Skip to main content

Mobile App Security Testing with SpartanX

Upload APK or IPA binaries, add them to collections, and launch SAST-only or SAST + runtime penetration test engagements for full mobile app security coverage.

Written by Antônio Baggio

SpartanX supports mobile application penetration testing for both Android and iOS. This guide walks through uploading mobile app binaries, organizing them into collections, and launching the right type of engagement for your testing objectives.


Uploading Mobile App Binaries

The first step is to upload your mobile application binary. Navigate to the Content section in the left-hand navigation and click the Upload button. SpartanX accepts both APK files for Android applications and IPA files for iOS applications. Once the upload completes, you will receive a confirmation notification confirming the file was received successfully.


Creating a Collection for Mobile Apps

After uploading your binary, create a collection to organize your mobile assets. Give the collection a descriptive name, such as "Martin's Mobile App Tests," and set the exposure type. In the vast majority of cases, mobile applications are externally facing since they are distributed through the Google Play Store or Apple App Store. Select Mobile Apps as the collection type and save.


Adding Assets to the Collection

With the collection in place, add your mobile application as an asset. Select the collection you just created and either upload the binary directly or choose from a previously uploaded file. Before the asset is added, SpartanX validates the image to confirm it is intact and has not been corrupted.


Once validated, the asset appears in the collection, clearly labeled as the specific mobile application binary.


Launching a Mobile App Engagement

Navigate to Engagements and click Launch Engagement. SpartanX offers two testing modes for mobile applications:

  • SAST Analysis: A static code analysis powered by AI that examines the APK or IPA file without executing it. No network guardrails or egress gateway configuration is required.

  • SAST and Runtime Test: A full penetration test that combines static analysis with dynamic runtime testing of the application as it executes.

For a pure static analysis, select the SAST option, filter the asset list to your mobile collection, confirm the selection, and start the engagement. Because there is no runtime component, no egress gateway or network policy configuration is required.


Conclusion

Mobile application security testing in SpartanX is a straightforward, three-step process: upload the binary, organize it into a collection, and launch the appropriate engagement. Whether you need a quick static code review or a full-blown penetration test with runtime analysis, SpartanX provides the tooling to support both approaches from a single platform.

Did this answer your question?