Mobile application penetration testing

Test what the mobile app trusts on the device and what the server still needs to enforce remotely.

Damocles Mobile Application Penetration Testing assesses authentication, local storage, transport security, platform permissions, deep links, application behaviour and supporting APIs across approved iOS or Android applications.

iOS and Android applicationsLocal data and token handlingPlatform permissions and deep linksSupporting API interaction
Why customers buy this test

Protect sensitive mobile data, identities and functions.

Mobile applications create security boundaries on both the device and the server. Sensitive information can be exposed locally, tokens can be mishandled, platform features can be abused, and server APIs can trust client behaviour they should independently enforce.

Damocles assesses the mobile package and runtime behaviour together with approved supporting interfaces so the customer can distinguish client-side weaknesses from server-side control failures.

01

Test device-side exposure

Assess local storage, logs, screenshots, backups, permissions and secrets that can expose sensitive information.

02

Test application trust

Review deep links, inter-process behaviour, certificate handling and assumptions the app makes about the device or caller.

03

Test the supporting API

Validate that the server still enforces identity, object ownership and privilege independently of the mobile client.

What we test

The approved application package, runtime behaviour, platform integration and supporting services.

The scope identifies application builds, platforms, test accounts, supporting APIs and whether source or debug builds are available.

LS

Local storage

Sensitive files, databases, preferences, caches, logs, screenshots and backup behaviour.

AU

Authentication and tokens

Login, MFA integration, token storage, refresh, logout and account transition behaviour.

TS

Transport security

TLS validation, certificate handling and network security controls used by the client.

PM

Platform permissions

Requested permissions, platform capability use and unintended access to device resources.

DL

Deep links and intents

URL schemes, deep links, exported components and other external invocation paths.

API

Supporting APIs

Approved API calls, authorisation, object access and business operations used by the mobile client.

Technical assurance

Test how the mobile app protects identities, data and trusted actions.

Test the application package, device behaviour and supporting API interactions to expose weaknesses in storage, transport, platform integration and business workflows.

Application package

Build settings, embedded material and exposed components.

Local data

Sensitive information in storage, logs, backups and caches.

Authentication and sessions

Login, token storage, lifecycle and device-binding controls.

Platform interaction

Permissions, deep links, inter-process communication and web views.

Transport security

Certificate validation and protection of data in transit.

API authorisation

Object, function and role controls behind the mobile client.

Client trust

Resistance to tampering and unsafe reliance on client decisions.

Business workflows

Replay, sequence bypass and misuse of legitimate functions.

13governed test areas
3authorised testing perspectives
6controlled evidence outputs
1framework / control evidence mappings
What we actually test

Representative technical coverage with the evidence produced.

These are governed procedures from the service assurance profile—not generic marketing categories. The complete matrix below records applicability, access requirements and limitations for every coverage area.

Jump to full coverage matrix ↓
Coverage area

Application package and build provenance

Damocles records package identifier, version, signing information, source channel and build hash for the exact application artefact tested.

Evidence producedEvidence records the package, device file, log, permission, IPC, deep-link, network or runtime observation relevant to application package and build provenance.
Framework references
Mobile Application Security Testing Guide 2.0.0
Coverage area

Local storage

Damocles inspects application files, databases, preferences, caches and platform-protected storage for sensitive data and access controls.

Evidence producedEvidence records the package, device file, log, permission, IPC, deep-link, network or runtime observation relevant to local storage.
Framework references
Mobile Application Security Testing Guide 2.0.0
Coverage area

Logs and backups

Damocles reviews application logs, screenshots, task snapshots and backup or restore behaviour on the supplied device.

Evidence producedEvidence records the package, device file, log, permission, IPC, deep-link, network or runtime observation relevant to logs and backups.
Framework references
Mobile Application Security Testing Guide 2.0.0
Coverage area

Tokens and credentials

Damocles follows token and credential creation, device storage, use, renewal, logout and revocation across representative accounts.

Evidence producedEvidence records the package, device file, log, permission, IPC, deep-link, network or runtime observation relevant to tokens and credentials.
Framework references
Mobile Application Security Testing Guide 2.0.0
Coverage area

Transport security

Damocles observes certificate and protocol behaviour for application traffic and tests transport enforcement through an authorised interception setup.

Evidence producedEvidence records the package, device file, log, permission, IPC, deep-link, network or runtime observation relevant to transport security.
Framework references
Mobile Application Security Testing Guide 2.0.0
Coverage area

Platform permissions

Damocles compares requested platform permissions with feature use and tests behaviour when representative permissions are denied or revoked.

Evidence producedEvidence records the package, device file, log, permission, IPC, deep-link, network or runtime observation relevant to platform permissions.
Framework references
Mobile Application Security Testing Guide 2.0.0

Showing 6 representative areas. The full governed matrix contains 13 coverage areas.

Standards and assurance coverage

See how this engagement is structured, classified and mapped before opening the full evidence matrix.

References are shown according to the role they play in the engagement. Methodologies guide testing, taxonomies classify findings, severity methods support consistent scoring, and control mappings connect scoped evidence to broader assurance work.

01 · Test method

How testing is structured

Approved methodology, verification and testing guidance used to select and structure relevant procedures within the authorised scope.

Mobile Application Security Testing Guide 2.0.0Mobile Application Security Verification Standard 2.1.0Guidelines for Software Development June 2026
02 · Finding language

How weaknesses and severity are classified

Approved risk, weakness and severity references provide a consistent language for confirmed findings without replacing customer-specific business impact.

Common Weakness Enumeration 4.20Common Vulnerability Scoring System 4.0
03 · Control evidence

What maps into compliance and assurance work

1governed evidence mappings across 1 approved framework and 1 referenced control.
1 supporting evidence
Information Security Manual June 2026Supporting evidence
ISM-1922

Mobile application behaviours mapped to agreed MASVS areas.

Jump to full control mapping ↓
04 · Evidence package

What the customer can use after the engagement

A prioritised mobile report with device and API evidence, affected data or functions, remediation guidance and retest results.

  • Authorised scope and rules of engagement
  • Coverage matrix
  • Retest and residual-risk record
  • + 3 additional controlled outputs

What this means: technical evidence may support risk, compliance and audit activity where the mapping is applicable. It does not by itself certify the organisation, establish complete compliance or assess controls outside the authorised scope.

How we test

Manual validation backed by controlled evidence.

Damocles inspects the supplied build on agreed devices, observes local and network behaviour, and correlates findings with architecture and supporting-API evidence. Static review and runtime validation are reported separately; device, build and root or jailbreak constraints bound conclusions.

How to read the mapping

Evidence is mapped to the part of a control we can actually assess.

Directly assessed means the engagement tests the relevant behaviour. Supporting evidence means the result can contribute to a broader control assessment. Contextual references explain relevance without claiming that the control was tested.

All relevant frameworks
Mobile Application Security Testing Guide 2.0.0Mobile Application Security Verification Standard 2.1.0Common Weakness Enumeration 4.20Common Vulnerability Scoring System 4.0Guidelines for Software Development June 2026Information Security Manual June 2026
Testing perspectives3 authorised viewpoints and access models

Black-box mobile application user

Installs and uses the supplied build as an ordinary user while observing storage, permissions, links and network behaviour.

Included when
Used for behaviour available without instrumentation or source evidence.
Access required
The exact package, test account, representative data and supported device or emulator.
Limitations
Conclusions apply to the supplied build, platform version and user path.

Instrumented test-device reviewer

Examines files, logs, IPC, runtime state and protection behaviour on an authorised instrumented or rooted test device.

Included when
Used where deeper device-side validation is included and technically possible.
Access required
A dedicated test device, instrumentation authority, package and agreed root or jailbreak state.
Limitations
Instrumentation can change behaviour and does not prove resistance on every device or OS release.

Mobile architecture and supporting-API reviewer

Correlates device observations with mobile design, cryptographic decisions and approved supporting API behaviour.

Included when
Used where architecture or supporting interfaces are included.
Access required
Data-flow diagrams, platform configuration, API endpoints and scoped client credentials.
Limitations
Document and API review are reported separately from behaviour observed in the app build.
Exact test coverage and evidence13 governed coverage areas
What Damocles tests, the evidence produced and the scope boundary for each controlled coverage area.
Coverage areaWhat Damocles testsPerspective and accessEvidence producedReferences and limits
Application package and build provenanceDamocles records package identifier, version, signing information, source channel and build hash for the exact application artefact tested.Black-box mobile application user
Assessment requires the exact application build, agreed device state, test accounts, representative data and supporting evidence, selected specifically for application package and build provenance.
Evidence records the package, device file, log, permission, IPC, deep-link, network or runtime observation relevant to application package and build provenance.
Mobile Application Security Testing Guide 2.0.0

Applicability: Applies to Application package and build provenance when the behaviour exists in the supplied build and agreed device configuration.

Limit: The conclusion is limited to the sampled application package and build provenance; conclusions are build and device specific; unsafe device, data and supporting-service effects are excluded.

Local storageDamocles inspects application files, databases, preferences, caches and platform-protected storage for sensitive data and access controls.Black-box mobile application user
Assessment requires the exact application build, agreed device state, test accounts, representative data and supporting evidence, selected specifically for local storage.
Evidence records the package, device file, log, permission, IPC, deep-link, network or runtime observation relevant to local storage.
Mobile Application Security Testing Guide 2.0.0

Applicability: Applies to Local storage when the behaviour exists in the supplied build and agreed device configuration.

Limit: The conclusion is limited to the sampled local storage; conclusions are build and device specific; unsafe device, data and supporting-service effects are excluded.

Logs and backupsDamocles reviews application logs, screenshots, task snapshots and backup or restore behaviour on the supplied device.Black-box mobile application user
Assessment requires the exact application build, agreed device state, test accounts, representative data and supporting evidence, selected specifically for logs and backups.
Evidence records the package, device file, log, permission, IPC, deep-link, network or runtime observation relevant to logs and backups.
Mobile Application Security Testing Guide 2.0.0

Applicability: Applies to Logs and backups when the behaviour exists in the supplied build and agreed device configuration.

Limit: The conclusion is limited to the sampled logs and backups; conclusions are build and device specific; unsafe device, data and supporting-service effects are excluded.

Tokens and credentialsDamocles follows token and credential creation, device storage, use, renewal, logout and revocation across representative accounts.Black-box mobile application user
Assessment requires the exact application build, agreed device state, test accounts, representative data and supporting evidence, selected specifically for tokens and credentials.
Evidence records the package, device file, log, permission, IPC, deep-link, network or runtime observation relevant to tokens and credentials.
Mobile Application Security Testing Guide 2.0.0

Applicability: Applies to Tokens and credentials when the behaviour exists in the supplied build and agreed device configuration.

Limit: The conclusion is limited to the sampled tokens and credentials; conclusions are build and device specific; unsafe device, data and supporting-service effects are excluded.

Transport securityDamocles observes certificate and protocol behaviour for application traffic and tests transport enforcement through an authorised interception setup.Black-box mobile application user
Assessment requires the exact application build, agreed device state, test accounts, representative data and supporting evidence, selected specifically for transport security.
Evidence records the package, device file, log, permission, IPC, deep-link, network or runtime observation relevant to transport security.
Mobile Application Security Testing Guide 2.0.0

Applicability: Applies to Transport security when the behaviour exists in the supplied build and agreed device configuration.

Limit: The conclusion is limited to the sampled transport security; conclusions are build and device specific; unsafe device, data and supporting-service effects are excluded.

Platform permissionsDamocles compares requested platform permissions with feature use and tests behaviour when representative permissions are denied or revoked.Black-box mobile application user
Assessment requires the exact application build, agreed device state, test accounts, representative data and supporting evidence, selected specifically for platform permissions.
Evidence records the package, device file, log, permission, IPC, deep-link, network or runtime observation relevant to platform permissions.
Mobile Application Security Testing Guide 2.0.0

Applicability: Applies to Platform permissions when the behaviour exists in the supplied build and agreed device configuration.

Limit: The conclusion is limited to the sampled platform permissions; conclusions are build and device specific; unsafe device, data and supporting-service effects are excluded.

Exported components and inter-process interactionDamocles enumerates exported components and approved inter-process entry points and invokes them with controlled intents or messages.Black-box mobile application user
Assessment requires the exact application build, agreed device state, test accounts, representative data and supporting evidence, selected specifically for exported components and inter-process interaction.
Evidence records the package, device file, log, permission, IPC, deep-link, network or runtime observation relevant to exported components and inter-process interaction.
Mobile Application Security Testing Guide 2.0.0

Applicability: Applies to Exported components and inter-process interaction when the behaviour exists in the supplied build and agreed device configuration.

Limit: The conclusion is limited to the sampled exported components and inter-process interaction; conclusions are build and device specific; unsafe device, data and supporting-service effects are excluded.

Deep linksDamocles opens approved deep links with valid and manipulated routes, parameters and calling contexts and observes destination and authorisation handling.Black-box mobile application user
Assessment requires the exact application build, agreed device state, test accounts, representative data and supporting evidence, selected specifically for deep links.
Evidence records the package, device file, log, permission, IPC, deep-link, network or runtime observation relevant to deep links.
Mobile Application Security Testing Guide 2.0.0

Applicability: Applies to Deep links when the behaviour exists in the supplied build and agreed device configuration.

Limit: The conclusion is limited to the sampled deep links; conclusions are build and device specific; unsafe device, data and supporting-service effects are excluded.

Cryptographic useDamocles traces application use of cryptographic APIs, keys, randomness and protected storage using runtime and supplied design evidence.Black-box mobile application user
Current configuration export or read-only access, diagrams, owners and representative validation endpoints.
Configuration excerpts, object or rule identifiers and observed validation results.
Mobile Application Security Testing Guide 2.0.0

Applicability: Performed when current configuration evidence and a representative endpoint or device are included in the review.

Limit: A configuration snapshot cannot prove continuous enforcement across excluded nodes; validation avoids changes unless implementation work is authorised.

Privacy-relevant behaviourDamocles observes collection, display, storage and transmission of privacy-relevant data through representative user actions.Black-box mobile application user
Assessment requires the exact application build, agreed device state, test accounts, representative data and supporting evidence, selected specifically for privacy-relevant behaviour.
Evidence records the package, device file, log, permission, IPC, deep-link, network or runtime observation relevant to privacy-relevant behaviour.
Mobile Application Security Testing Guide 2.0.0

Applicability: Applies to Privacy-relevant behaviour when the behaviour exists in the supplied build and agreed device configuration.

Limit: The conclusion is limited to the sampled privacy-relevant behaviour; conclusions are build and device specific; unsafe device, data and supporting-service effects are excluded.

Runtime protectionsDamocles evaluates anti-tamper, debugger, emulator and root or jailbreak responses only where runtime protection testing is included.Black-box mobile application user
Assessment requires the exact application build, agreed device state, test accounts, representative data and supporting evidence, selected specifically for runtime protections.
Evidence records the package, device file, log, permission, IPC, deep-link, network or runtime observation relevant to runtime protections.
Mobile Application Security Testing Guide 2.0.0

Applicability: Applies to Runtime protections when the behaviour exists in the supplied build and agreed device configuration.

Limit: The conclusion is limited to the sampled runtime protections; conclusions are build and device specific; unsafe device, data and supporting-service effects are excluded.

Supporting APIsDamocles exercises supporting API authentication, authorisation and data handling with the mobile client identities and approved endpoints.Black-box mobile application user
Assessment requires the exact application build, agreed device state, test accounts, representative data and supporting evidence, selected specifically for supporting APIs.
Evidence records the package, device file, log, permission, IPC, deep-link, network or runtime observation relevant to supporting APIs.
Mobile Application Security Testing Guide 2.0.0

Applicability: Applies to Supporting APIs when the behaviour exists in the supplied build and agreed device configuration.

Limit: The conclusion is limited to the sampled supporting APIs; conclusions are build and device specific; unsafe device, data and supporting-service effects are excluded.

Device, jailbreak, root and build limitationsDamocles records device model, OS, build, instrumentation and root or jailbreak state and limits conclusions to those conditions.Black-box mobile application user
Assessment requires the exact application build, agreed device state, test accounts, representative data and supporting evidence, selected specifically for device, jailbreak, root and build limitations.
Evidence records the package, device file, log, permission, IPC, deep-link, network or runtime observation relevant to device, jailbreak, root and build limitations.
Mobile Application Security Testing Guide 2.0.0

Applicability: Applies to Device, jailbreak, root and build limitations when the behaviour exists in the supplied build and agreed device configuration.

Limit: The conclusion is limited to the sampled device, jailbreak, root and build limitations; conclusions are build and device specific; unsafe device, data and supporting-service effects are excluded.

Framework and control mappings1 governed evidence mappings
Where scoped technical evidence maps to approved security frameworks and control objectives.
Framework and controlsMapping typeWhat Damocles assessesEvidence producedApplicability and limits
Information Security Manual June 2026
ISM-1922
Supporting evidenceMobile application behaviours mapped to agreed MASVS areas.Mobile coverage records and confirmed findings for the supplied build.

Applies: Only mobile application development and the supplied mobile build.

Limit: Does not assess the complete development lifecycle or every MASVS requirement.

Assurance boundary: Damocles maps assessed coverage and findings to agreed security frameworks and control objectives. This provides traceable technical evidence that may support risk, assurance and audit activities. A penetration test does not by itself certify an organisation, establish complete compliance with a framework or confirm the effectiveness of controls outside the authorised scope.

Report and evidence outputs6 controlled output types

Authorised scope and rules of engagement

Records authorised scope and rules of engagement produced from the authorised Mobile application penetration testing work.

Included when
Included in the final deliverable when the relevant procedure is performed.
Limitations
Contains only evidence gathered from authorised systems, identities and review material.

Coverage matrix

Records coverage matrix produced from the authorised Mobile application penetration testing work.

Included when
Included in the final deliverable when the relevant procedure is performed.
Limitations
Contains only evidence gathered from authorised systems, identities and review material.

Retest and residual-risk record

Records retest and residual-risk record produced from the authorised Mobile application penetration testing work.

Included when
Included in the final deliverable when the relevant procedure is performed.
Limitations
Contains only evidence gathered from authorised systems, identities and review material.

Build and device coverage record

Records build and device coverage record produced from the authorised Mobile application penetration testing work.

Included when
Included in the final deliverable when the relevant procedure is performed.
Limitations
Contains only evidence gathered from authorised systems, identities and review material.

Local storage and runtime evidence

Records local storage and runtime evidence produced from the authorised Mobile application penetration testing work.

Included when
Included in the final deliverable when the relevant procedure is performed.
Limitations
Contains only evidence gathered from authorised systems, identities and review material.

Mobile and supporting-API trace

Records mobile and supporting-API trace produced from the authorised Mobile application penetration testing work.

Included when
Included in the final deliverable when the relevant procedure is performed.
Limitations
Contains only evidence gathered from authorised systems, identities and review material.
What you receive

A prioritised mobile report with device and API evidence, affected data or functions, remediation guidance and retest results.

Attack paths we look for

Mobile attack paths that expose data or bypass trust between device and server.

Testing depends on platform, build type, protection controls and supporting services in scope.

DS

Sensitive local data

Credentials, tokens, personal data or application secrets stored or logged insecurely.

TK

Token theft or reuse

Token handling that allows replay, unintended persistence or access after expected logout or expiry.

DL

Deep-link abuse

Externally invoked application functions that accept unsafe data or bypass intended navigation and checks.

TS

Transport weakness

Client trust or certificate behaviour that exposes sensitive traffic to interception under authorised conditions.

PM

Platform-control weakness

Permissions, exported components or device features that expand access beyond intended application boundaries.

SA

Server-side assumption

Backend operations that trust client state, role or object ownership instead of enforcing it independently.

Engagement options

Scope the application builds, platforms and supporting interfaces that matter.

The statement of work identifies iOS/Android builds, accounts, environments, APIs, test devices and any protections that affect assessment depth.

Android
AN

Android application assessment

Assess the approved Android package, runtime behaviour and supporting APIs.

iOS
IO

iOS application assessment

Assess the approved iOS application, runtime behaviour and supporting APIs.

Combined
CP

Mobile + API assessment

Assess both the mobile client and server-side interfaces used for sensitive operations.

Release
RL

Pre-release mobile assessment

Test a defined build before production or application-store release.

Closure
RT

Mobile retest

Verify agreed findings against the remediated build and supporting service.

What you receive

Findings that separate device-side weaknesses from server-side security failures.

Evidence identifies platform, build, account, application condition and supporting API where relevant.

ES

Executive mobile risk

Material data, identity and business-function exposure explained clearly.

DB

Device-side findings

Local storage, token, permission, logging and platform-related evidence.

NF

Network findings

Transport, certificate and application-network trust conditions.

API

API findings

Server-side object, role and workflow issues observed through the mobile client or supporting interface.

RP

Remediation guidance

Specific mobile, platform and server-side control improvements.

RR

Retest evidence

Verification against the repaired application build and supporting services.

Remediation and retesting

Retesting checks the repaired mobile build and the server-side control involved in the original issue.

Damocles can retest agreed findings against a remediated application build and supporting API version, recording resolved and remaining conditions.

New major application versions, substantial feature changes or new platform support can require new assessment scope beyond the original retest.

Testing delivery

A controlled technical engagement without turning the service page into a methodology manual.

The commercial scope comes first. Delivery is then controlled through written authority, agreed safety boundaries and a clear retest path.

01

Scope and authorise

Confirm targets, ownership, attacker perspective, accounts, exclusions, timing, contacts and prohibited activity.

02

Test and validate

Perform the authorised manual and technical testing required to prove or disprove the attack paths in scope.

03

Report and brief

Provide evidence, impact, affected scope, remediation priorities and a technical walkthrough with the people responsible for the fix.

04

Retest

Reproduce agreed findings after remediation and record whether they are resolved, reduced or still exploitable.

Scope boundaries

Mobile testing covers the approved application, platform and supporting services in scope.

Source-code review, device exploitation, jailbreak/root bypass research, third-party SDK assessment and broader API testing are included only where expressly scoped.

Application-store, device-management and backend cloud configuration are separate assurance areas unless added to the engagement.

Scope the right test

Give us the application builds, platforms, accounts and supporting APIs that need testing.

We will define the mobile scope, test devices, environments, supporting interfaces, safety boundaries, deliverables and retest allowance.