awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectMCP serverAboutHow we rankPress
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
OWASP avatar

OWASP/mastg

0
View on GitHub↗

AI search

Explore more awesome repositories

Describe what you need in plain English — the AI ranks thousands of curated open-source projects by relevance.

Start searching with AI
mas.owasp.org
↗

Mastg

The Mobile Application Security Testing Guide is a comprehensive framework and technical resource designed for the assessment of mobile software security. It provides a structured collection of requirements and methodologies to identify vulnerabilities and security flaws in mobile applications prior to their deployment.

The project distinguishes itself by integrating reverse engineering techniques with standardized testing procedures to evaluate application logic and binary structures. It supports both Android and iOS platforms, utilizing threat-model-driven methodologies to ensure that security assessments are aligned with identified attack vectors and established industry frameworks.

The framework covers a broad range of security verification capabilities, including static analysis of source code and binaries, dynamic instrumentation for real-time assessment, and environment-isolated sandboxing. These procedures allow for the systematic investigation of application architectures and the verification of security controls against consistent evaluation criteria.

Features

  • Security Testing Methodologies - Serves as the primary comprehensive framework for verifying mobile application security through standardized testing and assessment techniques.
  • Mobile Security Tools - Provides a comprehensive framework for evaluating mobile software vulnerabilities through standardized testing and reverse engineering.
  • Security Assessment Frameworks - Provides a structured collection of technical requirements and testing methodologies for identifying security flaws in mobile software.
  • Security Assessment Methodologies - Provides structured methodologies for analyzing Android applications to identify security risks and verify compliance.
12,985 stars·2,757 forks·Python·CC-BY-SA-4.0·6 views
  • iOS Security Auditing - Provides security review methodologies for iOS applications to detect vulnerabilities and ensure data protection.
  • Reverse Engineering Guides - Provides technical guidance on analyzing mobile application binaries to uncover security vulnerabilities and logic flaws.
  • Vulnerability Research - Investigates mobile application architectures to discover and document security weaknesses using professional research methodologies.
  • Verification Procedures - Provides technical procedures to verify mobile security controls against standardized requirements before production deployment.
  • Reverse Engineering Tools - Provides techniques for decompiling and disassembling mobile binaries to reconstruct logic and identify hidden vulnerabilities.
  • Threat Modeling - Structures security assessments around identified attack vectors and adversary paths to ensure comprehensive coverage.
  • Sandbox and Isolation - Utilizes isolated runtime environments to safely execute and observe mobile application behavior during security testing.
  • Dynamic Binary Instrumentation - Provides methodologies for hooking into running mobile application processes to intercept function calls and modify memory state for security assessment.
  • Static Analysis - Includes procedures for analyzing mobile source code and binary structures to identify security flaws without runtime execution.
  • Security Requirement Frameworks - Defines standardized security requirements and evaluation criteria for consistent mobile application assessment.
  • Star history

    Star history chart for owasp/mastgStar history chart for owasp/mastg

    Open-source alternatives to Mastg

    Similar open-source projects, ranked by how many features they share with Mastg.
    • voorivex/pentest-guideVoorivex avatar

      Voorivex/pentest-guide

      2,761View on GitHub↗

      This project is a comprehensive web application penetration testing guide and vulnerability research framework. It provides a structured methodology for identifying and exploiting security flaws through a phased approach involving reconnaissance, analysis, and exploitation. The resource is distinguished by its use of a curated methodology framework that links theoretical vulnerability patterns to real-world bug bounty reports and historical exploit examples. It includes a payload-based testing library and a reference system that maps specific vulnerability categories to recommended third-part

      bugbountybypassowasp-tests
      View on GitHub↗2,761
    • kathanp19/howtohuntKathanP19 avatar

      KathanP19/HowToHunt

      7,146View on GitHub↗

      HowToHunt is a bug bounty hunting knowledge base and a structured guide for web application penetration testing. It provides a research methodology for organizing security testing procedures and validating application behaviors against known vulnerability patterns. The project features a curated library of security flaws and reconnaissance techniques. It organizes security testing into modular playbooks, checklists, and categorical vulnerability mappings to align specific exploitation techniques with target weaknesses. The repository covers a systematic sequence of information gathering task

      bugbountybugbountytipsbughunting-methodology
      View on GitHub↗7,146
    • carpedm20/awesome-hackingcarpedm20 avatar

      carpedm20/awesome-hacking

      15,722View on GitHub↗

      This project is a comprehensive, community-curated directory of cybersecurity resources, tools, and educational materials. It functions as a centralized index for researchers and students to discover frameworks and utilities across the entire security lifecycle, ranging from initial vulnerability assessment to post-exploitation analysis. The repository distinguishes itself through a hierarchical taxonomy that organizes diverse security disciplines into a searchable, version-controlled knowledge base. Rather than hosting software directly, it utilizes a decentralized aggregation model that lin

      awesomehacking
      View on GitHub↗15,722
    • hacktricks-wiki/hacktricksHackTricks-wiki avatar

      HackTricks-wiki/hacktricks

      11,700View on GitHub↗

      HackTricks is a comprehensive cybersecurity knowledge base and wiki designed to support ethical hacking, penetration testing, and infrastructure security auditing. It serves as a structured reference guide for security professionals, providing detailed documentation on common vulnerabilities, attack vectors, and remediation strategies across diverse software and network environments. The project distinguishes itself by offering actionable methodologies for identifying and analyzing security flaws. It functions as a centralized repository for security research, enabling practitioners to study

      CSShackinghacktrickspeass
      View on GitHub↗11,700
    See all 30 alternatives to Mastg→

    Frequently asked questions

    What does owasp/mastg do?

    The Mobile Application Security Testing Guide is a comprehensive framework and technical resource designed for the assessment of mobile software security. It provides a structured collection of requirements and methodologies to identify vulnerabilities and security flaws in mobile applications prior to their deployment.

    What are the main features of owasp/mastg?

    The main features of owasp/mastg are: Security Testing Methodologies, Mobile Security Tools, Security Assessment Frameworks, Security Assessment Methodologies, iOS Security Auditing, Reverse Engineering Guides, Vulnerability Research, Verification Procedures.

    What are some open-source alternatives to owasp/mastg?

    Open-source alternatives to owasp/mastg include: voorivex/pentest-guide — This project is a comprehensive web application penetration testing guide and vulnerability research framework. It… kathanp19/howtohunt — HowToHunt is a bug bounty hunting knowledge base and a structured guide for web application penetration testing. It… carpedm20/awesome-hacking — This project is a comprehensive, community-curated directory of cybersecurity resources, tools, and educational… hacktricks-wiki/hacktricks — HackTricks is a comprehensive cybersecurity knowledge base and wiki designed to support ethical hacking, penetration… radare/radare2 — radare2 is a reverse engineering framework and binary analysis toolset. It functions as a multi-architecture… frida/frida — Frida is a dynamic binary instrumentation toolkit that provides a framework for deep process introspection and live…