Mobile Reverse Engineering

Mobile reverse engineering is hands-on, engineer-performed analysis of a compiled mobile application — assessing what sensitive information, credentials, authentication artifacts, application logic, or client-side functionality could realistically be extracted or abused from the distributed application. It is manual and tool-assisted work, distinct from and complementary to automated static analysis.

Delivered as part of the Product Security Assessment engagement — Starting at $15,000

Who This Is Built For

  • Mobile applications that handle credentials, payment data, health information, or other sensitive personal data
  • Teams that need to understand their application's client-side attack surface beyond what static scanning alone reports
  • Organizations preparing for an enterprise security questionnaire or app-store review that asks about binary-level protections
  • Products where an engineer's manual judgment on exploitability meaningfully changes the risk picture

Typical Engagement Scope

Engagements are scoped collaboratively — this describes typical coverage, not a fixed checklist applied uniformly.

Typically Included

  • Static analysis of the application binary (APK and/or IPA)
  • Application structure and native library observations
  • Client-side attack surface review
  • Local storage and API endpoint discovery

May Be Included, Depending on Scope

  • Dynamic analysis, where applicable to the platform and artifact
  • Certificate pinning and root/jailbreak detection review
  • Token handling and authentication implementation observations

Outside This Engagement

  • Access to production systems, backend infrastructure, or live customer data
  • Any testing beyond the specific, explicitly authorized application artifact
  • Exploitation of any kind outside agreed, written scope

Representative Deliverables

Risk prioritization
Executive presentation
Technical walkthrough
Optional remediation validation

Deliverables reflect agreed scope — not every engagement includes every item. See the full deliverables breakdown on the Services hub.

What a Report for This Engagement Looks Like

Structure only — no findings are shown here. Every real report reflects the engagement's actual scope and results.

Sample Report Structure — Demonstration Only

Executive Reporting

Executive Summary

A plain-language overview of business risk and overall posture, for stakeholders who don't need technical detail.

Executive Recommendations

Strategic, prioritized next steps aimed at leadership, not implementation detail.

Reverse Engineering Findings

Reverse Engineering Summary

A plain-language overview of what manual binary analysis covered and found.

Binary Analysis

Findings from static and, where applicable, dynamic analysis of the compiled application artifact.

Authentication Review

How the mobile application implements authentication and session handling, observed directly in the binary.

Local Storage Review

What the application stores on-device, and how it's protected.

Certificate Pinning Review

Whether and how the application validates the server certificates it connects to.

Sensitive Data Exposure Review

Where sensitive information could realistically be exposed client-side.

Architecture & API Observations

Architecture Observations

How the application's components and trust boundaries fit together.

API Surface Observations

Endpoints and API behavior discovered through manual analysis of the client.

Assessment Process

  1. Discovery

    An initial conversation about the application, goals, and constraints.

  2. Scope Definition

    Engagement scope, tier, and boundaries are agreed in writing before work begins.

  3. Kickoff

    Access, authorization, and points of contact are confirmed with the client.

  4. Assessment

    Manual and tool-assisted review of the authorized application, repository, or artifact.

  5. Engineering Review

    Findings are validated and prioritized by the engineer who performed the assessment.

  6. Report Preparation

    Executive and technical findings are documented with evidence and remediation guidance.

  7. Executive Briefing

    Business risk and priorities are presented to stakeholders in plain language.

  8. Developer Walkthrough

    Technical findings are reviewed directly with the engineering team.

  9. Optional Validation

    A follow-up review to confirm remediation, scoped and scheduled separately.

For the full engineering practice behind every engagement, see the Methodology page.

Common Questions

No. Analysis is performed only on the specific application artifact the client provides, with explicit written authorization. Strata does not access production infrastructure, backend systems, or live customer data as part of this engagement.
No. Static and dynamic analysis of an application binary is a different discipline from a network or infrastructure penetration test — it focuses on what the distributed application artifact itself exposes, not live systems.
A build of the application (APK and/or IPA) and written authorization to analyze it. Source code can help but is not required — this is binary-level analysis by design.
Mobile reverse engineering is delivered as part of the Product Security Assessment, which combines it with application security review and client-side attack surface analysis for full context.

Scope Your Assessment

Every engagement starts with a conversation, not a purchase.