Find the weakness.
Understand the fix.

Practical security workshops for the teams building, testing, and protecting Android apps.

Work through vulnerable and hardened app examples with James Cullimore. Inspect the behaviour, reproduce the issue, make the fix, and verify it using the same test.

Remote or onsiteHands-on labsAdapted to your team
Delivered for BMW

James delivered a 16-hour Android security workshop over four sessions through Education4Industry, for security experts and Android developers.

Meet your trainer

Recognise the risk. Verify the mitigation.

Security issues often sit outside normal feature logic: network trust, signing, deep links, storage, and exposed components. The workshop connects those Android mechanics to practical implementation decisions.

Understand

Know where to look

Diagnose certificate pinning failures, inspect APKs for exposed secrets, and recognise unsafe entry points and storage choices.

Implement

Make a targeted change

Apply secure Android defaults, review WebView configuration, and harden deep links, intents, and exposed components.

Verify

Show that the fix works

Retest the same attack path with logs, focused test cases, and the vulnerable and secure build variants.

Four sessions. Time to put it into practice.

An illustrative full programme: four 4-hour sessions, each combining explanation, guided lab work, and review. We agree the final agenda around your team’s priorities; focused workshops can cover a smaller selection.

Session 01 · 4 hours

Network trust & payload encryption

Understand HTTPS trust decisions and how to protect sensitive client-server traffic.

Explore the topics
  • HTTPS and certificate pinning
  • NetworkSecurityConfig
  • Certificate Transparency
  • End-to-end payload encryption concepts
Session 02 · 4 hours

Reverse engineering & APK tampering

Inspect shipped APKs, identify exposed implementation details, and understand tamper controls.

Explore the topics
  • JADX and apktool
  • Hardcoded secrets
  • R8 and ProGuard
  • App signing and signing checks
Session 03 · 4 hours

Deep links, intents & local storage

Review Android entry points, URI validation, and storage choices for sensitive app data.

Explore the topics
  • App Links and URI validation
  • Intent handling
  • EncryptedSharedPreferences and DataStore
  • Room and SQLCipher
Session 04 · 4 hours

WebView & exposed components

Audit WebView settings and Android components that can expand an app’s attack surface.

Explore the topics
  • JavaScript interfaces and unsafe URL loading
  • Exported components
  • Content provider leakage
  • Shared UID risks

Who is allowed to start this service?

An example from the IPC module: compare a deliberately exposed Android service with a version that checks who can call it.

  1. 01

    Reproduce the weakness

    Attempt to start the exported service from outside the vulnerable app. Observe whether the caller is allowed through.

  2. 02

    Understand the protection

    Inspect the manifest and compare the hardened variant: keep private components unexported, or require a signature permission where sharing is intentional.

  3. 03

    Retest the caller

    Repeat the access attempt against the hardened build. Check the installed package and logs to establish why an unauthorised caller is blocked.

The takeaway: verify access in the installed app, rather than relying on what the source manifest appears to say.

Read the sample lab walkthrough

Tools in this example: adb, logcat, and the vulnerable and secure app variants.

Included in the workshop

  • Training slidesFocused explanations and the decisions behind secure defaults.
  • A dedicated Android demo appExamples aligned with the network, APK, storage, IPC, and WebView modules.
  • Vulnerable and secure variantsCompare the attack path with the hardened implementation.
  • Hands-on exercisesInspection, reproduction, hardening, and verification.
Explore the training repository

Across the programme: Android Studio, adb, logcat, mitmproxy, JADX, and apktool.

Built around your team.

Who it is for

Android developers, mobile engineering leads, security engineers, and QA/test engineers. Also relevant to teams preparing for security reviews or audits.

Delivery & scope

Remote or onsite. A focused half-day or full-day workshop can cover selected topics; broader coverage can be spread across multiple sessions. We agree the scope and duration together.

Before the session

Participants should know basic Android concepts. Hands-on labs work best with Android Studio, adb, and a local emulator or test device.

Led by James Cullimore.

James brings hands-on Android engineering, security work, and developer teaching into the workshop. He also teaches Android testing, networking, and release workflows on droidcon Academy.

The training is delivered through James Cullimore Software Engineering, with James leading the security sessions.

Explore courses & talks

Understanding over checklists.

The aim is for participants to recognise why an implementation is vulnerable and how to test the mitigation—not just copy a configuration.

Explanations stay tied to Android behaviour, practical tools, and code that participants can inspect.

A few practical questions.

You do not need to arrive with a finished training brief. Start with the team, the problem, and the topics that matter most.

Do we need the full four-session programme?

No. The agenda above shows one way to cover the full syllabus. A focused half-day or full-day workshop can concentrate on selected topics. We agree the depth and duration before the training.

Do we need to share our production app?

The exercises use a dedicated training app with vulnerable and hardened variants, so participants can work through the lab examples without sharing a production codebase.

What should participants know beforehand?

Basic Android concepts are the starting point. For hands-on exercises, participants should have Android Studio, adb, and an emulator or test device. Tell us about the mix of developers, QA engineers, and security specialists so we can discuss a suitable level.

What information helps you prepare a proposal?

Send your approximate team size, Android and security experience, preferred topics, dates, and whether you prefer remote or onsite delivery. These give us a starting point for discussing scope, format, and cost.

Team training

Plan a workshop for your team.

Tell us your team size, experience, preferred topics, and dates. We’ll use that to discuss a suitable agenda, delivery format, and proposal.

Request a workshop proposalinfo@jamescullimore.dev