The OWASP Mobile Application Security Testing Guide (MASTG) is a comprehensive reference manual for mobile application security testing and reverse engineering.
The guide addresses the need for standardized, technically detailed processes to verify mobile security weaknesses across both Android and iOS platforms. It maps directly to the OWASP Mobile Application Verification Standard (MASVS) and the OWASP Mobile Security Weakness Enumeration (MASWE), creating a structured framework that connects security controls to concrete testing methodologies. The MASTG provides step-by-step technical procedures for static analysis, dynamic analysis, network analysis, runtime analysis, and cryptography testing specific to mobile environments.
Teams conducting mobile security assessments, penetration testers specializing in mobile applications, and organizations building compliance programs around mobile security should adopt this guide. It suits projects requiring alignment with established security standards and those needing detailed, platform-specific testing procedures rather than generic security checklists. The guide is particularly valuable for teams working within regulated industries or those adopting the MASVS framework, as it provides the technical verification methods that correspond to MASVS controls.
The project maintains active engagement with industry through documented adoption by platform providers and standardization bodies. Contributions are actively solicited and the project provides supplementary resources including crackmes for hands-on learning. The guide receives consistent updates to address evolving mobile security threats and testing techniques across both major mobile platforms.