How to test a mobile app with Projects
Last updated: July 20, 2026
Projects are on-demand offensive security assessments (pentesting), carried out by experts (Strikers) over a defined scope. Mobile applications are always assessed as a Project, uploading the app as a target within the project.
A Project moves through four stages: Scope, Quote, Test, and Results. This article walks you through creating the project and uploading the app.
Step 1: Create the Project
From the Projects section:
Click New project.
Fill in the Project name (for example, "App security exercise").
Under What do you want to test?, choose Mobile (Android, iOS).
In Project goals, describe your objectives, key events, or important dates for the project.
Click Set up project.

Step 2: Define the scope
In the Scope stage, you define what will be tested and how:
Testing approach: choose the access level for the assessment:
Test with provided credentials: the test uses the credentials you provide, to assess the authenticated areas of the application.
Test without credentials: the test simulates an external attacker, with no authenticated access (black-box).
Targets to test: add at least one target with Create target. You need at least one target to be able to request the quote.
Optionally, you can attach supporting documentation to the project with the Attach files button in the left panel.

Step 3: Upload the app as a target
Clicking Create target opens the target creation flow in three steps (General → Settings → Confirmation). In the General step, you enter the app's details:
Operating system: choose Android App or iOS app.
Type: choose how you'll provide the app:
App URL/Target: if the assessment is on a URL, IP, or protocol. Fill in the APP URL/Target field.
IPA/APK/AAB File: if you'll upload the installable. Upload the file with Select file (IPA for iOS, APK or AAB for Android).
Target name: give it a name that makes the target easy to identify.
Test environment: select the environment where the target is: Development, Staging, or Production.
Technical documentation (recommended): you can upload supporting documentation for the app.
Complete the General step and continue with Next until you confirm the target.

What you need to upload the app
The app's operating system (Android or iOS).
The installable (IPA / APK / AAB) or the URL/Target, depending on how it will be assessed.
The environment where the target is (Development, Staging, or Production).
Considerations
Some applications include additional protections that may require a specially prepared build for the assessment to be carried out thoroughly. If this is the case for your app, your Strike team will let you know how to proceed.
What happens next in the Project
With the scope defined and at least one target uploaded:
Click Request quote to request the project's quote.
The Strike team reviews the scope and checks it against the amount of effort (hours) contracted, to make sure the scope is a good match. If needed, the team proposes an amount of hours.
Both parties need to agree on the effort and the scope to move forward. Final confirmation is done by Strike's operations team.
Once confirmed, a Striker is assigned and execution begins (Test stage).
When it's finished, you access the results with the findings and their validation (Results stage).
FAQ
What is a Project?
It's an on-demand offensive security assessment (pentesting), carried out by experts (Strikers) over a defined scope. It moves through the Scope, Quote, Test, and Results stages. For more information, see the article Projects: pentesting on demand.
How do I create a Project to test a mobile app?
From the Projects section in the sidebar, click New project, give it a name, choose the Mobile option under "What do you want to test?", and click Set up project.
Where do I upload my app's APK, IPA, or AAB?
In the Scope stage, click Create target. In the General step, choose the IPA/APK/AAB File type and upload the file with Select file.
What is the "testing approach"?
It's the access level for the assessment. You can choose Test with provided credentials (the test uses the credentials you provide, to assess authenticated areas) or Test without credentials (the test simulates an external attacker with no authenticated access).
Can I assess an app by URL instead of uploading the file?
Yes. In the target's Type field, you can choose App URL/Target and enter the URL, IP, or protocol.
Can I test Android and iOS in the same Project?
Yes. Upload each one as a separate target: one with Android App and another with iOS App, both from the Create target form. In each target, you choose the operating system in the Operating system field.
How many targets do I need to upload?
At least one. You need at least one target created to be able to move forward with the project.
Is it mandatory to attach documentation or fill in the project's goals?
No. The documentation, the Project goals, and the target's technical documentation are recommended, not mandatory. Completing them helps make the assessment more thorough and better focused.