
MASTG-Hacking-Playground
Collection of intentionally insecure iOS and Android apps for learning mobile security testing, reverse engineering, and vulnerability analysis,…

Collection of intentionally insecure iOS and Android apps for learning mobile security testing, reverse engineering, and vulnerability analysis,…

Intentionally vulnerable Android banking app for practicing mobile security testing. Covers OWASP Mobile Top 10 with hardcoded credentials, insecure…

Deliberately insecure OpenWrt-based firmware for hands-on IoT security training. Features vulnerability challenges mapped to the OWASP IoT Top 10 for…

Intentionally vulnerable iOS Swift application for learning mobile app security, exploitation, and defense techniques through hands-on exercises…

Industry-standard baseline for mobile app security and privacy requirements, providing verification criteria for Android and iOS applications used in…

Card game for software teams to identify security requirements in Agile, conventional, and formal development processes. Language, platform, and…

Static code analysis tool for Android apps based on OWASP MASVS, detecting security vulnerabilities in APK files with low false-positive rates and…

Easy to use cryptographic framework for data protection: secure messaging with forward secrecy and secure data storage. Has unified APIs across 14…

Comprehensive OWASP guide for mobile app security testing, reverse engineering, and verifying MASVS/MASWE weaknesses through static, dynamic, and…

OWASP enumeration of common security and privacy weaknesses in mobile applications, serving as a reference bridging the MASVS verification standard…

The OWASP Mobile Application Security Project website is the central hub for industry-leading standards, guides, and resources—helping developers and…

Collection of mobile reverse engineering challenges (UnCrackable Apps) from the OWASP MAS project for learning and practicing mobile app security…

Web and mobile application security training platform

The IoT Security Testing Guide (ISTG) provides a comprehensive methodology for penetration tests in the IoT field, offering flexibility to adapt…

Interactive iOS app security training tool with hands-on lessons covering common vulnerabilities like injection, broken cryptography, data leaks, and…

Community-driven security requirements standard for IoT ecosystems, covering hardware, software, embedded applications, and communication protocols…

Structured OWASP-grounded security playbooks for AI agents. Enables automated code review, dependency CVE scanning, secrets detection, API security…

C-based Android static analysis framework for decompilation, secret detection, endpoint discovery, permission analysis, and native library scanning…