BSides Canberra 2026

Luke Symons

Luke is a Principal Security Engineer and researcher at SEEK, where he specialises in mobile and web application security. He has discovered and responsibly disclosed a number of CVEs, and has contributed to the OWASP Mobile Security Testing Guide (MSTG). Luke is an active member of the Melbourne security community and has previously presented at Ruxmon Melbourne.


Session

09-24
15:15
55min
Whaling on mobile apps with Leviathan
Luke Symons

Mobile pentesters don't have a tooling problem. They have five tools and many problems. Between Frida, decompilers, instrumentation bridges, and platform-specific utilities, practitioners end up context-switching constantly just to assess a single product that ships on both iOS and Android.

This talk introduces Leviathan, a mobile auditing platform built to enable security research workflow into one interface. Leviathan helps trace real application flows, connect findings into meaningful vulnerability chains, and verify impact in modern mobile apps, all while making mobile auditing easier and less annoying. I'll start with a practical overview of today's mobile auditing workflow and where it breaks down, backed by real-world examples (including previous Samsung research). Then I'll explain the AppShark foundations including the Single Step Assessment that Appshark uses and its rule engine and show how Leviathan's scanning workflow features help find and validate the same classes of bugs with less friction and more enjoyable finishing with a live demo of the tool.

Off-Main Track
Off-Main Track