I will perform android apk security testing
Reverse Engineer, Pentester, Malware Analyst, OSCP CEH eJPT
About this Gig
Is your Android APK secure before release, or do you need to check a suspicious app?
I will perform a professional Android APK security analysis to identify vulnerabilities, insecure configurations, privacy risks, exposed secrets, and suspicious behavior.
My analysis can include:
- APK static analysis
- Android manifest and permission review
- Hardcoded API keys, secrets, URLs, and tokens
- Exported activities, services, receivers, and providers
- Insecure storage and logging risks
- Suspicious libraries, trackers, and network endpoints
- Runtime behavior analysis
- Network traffic and API endpoint observations
- SSL pinning and root/emulator detection review
- Manual reverse engineering of relevant components
- Clear PDF report with findings and remediation guidance
Depending on the selected package, I use static analysis, dynamic testing, network inspection, and manual reverse engineering to provide practical findings, not just automated scanner output.
FAQ
What do you need to begin the analysis?
Please provide the APK file or an authorized download link, a short description of the application, your primary concerns, and confirmation that you own the application or have permission to assess it.
Do you perform both static and dynamic analysis?
Static analysis is included in all packages. Dynamic runtime analysis is included in the Standard and Premium packages.
Can you determine whether an APK is malicious?
Yes. I can inspect an APK for suspicious permissions, embedded URLs, unusual libraries, network behavior, persistence-related functionality, data collection risks, and other indicators. The depth of the investigation depends on the selected package.
Will you test API endpoints used by the application?
Basic endpoint observations are included in the Standard package. A deeper review of relevant mobile API behavior is included in the Premium package. A full API penetration test may require a custom offer.
Do you bypass SSL pinning or root detection?
I can assess SSL pinning, root detection, and emulator-detection mechanisms during an authorized security review. The purpose is to document security weaknesses and recommend improvements.
Do you modify or crack Android applications?
No. I do not provide unauthorized modifications, paid-feature unlocking, account access, license bypasses, or services intended to violate an application owner’s rights.
Will I receive a report?
Yes. Each package includes a PDF report. Standard and Premium reports include more detailed findings, evidence, severity ratings, and remediation recommendations.
Can you analyze large or heavily obfuscated applications?
Yes, but the required effort varies. Please send the APK before placing an order so that I can recommend the appropriate package or prepare a custom offer.

