Test the application across device, runtime and backend trust.
A mobile assessment follows sensitive data and privileged actions across the packaged application, device runtime and backend. Testing distinguishes weaknesses in the client from decisions that must be enforced by the server.
SCOPE → DISCOVER → TEST → VALIDATE → REPORT → RETEST
Each boundary is tested independently, then examined as part of the complete path.
- 01PACKAGE
- 02DEVICE
- 03RUNTIME
- 04TRANSPORT
- 05API
TRUST BOUNDARY / CONTROL EVIDENCE
ASSESSMENT BOUNDARY
What is being assessed?
The engagement boundary is defined by systems, identities, workflows and restrictions—not only a list of URLs or assets.
- Android and iOS builds included in scope
- Application storage, logs, backups and secret handling
- Authentication, session, authorization and business logic
- Deep links and relevant inter-application communication
- Transport security and backend/API communication
- Platform/application configuration, client-side controls and tampering resilience where scoped
What Botnet tests.
Testing is manual-led and supported by appropriate tooling. Findings are manually validated before reporting. Coverage follows reachable trust decisions and agreed risk; source-code review is not implied unless explicitly scoped.
Package and configuration
Manifest, entitlements, signing-related assumptions, exported components and platform security configuration.
Local data
Storage, caches, logs, screenshots, backups and clipboard behavior around sensitive information.
Runtime behavior
Client-side decisions, tampering resistance and sensitive operations under controlled instrumentation where authorized.
Identity
Authentication, session lifecycle, account recovery, device trust and role transitions.
Transport
Network communication, certificate handling and exposure of data between application and service.
Backend boundary
Authorization and workflow controls in supporting APIs when those endpoints are explicitly in scope.
How the work progresses.
- 01
Prepare
Confirm platforms, builds, accounts, devices and backend boundaries.
- 02
Decompose
Review package structure, configuration and reachable application flows.
- 03
Observe
Inspect storage, transport and runtime behavior in the agreed environment.
- 04
Challenge
Test trust decisions across app, platform and API.
- 05
Validate
Demonstrate impact safely without retaining unnecessary customer data.
- 06
Report
Separate client, platform and server-side remediation actions.
EVIDENCE + ACTION
What the customer receives.
- Mobile attack-surface summary
- Platform-specific findings with reproducible evidence
- Affected app and backend trust boundaries
- Severity/risk context and prioritized remediation guidance
- Scope and device limitations
- Technical readout and one re-test result for agreed remediated findings
Evidence over assumption.
01One model across package, runtime and backend
02Manual workflow and authorization analysis
03Clear ownership of client-side versus server-side fixes
04Evidence captured with mobile engineering teams in mind
Before scoping.
Are both Android and iOS included?
Only platforms and builds named in scope are included. Coverage and device requirements are confirmed before testing.
Is the supporting API tested?
API behavior may be included when endpoints and roles are explicitly scoped; a mobile assessment does not automatically authorize broader API testing.
Is certificate pinning bypassed?
Instrumentation techniques and their boundaries must be agreed. The public page does not imply that bypass work is included in every engagement.
Define the target, constraints and required evidence.
An assessment request starts a scoping conversation. It does not authorize testing. Work proceeds only after scope acceptance, executed authorization/SOW and kickoff.