← Back to list

eMAPT 2023: My Journey and Review

Hi, I am back after few holidays and some busy work days. Today I will be talking about one of the most talked cert in the industry when…

Astik Rawat · 2023-03-06 11:42 · 80 claps · 4.4 min read
#emapt #mapts #mobile-app-development #mobile-penetration-test #tcm-academy
Open on Medium ↗

eMAPT 2023: My Journey and Review

Hi, I am back after few holidays and some busy work days. Today I will be talking about one of the most talked cert in the industry when people start Mobile Penetration Testing i.e. eLearnSecurity Mobile Application Penetration Testing also known as eMAPT. I passed the exam on my first attempt a few days ago and just wanted to share everything I learnt on the whole journey.

eMAPT: eLearnSecurity Mobile Application Penetration Tester

eMAPT: eLearnSecurity Mobile Application Penetration Tester

Background

If you are new here then I would like to you give you a small intro of myself. I am Astik Rawat, Security Consultant working mostly on Web Application and Network Penetration Testing. Recently I started learning Mobile App Testing. When comes to Mobile App Testing certs, I only came across eMAPT which fit my budget and as I already did eJPT before so I knew the exam would be a good chance to check my progress. I wrote an eJPT blog (My Journey for eJPT-eLearnSecurity) a while ago you can also check that if you are planning to go for the exam.

Preparation

To learn mobile app testing, I went with **TCM Academy Mobile Application Penetration Testing** few months ago to get started with it. It teaches you from Android to iOS Application testing. Not only that it also teaches you few more methods on your lab setup with live hunting real-world app examples. Thanks to the TCM Academy, Heath Adams and Instructor Aaron for putting in such an amazing course.

I never did INE Mobile App course, I did start it when I was in a year subscription but I never finished it and soon it was no more. I remember the start was too much of architecture theory and kind of boring for me while TCM Academy also had the same part but little shorter and just on point. It is also important to learn the whole system on Android and iOS and how it works so when comes to understanding the whole architecture I would say INE is better.

Exam

I bought the voucher when there was a 20% discount and held it since then. The validity of the exam after purchase is 6 months, so kept postponing and spending time learning and research. On its last month, I thought of starting the exam but I was still scared because my Android Development skill was very low (NULL in my POV) and I started it.

Well there were two Android Applications, both were vulnerable and to successfully pass the exam, I need to create a new Android Application which will exploit both of them via the new App.

It took me a couple of seconds to find the vulnerability in both of the app. When comes to exploit it was a little complicated for me because I haven’t done any such exercises. So exploitation took me a while, I also went with many security blogs and research to find its exploitation and learnt a lot through it. I was able to submit the POC and APK file.

I came across a tool called drozer and it was very helpful to understand the whole exploitation part.

Personal Thoughts on eMAPT

Well I would say the exam was almost nothing like a real world application and outdated. Before starting the exam I prepared few things which were not in use. Also the whole exam was kind of dull in my point of view. But it was worth it at the end of the day for me as I learnt new things and tools. Also some research taught me a lot. So by the end I learnt something, so it was a win for me.

The only con would be it is outdated and limited, if its scope was little big and complex — It would have been more fun and then be one of the best Mobile App testing certificate at this budget.

For people asking, if they don’t have android development background. I also didn’t had much experience I can understand some code but when comes to code — I am not very good. But I started the exam and just went with the flow. I wouldn't recommend it, if you understand some code and formatting then it would be fine. You will be able to find most of the format and code snippets to do anything in Java.

Personal Tips:

  • As It is a 7 Day Exam and there is no report to write just your POC code and APK file so take your time.
  • Logcat (Android Studio) is your best friend, if you want to check logs/errors just look at it and you can google the logs to understand what might be the issue in your application.
  • I would recommend check the drozer tool and play around.
  • Until unless you have an Android Developer and had did few projects on it hands on. Choose Java to develop your Android Application as there are many questions answered in the past and you might literally find the code snippet which you could use in your android app.
  • Learn how to work on Algorithm: Encryption and Decryption part on
  • For someone who is trying to submit the report and when archived but is bigger than the upload limit. You can delete the build folder as it only stores the generated and compiled java file. So it safe to delete the built folder itself.
  • When you started creating your java application, you need to follow its requirement Minimum SDK, as long as it is running in that SDK it doesn't matter in which SDK it is compiled. So you need to check your POC App run in the same SDK as the requirement SDK.
  • Do not forget to open the victim apps before you run your exploit.

Anyway that is all for eMAPT. I hope you liked and enjoyed the blog. As always if you are interested to move towards Mobile Application Security Testing, you can go with some online courses like TCM Academy, INE, or some good reviewed Udemy courses. It isn’t too difficult there was a time while I was in exam maybe 3–4 days in and I wasn't able to finish the POC yet but I found a High-Rated Vulnerability on a Real world Mobile Application while working!! YAY!!! So just give your best and learn everyday. Hope to see you again very soon. I am looking forward to bring more reviews, walkthrough or just some raw research. If you have any question regarding this, please feel free to drop me a message on my LinkedIn and if we haven’t connected yet then why spend some more time waiting ;)

Cheers, Have a good one and Happy Hacking…


메타데이터
post_id
f4b501d09f61
slug
emapt-2023-my-journey-and-review-f4b501d09f61
url
https://medium.com/@astikrawat/emapt-2023-my-journey-and-review-f4b501d09f61
canonical_url
https://medium.com/@astikrawat/emapt-2023-my-journey-and-review-f4b501d09f61
author_url
https://medium.com/@astikrawat
status
ok
fetched_at
2026-06-29 01:02:39