c0c0n is a 19 years old platform that is aimed at providing opportunities to showcase, educate, understand and spread awareness on Information Security, data protection, and privacy...
This course will take any student and ensure that:
Their overall proficiency in mobile security is significantly higher than when they arrived. The skills acquired can be immediately applied to Android, iOS, and IoT security assessments.
Their skills can be continuously sharpened via ongoing, free access to the training portal and updated 2026 Edition content.
They are equipped to defeat common mobile assessment challenges such as root/jailbreak detection, certificate/public key pinning, lack of source code, and limited device access.
Students new to mobile security gain a solid, practical foundation in Android and iOS security testing.
Advanced students leave with enhanced workflows and deeper insights into cross‐platform and IoT‐centric assessments.
All skills taught are practical, field‐tested, and directly applicable to real‐world penetration tests and code reviews.
This course is the culmination of years of hands-on penetration testing of Android, iOS, and IoT ecosystems, plus countless hours of focused research by the 7ASecurity team. It is structured around the OWASP Mobile Security Testing Guide (MSTG) and relevant items of the OWASP Mobile Application Security Verification Standard (MASVS). As a result, it not only covers the OWASP Mobile Top Ten but also the attack vectors that actually show up in modern production environments.
The 2026 Edition updates all labs, examples, and case studies with findings from recent 7ASecurity engagements: VPN clients, secure messaging apps, censorship‐circumvention tools, connected toys, mobile‐controlled devices, and government‐mandated apps, among others. The material is drawn from real issues in real apps, not artificial lab‐only vulnerabilities.
7ASecurity is an ISO 27001 and SOC 2–certified cybersecurity consultancy and OWASP Platinum Supporter that focuses on researcher‐led, heavily manual penetration tests and secure code audits. Lessons learned from these engagements—performed for organizations such as the Linux Foundation, Mozilla, the Tor Project, and others—feed directly into the course material, labs, and case studies.
Our courses are 100% hands-on. Instead of long slide decks, you get practical challenges and guidance to solve them, learning how to troubleshoot common problems and build efficient workflows. To keep both new and advanced students engaged, the content is intentionally comprehensive. In practice, no student has completed every challenge during the live class—which is why training continues after the event through our frequently updated training portal, for which you receive lifetime access and unlimited email support.
Day 1 – Android & IoT : We start with Android security architecture, then deep‐dive into static and dynamic analysis of Android apps, with a strong emphasis on finding IoT vulnerabilities via app and API analysis. The day ends with an Android & IoT‐focused CTF.
Day 1 – iOS & IoT: : We cover iOS architecture and defenses before performing static and dynamic analysis of iOS apps, including jailbreak detection and pinning bypasses and iOS‐specific secure storage issues. The day closes with an iOS & IoT CTF.
Day 3 – Cross‐platform Instrumentation: We focus on advanced dynamic instrumentation on both Android and iOS, mainly using Frida and Objection along with Xposed and related tooling. You will learn how to overcome common challenges and build powerful runtime hooks and automation, culminating in a cross‐platform instrumentation CTF.
Teaser Video: :
Get a free taste of this training, including access to video recordings, slides, and vulnerable apps to play with:
https://7asecurity.com/free-workshop-mobile-practical, https://7asecurity.com/free-workshop-mobile-deeplinks-xss
This is more than a typical “physical attendance” course. You receive the full 2‐day live intensive plus lifetime access to a training portal with step‐by‐step video recordings, slides, and lab exercises—including all future updates to the 2026 Edition at no additional cost.
Students can learn at their own pace during and after the course. Portal access ensures that topics can be reviewed on demand, for example right before a new engagement or when facing a tricky Android/iOS/IoT issue.
The training is built entirely from real vulnerabilities observed in real applications, not fabricated lab vulnerabilities that never appear in practice. You will see patterns from actual 7ASecurity penetration tests and code audits across multiple industries and countries.
The goal is to start from core concepts and ensure that each student leaves with a much higher level of proficiency in mobile penetration testing. You will learn how to: Identify the attack surface of Android, iOS, and IoT apps. Exploit interesting vulnerabilities and misconfigurations. Communicate and validate effective fixes.
From defeating root/jailbreak detection and certificate pinning, to modifying app behavior at runtime and inspecting what apps are really doing, this course emphasizes effective, repeatable techniques you can take back to your day job.
Because the course has been written and refined by professional mobile app penetration testers over many years, it includes practical tips on where to focus, how to leverage automation safely, and how to make your testing both faster and more thorough.
Learn how to uncover IoT vulnerabilities using only the Android and iOS apps and their APIs, even when you never have physical access to the hardware.
Build a repeatable, MSTG‐aligned workflow for finding and exploiting vulnerabilities in Android and iOS apps, from static analysis and repackaging to dynamic analysis and runtime instrumentation.
Improve your Android and iOS testing process by leveraging open source tools and frameworks and by applying battle‐tested tips and tricks shared by instructors with years of mobile app penetration testing experience.
Completing this training ensures attendees will be competent and able to:
A laptop with the following specifications:
This is more than a typical one‐day course: you receive lifetime access to a training portal with step‐by‐step video recordings, slides, and lab exercises, including all future updates at no additional cost—but the live session is focused on hands‐on work, not slide‐driven lectures.
Do not expect instructors to talk through slides most of the time. This class is practical, not theoretical: you’ll spend the majority of your time working on exercises while instructors help you solve the challenges you encounter.