[+] Familiarity with Network Basics (Network+)
[+] Familiarity with Linux (LPIC 1)
[+] Getting Familiar with Programming Basic Concepts (Python is Preferred)
- Variables, Loops, Conditions, OOP, etc.
- Interpreter vs Compiled Languages
- Common Intermediate Language (CIL) & Common Language Runtime (CLR)
- Understand What Are Byte-codes
- etc.
[+] Getting Familiar with Java Basics
[+] Understand the Android app development Language (Java & Kotlin)
[+] Understand Android OS Architecture, Security Mechanisms, and Android Life-cycle (
https://source.android.com)[+] Knowledge of basic security & PenTesting concepts (Security+, CEH)
[+] Basic Android Application Penetration Testing (Not Ordered)
- The Mobile Applications Hacker's Handbook
- Learning PenTesting for Android Devices
- Mobile Application Security Testing Guide (OWASP MASTG)
- eMAPT v2 (eLearnSecurity - INe Course)
- Android Exploitation (Pentester Academy)
- Android Application Penetration Testing (Pentester Academy)
- Android App Reverse Engineering (MaddieStone -
https://www.youtube.com/@maddiestonehacks)- Reading Android Bug Bounty Write-ups
[+] Intermediate Android Application Penetration Testing
- Familiarity with JavaScript
- Good Experience on Frida
- Knowledge of Smali
- Getting Hands on Native Reverse Engineering Tools (Ghidra & Radare2 Preferred)
- Getting Hands on Native Debugging Tools (GDB & Radare2 & IDA Pro are Preferred)
- Getting Hand on C# Reverse Engineering for Unity Applications (dnsPy Preferred)
[+] Advanced Android Penetration Testing
- Blue Fox: Arm Assembly Internals and Reverse Engineering
- ARM Assembly and ARM Exploit Development (
https://azeria-labs.com)- Android Security Internals: An in-Depth Guide to Android's Security
- Android Hacker's Handbook
- Android Kernel Exploitation (
https://cloudfuzz.github.io/android-kernel-exploitation)- Android User-Land Fuzzing and Exploitation (Black Hat Course)
#Roadmap
@TryHackBoxOfficial