SEC536: Adversarial AI - Penetration Testing AI Systems


Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact UsKey findings:
The review's overall takeaway is that Corellium doesn't replace manual mobile security analysis, but it removes several of the biggest practical obstacles to it, particularly on iOS. Testing recent iOS versions has traditionally required jailbroken hardware that is hard to obtain and share across a distributed team; Corellium's virtualized approach gives root-level access, tool compatibility, and shareable snapshots without that hardware dependency. The reviewer notes that automated tools like MATRIX can surface likely issues quickly, but reverse engineering complex application logic still requires a human analyst. The review was conducted by a SANS Certified Instructor and Mobile Solution Lead, who tested the Corellium Viper environment directly, including creating and interacting with a virtual iPhone 16 Pro Max on iOS 18.3.1 and validating the MATRIX automated testing tool against the OWASP iGoat-Swift benchmark application.
Mobile app security is more critical—and more complex—than ever. With growing pressure to release quickly, mobile security teams often face tough trade-offs: limited access to devices, remote team coordination challenges, and slow, unreliable emulators that fail to mirror real-world behavior.



Jeroen Beckers is a SANS instructor and Mobile Solution Lead at NVISO, specializing in Android and iOS security.
Read more about Jeroen Beckers