← All repos

owasp-mstg

The OWASP Mobile Application Security Testing Guide (MASTG) is a comprehensive manual for mobile app security testing and reverse engineering. It describes technical processes for verifying the OWASP Mobile Security Weakness Enumeration (MASWE) weaknesses, which are in alignment with the OWASP MASVS.

androidandroid-applicationcompliancy-checklistdynamic-analysishackingiosios-appmastmastgmobile-appmobile-securitymstgnetwork-analysispentestingreverse-engineeringreverse-enginneringruntime-analysisstatic-analysistesting-cryptography
Browse cluster: Static Analysis & Code Quality
10,722commits
341contributors
2languages

Tech stack & purpose

The OWASP Mobile Application Security Testing Guide (MASTG) is a comprehensive manual for mobile app security testing and reverse engineering that describes technical processes for verifying security weaknesses in mobile applications across Android and iOS platforms. The project is maintained by OWASP, an open-source organization, and aligns with related standards including the OWASP Mobile Security Weakness Enumeration (MASWE) and the OWASP Mobile Application Verification Standard (MASVS). The repository includes supporting materials such as reverse engineering challenge apps (UnCrackable Apps) and sample implementations, along with Python scripts and GitHub Actions workflows for generating deliverables like checklists and documentation websites.

Languages

Python
94.4%
Shell
5.6%

Contributors (top 30 of 341)