Course Overview

This course is for beginners and may be useful for some advanced users as well. The Android Hacking and Penetration Testing course is a hands-on video course. The course will focus on the tools and techniques for testing the Security of Android Mobile applications.?Android, the Google operating system that’s?on 80% of the world’s smartphones. In extreme cases, hackers with malicious intent can do much more than send premium text messages. In this course, you will learn how?to hack Android applications.? 

This course starts with a basic introduction to essential tools for Android development. Then, you will get to see how to set up your environment. Moving further, you will delve into Android app review, reverse engineering, and analysis, covering topics such as APK file structure, decompiling, static and dynamic analysis, malware assessment, and more through a series of comprehensive tutorials. Then, you will explore methods to bypass certificate pinning in Android applications, offering both automatic and manual techniques across multiple tutorial videos. Finally, you will wrap up the journey with insights into penetration testing, OWASP mobile vulnerabilities, developer guidelines, vulnerability scanning, and bonus tips, presented in a series of informative videos for comprehensive next steps in enhancing app security. 

By the end of the course, you will have gained a deep understanding of how to perform penetration tests against Android applications.

What You Will Learn

  • Learn to audit or perform penetration tests against Android applications
  • Learn tools and techniques
  • Perform real world attacks on Android Devices and Apps
  • Perform Certification Pinning bypass for most of Android Apps
  • Explore OWASP Top Ten Mobile and Web most common vulnerabilities
  • Android Malware Analysis

Program Curriculum

  • Android Studio
  • Android Debug Bridge (ADB)
  • $7 Million Cybersecurity Scholarship by EC-Council
  • Chapter 1 Quiz

  • Android Emulator or Android Device
  • Android Rooting
  • Setting up a Proxy for Android
  • Installing CA Certificate
  • Android Vulnerable Application Setup
  • Chapter 2 Quiz

  • APK File Structure. AndroidManifest XML File
  • Reversing to Get Source Code of the Application – Decompiling with dex2jar
  • Reversing and Re-compiling with APKTool
  • APK Teardown in a Nutshell using Dexplorer on Your Android Device
  • Static vs. Dynamic Analysis
  • Static Analysis of Android Application using QARK
  • Dynamic Analysis of Android Application using Inspeckage and xposed
  • MobSF – Mobile – Security – Framework. Malware Analysis
  • Automated Security Assessments with Drozer
  • Intercept Traffic using Wireshark and tcpdump
  • Intent Sniffing
  • Fuzzing using Burp – Password Brute-Force. Username Enumeration
  • Chapter 3 Quiz

  • General Description
  • Automatic Bypass of Certificate Pinning
  • Manual Bypass of Certificate Pinning
  • Chapter 4 Quiz

  • Bonus – Take Control Over an Android Phone using Metasploit
  • Penetration Testing Cheat Sheet
  • OWASP Top 10 Mobile Vulnerabilities and Attacks
  • Further Research – Automatic and Manual Scanning for Vulnerabilities
  • For Developers – Android Security Guidelines
  • Bonus – Easily Download Any APK File from Google Play Directly on Your PC
  • Final Words
Load more modules

Instructor

Gabriel Avramescu

Gabriel Avramescu is a Senior Information Security Consultant and an IT Trainer with certifications like OSWE (Offensive Security Web Expert), CREST Registered Penetration Tester (CRT), ECIH (EC-Council Incident Handling), Ec-Council ICS-SCADA Cybersecurity, OSCE (Offensive Security Certified Expert), OSWP (Offensive Security Wireless Professional), OSCP (Offensive Security Certified Professional), CHFI (Computer Hacking Forensic Investigator), ISO 270001 Lead Auditor, ECSA (EC-Council Security Analyst), CEH (Certified Ethical Hacker), CCNA and CCNA Security, CCNP Routing and CCNP Switching, Advanced Linux&InfoSEC, VMWare vSphere Install, Configure, Manage, and Microsoft Certified Technology Specialist (MCTS/MCP 70-642): Microsoft Windows Server 2008 Network Infrastructure, etc.

Join over 1 Million professionals from the most renowned Companies in the world!

certificate

Empower Your Learning with Our Flexible Plans

Invest in your future with our flexible subscription plans. Whether you're just starting out or looking to enhance your expertise, there's a plan tailored to meet your needs. Gain access to in-demand skills and courses for your continuous learning needs.

Monthly Plans
Annual Plans
Save 20% with our annual plans!

Pro

Ideal for continuous learning, offering extensive resources with 600+ courses and diverse Learning Paths to enhance your skills.

$ 499.00
Billed annually or $59.00 billed monthly

What is included

  • 700+ Premium Short Courses
  • 50+ Structured Learning Paths
  • Validation of Completion with all courses and learning paths
  • New Courses added every month
Early Access Offer

Pro +

Experience immersive learning with Practice Labs, CTF Challenges, and exclusive EC-Council certifications for comprehensive skill-building.

$ 599.00
Billed annually or $69.00 billed monthly

Everything in Pro and

  • 800+ Practice Lab exercises with guided instructions
  • 150+ CTF Challenges with detailed walkthroughs
  • New Practice Labs and Challenges added every month
  • 3 Official EC-Council Essentials Certifications¹ (retails at $897!)
    Exclusive Bonus with Annual Plans

¹This plan includes Digital Forensics Essentials (DFE), Ethical Hacking Essentials (EHE), and Network Defense Essentials (NDE) certifications. No other EC-Council certifications are included.

Related Courses

1 of 8