owasp-mastg

Mobile App Security Guide

A comprehensive guide to mobile app security testing and reverse engineering

The Mobile Application Security Testing Guide (MASTG) is a comprehensive manual for mobile app security testing and reverse engineering. It describes the technical processes for verifying the controls listed in the OWASP Mobile Application Security Verification Standard (MASVS).

GitHub

12k stars
424 watching
2k forks
Language: Python
last commit: almost 2 years ago
Linked from 4 awesome lists

androidandroid-applicationcompliancy-checklistdynamic-analysishackingiosios-appmastmastgmobile-appmobile-securitymstgnetwork-analysispentestingreverse-engineeringreverse-enginneringruntime-analysisstatic-analysistesting-cryptography

Backlinks from these awesome lists:

Related projects:

RepositoryDescriptionStars
owasp/wstgA comprehensive guide to testing the security of web applications and services7,431
owasp/cheatsheetseriesProvides concise security guidance for web application developers28,396
tanprathan/mobileapp-pentest-cheatsheetA collection of tools and resources for conducting security assessments and penetration testing on mobile applications.4,609
tanprathan/owasp-testing-checklistA comprehensive security testing checklist based on OWASP guidelines1,523
webpwnized/mutillidaeAn intentionally vulnerable web application designed to aid in learning and practicing web security skills1,282
xtiankisutsa/mara_frameworkAn all-in-one toolkit to analyze and test mobile applications for security vulnerabilities630
mobsf/mobile-security-framework-mobsfAn automated, all-in-one platform for mobile application security assessment and analysis17,691
owasp/raiderA framework for simulating and testing complex web authentication processes104
0xradi/owasp-web-checklistA comprehensive checklist for web application security testing and vulnerability assessment1,763
coreruleset/corerulesetA comprehensive set of rules to detect and prevent web application attacks2,330
owasp/nettackerAutomated tool for identifying vulnerabilities and gathering information about network services and systems.3,700
owasp/iotgoatA deliberately insecure firmware designed to test common vulnerabilities in IoT devices717
voorivex/pentest-guideA comprehensive guide for penetration testing and vulnerability assessment based on OWASP guidelines2,497
owasp-amass/amassAn information gathering and reconnaissance tool used to map attack surfaces and discover external assets on networks.12,185
owasp/joomscanAutomated vulnerability scanner for Joomla CMS deployments to identify potential security issues.1,088