APPLICATION SECURITY / MOBILE

Test the application across device, runtime and backend trust.

A mobile assessment follows sensitive data and privileged actions across the packaged application, device runtime and backend. Testing distinguishes weaknesses in the client from decisions that must be enforced by the server.

AUTHORIZED ENGAGEMENT MODEL
01Prepare02Decompose03Observe04Challenge

SCOPE → DISCOVER → TEST → VALIDATE → REPORT → RETEST

ENGAGEMENT LENS

Each boundary is tested independently, then examined as part of the complete path.

  1. PACKAGE
  2. DEVICE
  3. RUNTIME
  4. TRANSPORT
  5. API

TRUST BOUNDARY / CONTROL EVIDENCE

01

ASSESSMENT BOUNDARY

What is being assessed?

The engagement boundary is defined by systems, identities, workflows and restrictions—not only a list of URLs or assets.

  • Android and iOS builds included in scope
  • Application storage, logs, backups and secret handling
  • Authentication, session, authorization and business logic
  • Deep links and relevant inter-application communication
  • Transport security and backend/API communication
  • Platform/application configuration, client-side controls and tampering resilience where scoped
02 / TEST MODEL

What Botnet tests.

Testing is manual-led and supported by appropriate tooling. Findings are manually validated before reporting. Coverage follows reachable trust decisions and agreed risk; source-code review is not implied unless explicitly scoped.

01

Package and configuration

Manifest, entitlements, signing-related assumptions, exported components and platform security configuration.

02

Local data

Storage, caches, logs, screenshots, backups and clipboard behavior around sensitive information.

03

Runtime behavior

Client-side decisions, tampering resistance and sensitive operations under controlled instrumentation where authorized.

04

Identity

Authentication, session lifecycle, account recovery, device trust and role transitions.

05

Transport

Network communication, certificate handling and exposure of data between application and service.

06

Backend boundary

Authorization and workflow controls in supporting APIs when those endpoints are explicitly in scope.

03 / ENGAGEMENT

How the work progresses.

  1. 01

    Prepare

    Confirm platforms, builds, accounts, devices and backend boundaries.

  2. 02

    Decompose

    Review package structure, configuration and reachable application flows.

  3. 03

    Observe

    Inspect storage, transport and runtime behavior in the agreed environment.

  4. 04

    Challenge

    Test trust decisions across app, platform and API.

  5. 05

    Validate

    Demonstrate impact safely without retaining unnecessary customer data.

  6. 06

    Report

    Separate client, platform and server-side remediation actions.

04

EVIDENCE + ACTION

What the customer receives.

  • Mobile attack-surface summary
  • Platform-specific findings with reproducible evidence
  • Affected app and backend trust boundaries
  • Severity/risk context and prioritized remediation guidance
  • Scope and device limitations
  • Technical readout and one re-test result for agreed remediated findings
05 / BOTNET APPROACH

Evidence over assumption.

01One model across package, runtime and backend

02Manual workflow and authorization analysis

03Clear ownership of client-side versus server-side fixes

04Evidence captured with mobile engineering teams in mind

06 / QUESTIONS

Before scoping.

Are both Android and iOS included?

Only platforms and builds named in scope are included. Coverage and device requirements are confirmed before testing.

Is the supporting API tested?

API behavior may be included when endpoints and roles are explicitly scoped; a mobile assessment does not automatically authorize broader API testing.

Is certificate pinning bypassed?

Instrumentation techniques and their boundaries must be agreed. The public page does not imply that bypass work is included in every engagement.

NEXT STEP

Define the target, constraints and required evidence.

An assessment request starts a scoping conversation. It does not authorize testing. Work proceeds only after scope acceptance, executed authorization/SOW and kickoff.