mobile-technique

Installation
SKILL.md

Mobile Pentest Technique

Goal: systematically identify security weaknesses in Android and iOS applications following OWASP MASTG/MASVS.

When this technique applies

  • Mobile application (Android or iOS) in scope for pentest or bug bounty.
  • Need to test authentication, storage, network, or platform-specific controls.
  • Reverse engineering mobile app logic or extracting secrets.

Boundary

  • CTF mobile tasks: flag-extraction from APK/IPA/backup → mobile-ctf (faster, CTF-specific patterns including .ab, Unity/IL2CPP, asset stego).
  • Input from web-exploit-technique: API-level findings from mobile app traffic.
  • Deep binary analysis: reversing-technique for obfuscated native libraries and IL2CPP binaries.
  • Tool skills: offensive-tools/rev/jadx/, offensive-tools/rev/apktool/, offensive-tools/rev/dex2jar/, offensive-tools/rev/androguard/, offensive-tools/rev/frida/.

Initial triage

Installs
4
GitHub Stars
22
First Seen
Sep 5, 2026
mobile-technique — aeondave/malskill