A structured, hands-on learning repository for Android application security testing, mobile VAPT, reverse engineering, runtime instrumentation, and security research — from fundamentals to professional assessment.
All content in this repository is for educational use only.
Use these techniques exclusively against:
- Intentionally vulnerable applications (listed in this repository)
- Your own applications and devices
- Systems and applications for which you hold explicit written authorization
Unauthorized testing of applications or devices you do not own is illegal in most jurisdictions and violates the terms of service of every major platform. The maintainer accepts no liability for misuse. See SECURITY.md for the full policy.
This is a self-contained learning environment for Android application security testing. It covers the full assessment lifecycle: from setting up a lab and understanding Android internals, through static and dynamic analysis, runtime instrumentation with Frida and Objection, network interception, and producing professional security reports. Content is mapped to the OWASP Mobile Application Security Verification Standard (MASVS v2.1.0) and the OWASP Mobile Application Security Testing Guide (MASTG).
The repository is organized as a curriculum, not just a reference. Each section builds on the previous one, and lab guides provide step-by-step walkthroughs using publicly available, intentionally vulnerable Android applications — no proprietary targets, no black-box surprises. All exploitation techniques, scripts, and bypass methods demonstrated here have a clearly documented scope: intentionally vulnerable apps, your own apps, or authorized engagements.
- Students learning Android security for the first time and wanting a structured path
- Bug bounty hunters targeting Android applications on HackerOne, Bugcrowd, or private programs
- Penetration testers conducting mobile VAPT engagements and needing a systematic methodology reference
- Application security engineers who want to understand the attacker perspective on mobile threats
- Mobile developers who want to understand what testers look for so they can build more secure applications
- CTF competitors working on Android reverse engineering and exploitation challenges
Expand directory tree
android-pentesting/
├── 00-Getting-Started/ Prerequisites, environment checklist, first ADB steps
├── 01-Android-Fundamentals/ Architecture, components, permissions, IPC, storage model
├── 02-Lab-Setup/ Emulator, device root, proxy, tool installation guides
├── 03-Testing-Methodology/ VAPT methodology, scope, evidence standards, triage
├── 04-Static-Analysis/ APK unpacking, decompilation, manifest audit, secrets hunting
├── 05-Dynamic-Analysis/ Logcat, ADB component testing, storage inspection, IPC
├── 06-Vulnerability-Testing/ Per-vulnerability guides mapped to MASVS categories
├── 07-Android-Vulnerable-Apps/ Lab guides for intentionally vulnerable applications
├── 08-Exploitation-Labs/ Pinning bypass, root bypass, WebView, deep link, IPC labs
├── 09-OWASP-Mapping/ MASVS v2.1.0 index, MASTG test mapping, MAS Crackmes
├── 10-Checklists/ Pre-engagement, static, dynamic, network, resilience checklists
├── 11-Cheat-Sheets/ ADB, Frida, Objection, Drozer, Apktool, Burp quick reference
├── 12-Reporting/ Report templates, finding templates, severity guide
├── 13-CTF-and-Practice/ CTF strategy, MAS Crackmes guide, challenge write-up template
├── resources/ Tool download links, version pins, reading list
├── scripts/ Reusable Frida scripts, Python audit tools, ADB enumeration
├── .gitignore
├── CHANGELOG.md
├── CODE_OF_CONDUCT.md
├── CONTRIBUTING.md
├── LICENSE
├── REFERENCES.md
├── README.md
└── SECURITY.md
| Section | Description |
|---|---|
| 00-Getting-Started | Prerequisites checklist and first steps |
| 01-Android-Fundamentals | Android architecture, components, permissions, IPC |
| 02-Lab-Setup | Emulator, device, proxy, and tool setup |
| 03-Testing-Methodology | Full assessment methodology and workflow |
| 04-Static-Analysis | Decompilation, manifest audit, secrets, crypto review |
| 05-Dynamic-Analysis | Logcat, ADB testing, storage, IPC, runtime |
| 06-Vulnerability-Testing | Per-vulnerability guides with MASVS mapping |
| 07-Android-Vulnerable-Apps | Lab guides for intentionally vulnerable apps |
| 08-Exploitation-Labs | Pinning bypass, root bypass, WebView, deep link labs |
| 09-OWASP-Mapping | MASVS v2.1.0 index and MASTG test mapping |
| 10-Checklists | Assessment checklists for every phase |
| 11-Cheat-Sheets | Quick-reference command sheets for all major tools |
| 12-Reporting | Report and finding templates, evidence guide |
| 13-CTF-and-Practice | CTF strategy and practice app index |
| resources/ | Tool links, version pins, reading list |
| scripts/ | Reusable Frida, Python, and shell scripts |
Work through the sections in order. Each level assumes completion of the previous one.
Level 1 — Prerequisites
Linux/macOS basics · Python basics · Networking fundamentals
· What is an APK · Java/Kotlin basics (read-level is enough)
→ 00-Getting-Started/
Level 2 — Android Fundamentals
Android architecture · Application components · Permissions model
· AndroidManifest.xml · Intents and IPC · Storage model
→ 01-Android-Fundamentals/
Level 3 — Basic Tooling
ADB setup · Emulator or rooted device · Burp proxy + CA cert
· Install Frida server · First Objection session · MobSF scan
→ 02-Lab-Setup/
Level 4 — Static Analysis
APK unpacking · JADX decompilation · Manifest audit
· Hardcoded secrets · Crypto review · MobSF automated scan
→ 04-Static-Analysis/
Level 5 — Dynamic Analysis
Logcat monitoring · ADB component invocation · Storage inspection
· Content provider extraction · Network interception
→ 05-Dynamic-Analysis/ · 06-Vulnerability-Testing/
Level 6 — Runtime Instrumentation
Frida basics · SSL pinning bypass · Root detection bypass
· Objection exploration · Custom hook writing
→ 08-Exploitation-Labs/ · scripts/
Level 7 — Professional Assessment
Full methodology · MASVS mapping · Evidence collection
· Severity classification · Professional report writing
→ 03-Testing-Methodology/ · 09-OWASP-Mapping/ · 12-Reporting/
┌─────────────┐
│ Recon │ App store metadata, permissions, app version, backend URLs
└──────┬──────┘
│
┌──────▼──────┐
│ Static │ APK unpack → decompile → manifest audit → secrets → crypto → deps
└──────┬──────┘
│
┌──────▼──────┐
│ Dynamic │ Logcat → storage → IPC → exported components → backups
└──────┬──────┘
│
┌──────▼──────┐
│ Network │ Proxy setup → cleartext → cert validation → pinning bypass
└──────┬──────┘
│
┌──────▼──────┐
│ Runtime │ Frida/Objection → hook crypto → bypass auth → trace calls
└──────┬──────┘
│
┌──────▼──────┐
│ RE │ Smali analysis → patch → repack → sign → deeper logic tracing
└──────┬──────┘
│
┌──────▼──────┐
│ Report │ CVSS scoring → MASVS mapping → findings → recommendations
└─────────────┘
Full methodology documentation: 03-Testing-Methodology/
Coverage is organized by MASVS v2.1.0 category. Each category links to the relevant section.
| MASVS Category | Description | Lab Section |
|---|---|---|
| MASVS-STORAGE | Sensitive data stored insecurely on-device: shared preferences, SQLite, external storage, app backups | 06-Vulnerability-Testing/ |
| MASVS-CRYPTO | Weak or misused cryptography: hardcoded keys, weak algorithms, ECB mode, improper random | 06-Vulnerability-Testing/ |
| MASVS-AUTH | Broken authentication and authorization: session management, token storage, biometric bypass | 06-Vulnerability-Testing/ |
| MASVS-NETWORK | Insecure network communication: cleartext, custom TrustManagers, hostname verification, pinning | 06-Vulnerability-Testing/ |
| MASVS-PLATFORM | Android platform misuse: exported components, intent injection, deep links, WebView, JavaScript interfaces | 06-Vulnerability-Testing/ |
| MASVS-CODE | Code quality issues: debuggable builds, memory corruption, injection, third-party library vulnerabilities | 06-Vulnerability-Testing/ |
| MASVS-RESILIENCE | Anti-tampering and anti-analysis: root detection, emulator detection, certificate pinning, anti-debugging | 08-Exploitation-Labs/ |
| MASVS-PRIVACY | Privacy controls: PII in logs, unnecessary permissions, sensor/location data leakage | 06-Vulnerability-Testing/ |
Full MASVS v2.1.0 mapping: 09-OWASP-Mapping/ · Official spec: https://mas.owasp.org/MASVS/
| Tool | Purpose | Guide |
|---|---|---|
| ADB | Device communication, component testing, file system access | 02-Lab-Setup/ · 11-Cheat-Sheets/ |
| MobSF | Automated static and dynamic analysis | 04-Static-Analysis/ · 02-Lab-Setup/ |
| JADX | Java/Kotlin decompilation from DEX | 04-Static-Analysis/ |
| Apktool | APK unpacking, smali disassembly, repacking | 04-Static-Analysis/ |
| dex2jar + JD-GUI | DEX to JAR conversion and Java decompilation | 04-Static-Analysis/ |
| Burp Suite Community | HTTP(S) interception and analysis | 02-Lab-Setup/ · 11-Cheat-Sheets/ |
| Frida | Dynamic instrumentation, hooking, bypass | 08-Exploitation-Labs/ · scripts/ |
| Objection | Frida-based runtime exploration toolkit | 08-Exploitation-Labs/ · 11-Cheat-Sheets/ |
| Drozer | IPC, component, and content provider testing | 05-Dynamic-Analysis/ · 11-Cheat-Sheets/ |
| Magisk | Device root and DenyList for bypass testing | 02-Lab-Setup/ |
| Uber APK Signer | Re-signing patched APKs | 04-Static-Analysis/ |
| scrcpy | Screen mirroring and device control | 02-Lab-Setup/ |
All exploitation labs target one or more of these applications. They are vulnerable by design.
| Application | Primary Focus | Difficulty | Source |
|---|---|---|---|
| InsecureBankv2 | Broad: auth, storage, crypto, network, IPC | Beginner–Intermediate | GitHub |
| DIVA | Insecure logging, storage, input validation, access control | Beginner | GitHub |
| AndroGoat | OWASP Mobile Top 10 | Beginner–Intermediate | GitHub |
| InsecureShop | Auth bypass, deep links, WebView | Intermediate | GitHub |
| OVAA | Intent hijacking, path traversal, fragment injection | Advanced | GitHub |
| AllSafe | Broad vulnerability set; tool practice | Beginner–Intermediate | GitHub |
| BugBazaar | Marketplace scenario; broad OWASP coverage | Intermediate | GitHub |
| DodoVulnerableBank | Banking scenario; includes backend server | Intermediate | GitHub |
| DVHMA | Hybrid/WebView; JavaScript interface attacks | Intermediate | GitHub |
| OWASP MAS Crackmes | Reverse engineering, instrumentation, bypass | Intermediate–Advanced | mas.owasp.org |
Full app index and lab guides: 07-Android-Vulnerable-Apps/
Ready-to-use assessment checklists and command references:
- 10-Checklists/ — Pre-engagement, static, dynamic, network, resilience, privacy, and full MASVS v2.1.0 checklists
- 11-Cheat-Sheets/ — ADB, Frida, Objection, Drozer, Apktool, MobSF, Logcat, Burp Suite + Android
This repository uses OWASP MASVS v2.1.0 as the primary vulnerability classification framework and references MASTG test cases throughout the lab guides.
- MASVS defines what to verify (security requirements organized into eight categories)
- MASTG defines how to test (specific test cases, tools, and techniques for each requirement)
The full mapping table — MASVS control → MASTG test case → local lab section — is in 09-OWASP-Mapping/.
Official resources: MASVS v2.1.0 · MASTG
Professional assessment reporting templates and guidance:
- Report structure template (executive summary, scope, findings, recommendations)
- Finding template with CVSS v3.1 scoring, MASVS reference, reproduction steps, and evidence fields
- Severity classification guide with mobile-context examples
- Evidence organization guide
See 12-Reporting/.
Contributions are welcome. Please read CONTRIBUTING.md before opening an issue or pull request.
Key points:
- All exploitation labs must use intentionally vulnerable apps
- Do not commit APK files, real credentials, or proprietary content
- Commands should be tested against the stated Android version and tool version
- Follow the Conventional Commits style for commit messages
External tools, standards, and resources referenced throughout this repository are listed in REFERENCES.md, organized by:
- OWASP Mobile Security (MASVS, MASTG, MAS Crackmes)
- Android Official Documentation
- Tools (static analysis, dynamic analysis, instrumentation, proxy, root)
- Intentionally Vulnerable Applications
- Books and Guides
- Blogs and Research Sources
This repository is licensed under the MIT License.
Copyright (c) 2026 VoidCatalyst
The MIT License applies to the original content in this repository: guides, scripts, templates, and documentation. It does not grant rights to third-party tools, applications, or content referenced or linked herein — those are subject to their own respective licenses.