awesome-repositories.comCategoriesBlog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectMCP serverAboutHow we rankPress
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
OWASP avatar

OWASP/owasp-mstg

0
View on GitHub↗
12,973 stars·2,752 forks·Python·CC-BY-SA-4.0·9 viewsmas.owasp.org↗

Owasp Mstg

The Mobile Application Security Testing Guide is a comprehensive manual and compliance framework for verifying the security of mobile applications. It provides a standardized reference for identifying and validating common software security weaknesses and performing reverse engineering based on industry standards.

The project provides a structured set of technical processes and checklists used to audit applications against established security weakness enumerations. It encompasses guidance for analyzing application binaries and runtime behavior to identify hidden functionality and security gaps.

The framework covers mobile application security testing, compliance auditing, and software weakness verification across mobile architectures.

Features

  • Mobile Security Tools - Serves as a comprehensive guide and framework for conducting security audits and identifying vulnerabilities in mobile apps.
  • Binary Analysis - Provides a detailed workflow for reverse engineering and analyzing compiled binary executables to identify security vulnerabilities.
  • Mobile Security Assessment - Acts as a comprehensive manual for testing mobile app security and performing industry-standard reverse engineering.
  • Reverse Engineering and Decompilation - Includes comprehensive techniques for disassembling and decompiling mobile application binaries to uncover hidden functionality.
  • Reverse Engineering Guides - Offers detailed technical methodologies and guides for analyzing compiled mobile binaries and runtime behavior.
  • Application Security Standards - Provides a standardized reference of security weaknesses and baseline requirements for mobile software lifecycles.
  • Audit and Compliance - Provides the processes and checklists necessary to verify that mobile software adheres to established security and industry standards.
  • Security and Compliance - Combines technical security controls with formal compliance monitoring and reporting for mobile applications.
  • Weakness Verification - Identifies and validates specific security flaws using a standardized enumeration of known mobile software vulnerabilities.
  • Security Testing and Auditing - Provides a framework for identifying and validating software security flaws through standardized auditing processes.
  • Mobile App Security Auditing - Provides structured processes for auditing Android and iOS binaries to verify adherence to security industry standards.
  • Mobile Security Checklists - Offers a structured set of verification steps to ensure consistent security auditing across different mobile operating systems.
  • Weakness Enumerations - Implements a system for matching discovered flaws against predefined lists of known security weaknesses.
  • Runtime State Monitoring - Provides guidance on monitoring the internal state and behavior of running mobile processes to identify runtime security flaws.
  • Vulnerability Mapping - Links specific software vulnerabilities to high-level security standards for organized compliance reporting.
  • Security Control Validation - Provides a unified methodology for analyzing and validating security controls across both Android and iOS ecosystems.
  • Security Reference Materials - Comprehensive guide for mobile app security testing.
  • Vulnerable Testing Apps - Reverse engineering challenges for mobile security skill development.
  • Mobile Security - Comprehensive guide for mobile application security testing.
  • Mobile Security Resources - Comprehensive manual for mobile app security testing and reverse engineering.
  • Security References - Comprehensive manual for mobile app security testing.
  • Security Resources and Guides - Comprehensive security testing guide for mobile apps.
  • Security Standards - Comprehensive manual for mobile application security and testing.
  • Vulnerable Labs and Apps - Mobile security testing guide repository and apps.
  • Vulnerable Mobile Applications - Mobile applications for improving reverse engineering skills.

Star history

Star history chart for owasp/owasp-mstgStar history chart for owasp/owasp-mstg

AI search

Explore more awesome repositories

Describe what you need in plain English — the AI ranks thousands of curated open-source projects by relevance.

Start searching with AI

Frequently asked questions

What does owasp/owasp-mstg do?

The Mobile Application Security Testing Guide is a comprehensive manual and compliance framework for verifying the security of mobile applications. It provides a standardized reference for identifying and validating common software security weaknesses and performing reverse engineering based on industry standards.

What are the main features of owasp/owasp-mstg?

The main features of owasp/owasp-mstg are: Mobile Security Tools, Binary Analysis, Mobile Security Assessment, Reverse Engineering and Decompilation, Reverse Engineering Guides, Application Security Standards, Audit and Compliance, Security and Compliance.

What are some open-source alternatives to owasp/owasp-mstg?

Open-source alternatives to owasp/owasp-mstg include: ignitetechnologies/mindmap — Mindmap is a cybersecurity knowledge base and reference library that organizes security tools, frameworks, and… kjcracks/clutch — Clutch is a command-line utility designed for security research on jailbroken mobile devices. It functions as a… voltagent/awesome-claude-code-subagents — This project provides a framework for managing multi-agent systems, designed to automate complex software development,… owasp/owasp-masvs — NEW❗ The MASVS 2.0.0 is already available as a spreadsheet. We're currently working on updating this page and the… cisofy/lynis — Lynis is an automated security auditing and system hardening framework designed for UNIX-based operating systems. It… mvt-project/mvt — This project is a command-line forensic toolkit designed for the investigation and security auditing of mobile…

Open-source alternatives to Owasp Mstg

Similar open-source projects, ranked by how many features they share with Owasp Mstg.
  • ignitetechnologies/mindmapIgnitetechnologies avatar

    Ignitetechnologies/Mindmap

    8,656View on GitHub↗

    Mindmap is a cybersecurity knowledge base and reference library that organizes security tools, frameworks, and methodologies into a visual knowledge map. It functions as a curated directory of cheat sheets and command guides for offensive and defensive security operations, presented as a hierarchical interface with collapsible nodes. The project converts structured markdown files into navigable visual trees to facilitate the study of penetration testing workflows and DevOps learning roadmaps. It also serves as a security compliance framework, providing structured mappings of NIST and ISO 2700

    View on GitHub↗8,656
  • kjcracks/clutchKJCracks avatar

    KJCracks/Clutch

    3,810View on GitHub↗

    Clutch is a command-line utility designed for security research on jailbroken mobile devices. It functions as a specialized toolkit for identifying, decrypting, and extracting installed mobile application binaries to facilitate manual code inspection and vulnerability assessment. The tool provides capabilities for removing platform-level encryption from protected software, allowing researchers to isolate core executable files from application bundles. By performing memory-mapped file dumping and reconstructing binary headers, it enables the conversion of protected applications into portable,

    Objective-C
    View on GitHub↗3,810
  • voltagent/awesome-claude-code-subagentsVoltAgent avatar

    VoltAgent/awesome-claude-code-subagents

    21,906View on GitHub↗

    This project provides a framework for managing multi-agent systems, designed to automate complex software development, infrastructure, and business workflows. It functions as a multi-agent workflow orchestrator that routes tasks to domain-specific workers while maintaining state persistence and infrastructure automation. By leveraging large language models, the system decomposes high-level objectives into actionable plans, ensuring that complex operations are executed with consistency and reliability. The framework distinguishes itself through its hierarchical agent registry and policy-driven

    Shellai-agent-frameworkai-agent-toolsai-agents
    View on GitHub↗21,906
  • owasp/owasp-masvsOWASP avatar

    OWASP/owasp-masvs

    2,398View on GitHub↗

    NEW❗ The MASVS 2.0.0 is already available as a spreadsheet. We're currently working on updating this page and the related documents. Learn more about the refactoring process here.

    Python
    View on GitHub↗2,398
See all 30 alternatives to Owasp Mstg→