OWASP/owasp-mstg

The OWASP Mobile Application Security Testing Guide (MASTG) is a comprehensive manual for mobile app security testing and reverse engineering. It describes technical processes for verifying the OWASP Mobile Security Weakness Enumeration (MASWE) weaknesses, which are in alignment with the OWASP MASVS.

13,155

stars

8,830

commits

Python

primary language

Sep 4, 2026

updated

mas.owasp.org/
android
android-application
compliancy-checklist
dynamic-analysis
hacking
ios
ios-app
mast
mastg
mobile-app
mobile-security
mstg
network-analysis
pentesting
reverse-engineering
reverse-enginnering
runtime-analysis
static-analysis
testing-cryptography

README

OWASP Mobile Application Security Testing Guide (MASTG)

OWASP Flagship Creative Commons License

Markdown Linter URL Checker

The OWASP Mobile Application Security Testing Guide (MASTG) is a comprehensive manual for mobile app security testing and reverse engineering. It describes technical processes for verifying the OWASP Mobile Security Weakness Enumeration (MASWE) weaknesses, which are in alignment with the controls listed in the OWASP Mobile Application Verification Standard (MASVS).

OWASP MAS: OWASP MASVSOWASP MASWEOWASP MASTG




Trusted by

The OWASP MASVS, MASWE and MASTG are trusted by the following platform providers and standardization, governmental and educational institutions. Learn more.


🥇 MAS Advocates

MAS Advocates are industry adopters of the OWASP MASVS, MASWE and MASTG who have invested a significant and consistent amount of resources to push the project forward by providing consistent high-impact contributions and continuously spreading the word. Learn more.



Contributors

(top 30 of 249)

cpholguera

2,369 commits

commjoen

1,111 commits

muellerberndt

1,007 commits

sushi2k

792 commits

OWASP/owasp-mstg

The OWASP Mobile Application Security Testing Guide (MASTG) is a comprehensive manual for mobile app security testing and reverse engineering. It describes technical processes for verifying the OWASP Mobile Security Weakness Enumeration (MASWE) weaknesses, which are in alignment with the OWASP MASVS.

13,155

stars

8,830

commits

Python

primary language

Sep 4, 2026

updated

mas.owasp.org/
android
android-application
compliancy-checklist
dynamic-analysis
hacking
ios
ios-app
mast
mastg
mobile-app
mobile-security
mstg
network-analysis
pentesting
reverse-engineering
reverse-enginnering
runtime-analysis
static-analysis
testing-cryptography

README

OWASP Mobile Application Security Testing Guide (MASTG)

OWASP Flagship Creative Commons License

Markdown Linter URL Checker

The OWASP Mobile Application Security Testing Guide (MASTG) is a comprehensive manual for mobile app security testing and reverse engineering. It describes technical processes for verifying the OWASP Mobile Security Weakness Enumeration (MASWE) weaknesses, which are in alignment with the controls listed in the OWASP Mobile Application Verification Standard (MASVS).

OWASP MAS: OWASP MASVSOWASP MASWEOWASP MASTG




Trusted by

The OWASP MASVS, MASWE and MASTG are trusted by the following platform providers and standardization, governmental and educational institutions. Learn more.


🥇 MAS Advocates

MAS Advocates are industry adopters of the OWASP MASVS, MASWE and MASTG who have invested a significant and consistent amount of resources to push the project forward by providing consistent high-impact contributions and continuously spreading the word. Learn more.



Contributors

(top 30 of 249)

cpholguera

2,369 commits

commjoen

1,111 commits

muellerberndt

1,007 commits

sushi2k

792 commits

Languages

Python

94.4%

Shell

5.6%