Explore red team engagements and the often-overlooked risks associated with mobile devices in this DefCamp 2019 conference talk. Delve into the fundamentals of red teaming, its phases, and the significance of mobile security. Examine two real-world scenarios involving mobile applications, learning about tools for Android app analysis and penetration testing techniques. Discover how to leverage existing pentesting tools for mobile targets and gain insights into using Frida for mobile app penetration testing, including creating backdoors, offensive instrumentation, and automating with Gadget Config. Conclude with a discussion on reverse shells using Frida and explore potential areas for further research in this critical aspect of information security.
Red Team Engagements and the Forgotten Risk of Mobile Devices - DefCamp - 2019