Skip to content

Latest commit

 

History

History
95 lines (71 loc) · 7.5 KB

File metadata and controls

95 lines (71 loc) · 7.5 KB
layout title tags level url type pitch
col-sidebar
OWASP Mobile Security Testing Guide
mstg
4
documentation
The OWASP Mobile Security Testing Guide project consists of a series of documents that establish a security standard for mobile apps and a comprehensive testing guide that covers the processes, techniques, and tools used during a mobile app security test, as well as an exhaustive set of test cases that enables testers to deliver consistent and complete results.

Creative Commons License OWASP Flagship Github stars MSTG Github stars MASVS Twitter Follow MSTG release MASVS release

Our Vision

"Define the industry standard for mobile application security."

We are writing a security standard for mobile apps and a comprehensive testing guide that covers the processes, techniques, and tools used during a mobile app security test, as well as an exhaustive set of test cases that enables testers to deliver consistent and complete results.

Main Deliverables

Mobile Security Testing Guide (MSTG)

The MSTG is a comprehensive manual for mobile app security testing and reverse engineering for iOS and Android mobile security testers with the following content:

  • Mobile platform internals
  • Security testing in the mobile app development lifecycle
  • Basic static and dynamic security testing
  • Mobile app reverse engineering and tampering
  • Assessing software protections
  • Detailed test cases that map to the requirements in the MASVS.

You can contribute and comment in the GitHub Repo. An online book version of the current master branch is available on Gitbook.

Feel free to download the EPUB or Mobi for $0 or contribute any amount you like. All funds raised through sales of this book go directly into the project budget and will be used to for technical editing and designing the book and fund production of future releases.

Mobile App Security Requirements and Verification

The OWASP Mobile Application Security Verification Standard (MASVS) is, as the name implies, a standard for mobile app security. It can be used by mobile software architects and developers seeking to develop secure mobile applications, as well as security testers to ensure completeness and consistency of test results.

You can contribute and comment in the GitHub Repo. An online book version of the current master branch is available on Gitbook.

We now have versions in the following languages:

  • Chinese (traditional)
  • Chinese (simplified)
  • English
  • French
  • German
  • Japanese
  • Korean
  • Russian
  • Spanish

Want to get a PDF/Mobi/EPUB of the standard? Check the release page on Github.

Mobile App Security Checklist

A checklist is available for use in security assessments that is based on the MASVS and MSTG and contains links to the MSTG test case for each requirement. The current release can be found at Github in English, French, Spanish and Japanese.

Presentations

Below you can find a list of upcoming and previous talks: