Know where to look
Diagnose certificate pinning failures, inspect APKs for exposed secrets, and recognise unsafe entry points and storage choices.
Practical security workshops for the teams building, testing, and protecting Android apps.
Work through vulnerable and hardened app examples with James Cullimore. Inspect the behaviour, reproduce the issue, make the fix, and verify it using the same test.
James delivered a 16-hour Android security workshop over four sessions through Education4Industry, for security experts and Android developers.
Meet your trainerSecurity issues often sit outside normal feature logic: network trust, signing, deep links, storage, and exposed components. The workshop connects those Android mechanics to practical implementation decisions.
Diagnose certificate pinning failures, inspect APKs for exposed secrets, and recognise unsafe entry points and storage choices.
Apply secure Android defaults, review WebView configuration, and harden deep links, intents, and exposed components.
Retest the same attack path with logs, focused test cases, and the vulnerable and secure build variants.
An illustrative full programme: four 4-hour sessions, each combining explanation, guided lab work, and review. We agree the final agenda around your team’s priorities; focused workshops can cover a smaller selection.
Understand HTTPS trust decisions and how to protect sensitive client-server traffic.
Inspect shipped APKs, identify exposed implementation details, and understand tamper controls.
Review Android entry points, URI validation, and storage choices for sensitive app data.
Audit WebView settings and Android components that can expand an app’s attack surface.
An example from the IPC module: compare a deliberately exposed Android service with a version that checks who can call it.
Attempt to start the exported service from outside the vulnerable app. Observe whether the caller is allowed through.
Inspect the manifest and compare the hardened variant: keep private components unexported, or require a signature permission where sharing is intentional.
Repeat the access attempt against the hardened build. Check the installed package and logs to establish why an unauthorised caller is blocked.
The takeaway: verify access in the installed app, rather than relying on what the source manifest appears to say.
Read the sample lab walkthroughTools in this example: adb, logcat, and the vulnerable and secure app variants.
Across the programme: Android Studio, adb, logcat, mitmproxy, JADX, and apktool.
Android developers, mobile engineering leads, security engineers, and QA/test engineers. Also relevant to teams preparing for security reviews or audits.
Remote or onsite. A focused half-day or full-day workshop can cover selected topics; broader coverage can be spread across multiple sessions. We agree the scope and duration together.
Participants should know basic Android concepts. Hands-on labs work best with Android Studio, adb, and a local emulator or test device.
James brings hands-on Android engineering, security work, and developer teaching into the workshop. He also teaches Android testing, networking, and release workflows on droidcon Academy.
The training is delivered through James Cullimore Software Engineering, with James leading the security sessions.
Explore courses & talksThe aim is for participants to recognise why an implementation is vulnerable and how to test the mitigation—not just copy a configuration.
Explanations stay tied to Android behaviour, practical tools, and code that participants can inspect.
You do not need to arrive with a finished training brief. Start with the team, the problem, and the topics that matter most.
No. The agenda above shows one way to cover the full syllabus. A focused half-day or full-day workshop can concentrate on selected topics. We agree the depth and duration before the training.
The exercises use a dedicated training app with vulnerable and hardened variants, so participants can work through the lab examples without sharing a production codebase.
Basic Android concepts are the starting point. For hands-on exercises, participants should have Android Studio, adb, and an emulator or test device. Tell us about the mix of developers, QA engineers, and security specialists so we can discuss a suitable level.
Send your approximate team size, Android and security experience, preferred topics, dates, and whether you prefer remote or onsite delivery. These give us a starting point for discussing scope, format, and cost.
Tell us your team size, experience, preferred topics, and dates. We’ll use that to discuss a suitable agenda, delivery format, and proposal.
Request a workshop proposalinfo@jamescullimore.dev