owasp/mastg

The OWASP Mobile Application Security Testing Guide (MASTG) is a comprehensive manual for mobile app security testing and reverse engineering. It describes...

View on GitHub ↗Jump to charts ↓

Summary Information

Updated 48 minutes ago
Added to GitGenius on September 4th, 2026
Created on September 30th, 2016
Open Issues & Pull Requests: 238 (+0)
GitHub issues: Enabled
Number of forks: 2,788
Total Stargazers: 13,157 (+0)
Total Subscribers: 415 (+0)

Charts & Analytics

Fetching additional details & charts...

Issue Activity (beta)

Issue API getrepoissuespagesummary failed: 429 Rate limit exceeded. Please try again later.

Detailed Description

The OWASP Mobile Application Security Testing Guide (MASTG) is a comprehensive reference manual for mobile application security testing and reverse engineering.

The guide addresses the need for standardized, technically detailed processes to verify mobile security weaknesses across both Android and iOS platforms. It maps directly to the OWASP Mobile Application Verification Standard (MASVS) and the OWASP Mobile Security Weakness Enumeration (MASWE), creating a structured framework that connects security controls to concrete testing methodologies. The MASTG provides step-by-step technical procedures for static analysis, dynamic analysis, network analysis, runtime analysis, and cryptography testing specific to mobile environments.

Teams conducting mobile security assessments, penetration testers specializing in mobile applications, and organizations building compliance programs around mobile security should adopt this guide. It suits projects requiring alignment with established security standards and those needing detailed, platform-specific testing procedures rather than generic security checklists. The guide is particularly valuable for teams working within regulated industries or those adopting the MASVS framework, as it provides the technical verification methods that correspond to MASVS controls.

The project maintains active engagement with industry through documented adoption by platform providers and standardization bodies. Contributions are actively solicited and the project provides supplementary resources including crackmes for hands-on learning. The guide receives consistent updates to address evolving mobile security threats and testing techniques across both major mobile platforms.