Mobile App Penetration Testing
Mobile app penetration testing is a manual security assessment of an Android or iOS application, its local storage, its runtime and the APIs behind it. Testing follows th...
Kochi, Kerala · Remote engagements worldwide
What this is
Abin Antony is an independent cybersecurity engineer in Kochi, Kerala, providing mobile, web, API and cloud penetration testing, secure code review and threat modelling. Engagements are fixed-scope and fixed-price, follow OWASP MASVS and ASVS, and include a free retest of every fixed finding.
Services
Fixed-scope, fixed-price assessments with a written report, a remediation call and a free retest of every fixed finding.
Mobile app penetration testing is a manual security assessment of an Android or iOS application, its local storage, its runtime and the APIs behind it. Testing follows th...
Web application penetration testing is a manual assessment of a live web application performed with real user accounts, targeting broken access control, injection, authen...
API security testing is a manual assessment of REST, GraphQL or gRPC endpoints against the OWASP API Security Top 10. It targets broken object and function level authoris...
Secure code review is a manual inspection of source code focused on the paths where security actually fails: authentication, authorisation, payment handling, cryptography...
A cloud security assessment reviews IAM permissions, network exposure, storage access, secrets management and CI/CD pipeline trust boundaries across AWS, GCP or Azure. Fi...
Threat modelling is a structured design review that maps data flows and trust boundaries, enumerates how each component can be abused, and ranks the controls worth buildi...
Developer security training is a hands-on workshop where a team exploits vulnerabilities in its own application and then fixes them, followed by wiring the matching check...
Method
Every finding lands with a proof of concept, a business-impact rating and a fix a developer can merge — because I spent five years on the other side of that pull request.
Targets, test windows, data handling and a signed authorisation. Nothing outside the agreed scope is touched.
Attack surface mapping and abuse cases, so testing hours go where the real risk lives.
Tool-assisted, human-driven testing. Findings are chained to prove genuine impact.
Reproduction steps, remediation walkthrough, and a retest of every fix at no extra cost.
abin@sec:~$ ls ~/toolchain
recon/ nmap amass subfinder httpx
web/ burpsuite ffuf sqlmap nuclei
mobile/ frida objection mobsf jadx apktool
cloud/ scoutsuite prowler trivy
code/ semgrep gitleaks dependency-check
abin@sec:~$ ▍
Answers
Direct answers, dated and maintained. No gated PDFs, no discovery call required.
A professional penetration test in India typically costs between ₹60,000 and ₹4,00,000 depending on scope. A single web application usually lands at ₹...
Read the answer →A typical application penetration test takes two to three weeks from kickoff to final report: two to three days of scoping and setup, five to ten days...
Read the answer →VAPT stands for Vulnerability Assessment and Penetration Testing. The vulnerability assessment is broad and largely automated, listing known weaknesse...
Read the answer →A vulnerability scan is an automated tool that compares your system against a database of known weaknesses and reports matches. A penetration test is...
Read the answer →Test at least once a year, and additionally after any change that alters your attack surface: a new authentication system, a major architecture refact...
Read the answer →A pre-launch penetration test is worth it if your product handles payments, personal data, health or financial records, or user-generated content. If...
Read the answer →Service areas
Kickoff workshops and developer training happen in person where travel makes sense. Testing itself is remote by default, which keeps travel off your invoice.
Blog
18 posts on mobile, web, API and cloud security — what turns up in assessments, and the structural fixes for it.
Compliance · 5 min read
The Act is short, and most of what it asks a product team for is engineering work you can do in a sprint: know what you hold, prove consent, delete on request, notice a breach.
Mobile security · 4 min read
Twenty checks, grouped the way an attacker looks at an app: what ships inside the package, what lands on the device, what crosses the network, and what the server accepts.
Mobile security · 4 min read
The Top 10 is written platform-agnostically. Here is what each risk looks like in a real Flutter project, and which package choice usually causes it.
Scope and a fixed quote within two working days. First consultation is free.