object or rule identifiers and observed validation results. | Mobile Application Security Testing Guide 2.0.0 Applicability: Performed when current configuration evidence and a representative endpoint or device are included in the review. Limit: A configuration snapshot cannot prove continuous enforcement across excluded nodes; validation avoids changes unless implementation work is authorised. |
| Privacy-relevant behaviour | Damocles observes collection, display, storage and transmission of privacy-relevant data through representative user actions. | Black-box mobile application user Assessment requires the exact application build, agreed device state, test accounts, representative data and supporting evidence, selected specifically for privacy-relevant behaviour. | Evidence records the package, device file, log, permission, IPC, deep-link, network or runtime observation relevant to privacy-relevant behaviour. | Mobile Application Security Testing Guide 2.0.0 Applicability: Applies to Privacy-relevant behaviour when the behaviour exists in the supplied build and agreed device configuration. Limit: The conclusion is limited to the sampled privacy-relevant behaviour; conclusions are build and device specific; unsafe device, data and supporting-service effects are excluded. |
| Runtime protections | Damocles evaluates anti-tamper, debugger, emulator and root or jailbreak responses only where runtime protection testing is included. | Black-box mobile application user Assessment requires the exact application build, agreed device state, test accounts, representative data and supporting evidence, selected specifically for runtime protections. | Evidence records the package, device file, log, permission, IPC, deep-link, network or runtime observation relevant to runtime protections. | Mobile Application Security Testing Guide 2.0.0 Applicability: Applies to Runtime protections when the behaviour exists in the supplied build and agreed device configuration. Limit: The conclusion is limited to the sampled runtime protections; conclusions are build and device specific; unsafe device, data and supporting-service effects are excluded. |
| Supporting APIs | Damocles exercises supporting API authentication, authorisation and data handling with the mobile client identities and approved endpoints. | Black-box mobile application user Assessment requires the exact application build, agreed device state, test accounts, representative data and supporting evidence, selected specifically for supporting APIs. | Evidence records the package, device file, log, permission, IPC, deep-link, network or runtime observation relevant to supporting APIs. | Mobile Application Security Testing Guide 2.0.0 Applicability: Applies to Supporting APIs when the behaviour exists in the supplied build and agreed device configuration. Limit: The conclusion is limited to the sampled supporting APIs; conclusions are build and device specific; unsafe device, data and supporting-service effects are excluded. |
| Device, jailbreak, root and build limitations | Damocles records device model, OS, build, instrumentation and root or jailbreak state and limits conclusions to those conditions. | Black-box mobile application user Assessment requires the exact application build, agreed device state, test accounts, representative data and supporting evidence, selected specifically for device, jailbreak, root and build limitations. | Evidence records the package, device file, log, permission, IPC, deep-link, network or runtime observation relevant to device, jailbreak, root and build limitations. | Mobile Application Security Testing Guide 2.0.0 Applicability: Applies to Device, jailbreak, root and build limitations when the behaviour exists in the supplied build and agreed device configuration. Limit: The conclusion is limited to the sampled device, jailbreak, root and build limitations; conclusions are build and device specific; unsafe device, data and supporting-service effects are excluded. |
| Framework and controls | Mapping type | What Damocles assesses | Evidence produced | Applicability and limits |
|---|---|---|---|---|
| Information Security Manual June 2026 ISM-1922 | Supporting evidence | Mobile application behaviours mapped to agreed MASVS areas. | Mobile coverage records and confirmed findings for the supplied build. | Applies: Only mobile application development and the supplied mobile build. Limit: Does not assess the complete development lifecycle or every MASVS requirement. |
Assurance boundary: Damocles maps assessed coverage and findings to agreed security frameworks and control objectives. This provides traceable technical evidence that may support risk, assurance and audit activities. A penetration test does not by itself certify an organisation, establish complete compliance with a framework or confirm the effectiveness of controls outside the authorised scope.
Records authorised scope and rules of engagement produced from the authorised Mobile application penetration testing work.
Records coverage matrix produced from the authorised Mobile application penetration testing work.
Records retest and residual-risk record produced from the authorised Mobile application penetration testing work.
Records build and device coverage record produced from the authorised Mobile application penetration testing work.
Records local storage and runtime evidence produced from the authorised Mobile application penetration testing work.
Records mobile and supporting-API trace produced from the authorised Mobile application penetration testing work.
A prioritised mobile report with device and API evidence, affected data or functions, remediation guidance and retest results.
Testing depends on platform, build type, protection controls and supporting services in scope.
Credentials, tokens, personal data or application secrets stored or logged insecurely.
Token handling that allows replay, unintended persistence or access after expected logout or expiry.
Externally invoked application functions that accept unsafe data or bypass intended navigation and checks.
Client trust or certificate behaviour that exposes sensitive traffic to interception under authorised conditions.
Permissions, exported components or device features that expand access beyond intended application boundaries.
Backend operations that trust client state, role or object ownership instead of enforcing it independently.
The statement of work identifies iOS/Android builds, accounts, environments, APIs, test devices and any protections that affect assessment depth.
Assess the approved Android package, runtime behaviour and supporting APIs.
Assess the approved iOS application, runtime behaviour and supporting APIs.
Assess both the mobile client and server-side interfaces used for sensitive operations.
Test a defined build before production or application-store release.
Verify agreed findings against the remediated build and supporting service.
Evidence identifies platform, build, account, application condition and supporting API where relevant.
Material data, identity and business-function exposure explained clearly.
Local storage, token, permission, logging and platform-related evidence.
Transport, certificate and application-network trust conditions.
Server-side object, role and workflow issues observed through the mobile client or supporting interface.
Specific mobile, platform and server-side control improvements.
Verification against the repaired application build and supporting services.
Damocles can retest agreed findings against a remediated application build and supporting API version, recording resolved and remaining conditions.
New major application versions, substantial feature changes or new platform support can require new assessment scope beyond the original retest.
The commercial scope comes first. Delivery is then controlled through written authority, agreed safety boundaries and a clear retest path.
Confirm targets, ownership, attacker perspective, accounts, exclusions, timing, contacts and prohibited activity.
Perform the authorised manual and technical testing required to prove or disprove the attack paths in scope.
Provide evidence, impact, affected scope, remediation priorities and a technical walkthrough with the people responsible for the fix.
Reproduce agreed findings after remediation and record whether they are resolved, reduced or still exploitable.
Source-code review, device exploitation, jailbreak/root bypass research, third-party SDK assessment and broader API testing are included only where expressly scoped.
Application-store, device-management and backend cloud configuration are separate assurance areas unless added to the engagement.
We will define the mobile scope, test devices, environments, supporting interfaces, safety boundaries, deliverables and retest allowance.