Skip to content

Latest commit

 

History

2 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

Android Penetration Testing Lab

License: MIT OWASP MASVS Platform Contributions Welcome

A structured, hands-on learning repository for Android application security testing, mobile VAPT, reverse engineering, runtime instrumentation, and security research — from fundamentals to professional assessment.


⚠️ Legal & Ethics

All content in this repository is for educational use only.

Use these techniques exclusively against:

  • Intentionally vulnerable applications (listed in this repository)
  • Your own applications and devices
  • Systems and applications for which you hold explicit written authorization

Unauthorized testing of applications or devices you do not own is illegal in most jurisdictions and violates the terms of service of every major platform. The maintainer accepts no liability for misuse. See SECURITY.md for the full policy.


What This Repository Is

This is a self-contained learning environment for Android application security testing. It covers the full assessment lifecycle: from setting up a lab and understanding Android internals, through static and dynamic analysis, runtime instrumentation with Frida and Objection, network interception, and producing professional security reports. Content is mapped to the OWASP Mobile Application Security Verification Standard (MASVS v2.1.0) and the OWASP Mobile Application Security Testing Guide (MASTG).

The repository is organized as a curriculum, not just a reference. Each section builds on the previous one, and lab guides provide step-by-step walkthroughs using publicly available, intentionally vulnerable Android applications — no proprietary targets, no black-box surprises. All exploitation techniques, scripts, and bypass methods demonstrated here have a clearly documented scope: intentionally vulnerable apps, your own apps, or authorized engagements.


Who Is This For

  • Students learning Android security for the first time and wanting a structured path
  • Bug bounty hunters targeting Android applications on HackerOne, Bugcrowd, or private programs
  • Penetration testers conducting mobile VAPT engagements and needing a systematic methodology reference
  • Application security engineers who want to understand the attacker perspective on mobile threats
  • Mobile developers who want to understand what testers look for so they can build more secure applications
  • CTF competitors working on Android reverse engineering and exploitation challenges

Repository Structure

Expand directory tree
android-pentesting/
├── 00-Getting-Started/          Prerequisites, environment checklist, first ADB steps
├── 01-Android-Fundamentals/     Architecture, components, permissions, IPC, storage model
├── 02-Lab-Setup/                Emulator, device root, proxy, tool installation guides
├── 03-Testing-Methodology/      VAPT methodology, scope, evidence standards, triage
├── 04-Static-Analysis/          APK unpacking, decompilation, manifest audit, secrets hunting
├── 05-Dynamic-Analysis/         Logcat, ADB component testing, storage inspection, IPC
├── 06-Vulnerability-Testing/    Per-vulnerability guides mapped to MASVS categories
├── 07-Android-Vulnerable-Apps/  Lab guides for intentionally vulnerable applications
├── 08-Exploitation-Labs/        Pinning bypass, root bypass, WebView, deep link, IPC labs
├── 09-OWASP-Mapping/            MASVS v2.1.0 index, MASTG test mapping, MAS Crackmes
├── 10-Checklists/               Pre-engagement, static, dynamic, network, resilience checklists
├── 11-Cheat-Sheets/             ADB, Frida, Objection, Drozer, Apktool, Burp quick reference
├── 12-Reporting/                Report templates, finding templates, severity guide
├── 13-CTF-and-Practice/         CTF strategy, MAS Crackmes guide, challenge write-up template
├── resources/                   Tool download links, version pins, reading list
├── scripts/                     Reusable Frida scripts, Python audit tools, ADB enumeration
├── .gitignore
├── CHANGELOG.md
├── CODE_OF_CONDUCT.md
├── CONTRIBUTING.md
├── LICENSE
├── REFERENCES.md
├── README.md
└── SECURITY.md
Section Description
00-Getting-Started Prerequisites checklist and first steps
01-Android-Fundamentals Android architecture, components, permissions, IPC
02-Lab-Setup Emulator, device, proxy, and tool setup
03-Testing-Methodology Full assessment methodology and workflow
04-Static-Analysis Decompilation, manifest audit, secrets, crypto review
05-Dynamic-Analysis Logcat, ADB testing, storage, IPC, runtime
06-Vulnerability-Testing Per-vulnerability guides with MASVS mapping
07-Android-Vulnerable-Apps Lab guides for intentionally vulnerable apps
08-Exploitation-Labs Pinning bypass, root bypass, WebView, deep link labs
09-OWASP-Mapping MASVS v2.1.0 index and MASTG test mapping
10-Checklists Assessment checklists for every phase
11-Cheat-Sheets Quick-reference command sheets for all major tools
12-Reporting Report and finding templates, evidence guide
13-CTF-and-Practice CTF strategy and practice app index
resources/ Tool links, version pins, reading list
scripts/ Reusable Frida, Python, and shell scripts

Learning Roadmap

Work through the sections in order. Each level assumes completion of the previous one.

Level 1 — Prerequisites
  Linux/macOS basics · Python basics · Networking fundamentals
  · What is an APK · Java/Kotlin basics (read-level is enough)
  → 00-Getting-Started/

Level 2 — Android Fundamentals
  Android architecture · Application components · Permissions model
  · AndroidManifest.xml · Intents and IPC · Storage model
  → 01-Android-Fundamentals/

Level 3 — Basic Tooling
  ADB setup · Emulator or rooted device · Burp proxy + CA cert
  · Install Frida server · First Objection session · MobSF scan
  → 02-Lab-Setup/

Level 4 — Static Analysis
  APK unpacking · JADX decompilation · Manifest audit
  · Hardcoded secrets · Crypto review · MobSF automated scan
  → 04-Static-Analysis/

Level 5 — Dynamic Analysis
  Logcat monitoring · ADB component invocation · Storage inspection
  · Content provider extraction · Network interception
  → 05-Dynamic-Analysis/ · 06-Vulnerability-Testing/

Level 6 — Runtime Instrumentation
  Frida basics · SSL pinning bypass · Root detection bypass
  · Objection exploration · Custom hook writing
  → 08-Exploitation-Labs/ · scripts/

Level 7 — Professional Assessment
  Full methodology · MASVS mapping · Evidence collection
  · Severity classification · Professional report writing
  → 03-Testing-Methodology/ · 09-OWASP-Mapping/ · 12-Reporting/

Methodology Overview

┌─────────────┐
│    Recon    │  App store metadata, permissions, app version, backend URLs
└──────┬──────┘
       │
┌──────▼──────┐
│   Static    │  APK unpack → decompile → manifest audit → secrets → crypto → deps
└──────┬──────┘
       │
┌──────▼──────┐
│   Dynamic   │  Logcat → storage → IPC → exported components → backups
└──────┬──────┘
       │
┌──────▼──────┐
│   Network   │  Proxy setup → cleartext → cert validation → pinning bypass
└──────┬──────┘
       │
┌──────▼──────┐
│   Runtime   │  Frida/Objection → hook crypto → bypass auth → trace calls
└──────┬──────┘
       │
┌──────▼──────┐
│     RE      │  Smali analysis → patch → repack → sign → deeper logic tracing
└──────┬──────┘
       │
┌──────▼──────┐
│   Report    │  CVSS scoring → MASVS mapping → findings → recommendations
└─────────────┘

Full methodology documentation: 03-Testing-Methodology/


Vulnerability Coverage

Coverage is organized by MASVS v2.1.0 category. Each category links to the relevant section.

MASVS Category Description Lab Section
MASVS-STORAGE Sensitive data stored insecurely on-device: shared preferences, SQLite, external storage, app backups 06-Vulnerability-Testing/
MASVS-CRYPTO Weak or misused cryptography: hardcoded keys, weak algorithms, ECB mode, improper random 06-Vulnerability-Testing/
MASVS-AUTH Broken authentication and authorization: session management, token storage, biometric bypass 06-Vulnerability-Testing/
MASVS-NETWORK Insecure network communication: cleartext, custom TrustManagers, hostname verification, pinning 06-Vulnerability-Testing/
MASVS-PLATFORM Android platform misuse: exported components, intent injection, deep links, WebView, JavaScript interfaces 06-Vulnerability-Testing/
MASVS-CODE Code quality issues: debuggable builds, memory corruption, injection, third-party library vulnerabilities 06-Vulnerability-Testing/
MASVS-RESILIENCE Anti-tampering and anti-analysis: root detection, emulator detection, certificate pinning, anti-debugging 08-Exploitation-Labs/
MASVS-PRIVACY Privacy controls: PII in logs, unnecessary permissions, sensor/location data leakage 06-Vulnerability-Testing/

Full MASVS v2.1.0 mapping: 09-OWASP-Mapping/ · Official spec: https://mas.owasp.org/MASVS/


Tools Covered

Tool Purpose Guide
ADB Device communication, component testing, file system access 02-Lab-Setup/ · 11-Cheat-Sheets/
MobSF Automated static and dynamic analysis 04-Static-Analysis/ · 02-Lab-Setup/
JADX Java/Kotlin decompilation from DEX 04-Static-Analysis/
Apktool APK unpacking, smali disassembly, repacking 04-Static-Analysis/
dex2jar + JD-GUI DEX to JAR conversion and Java decompilation 04-Static-Analysis/
Burp Suite Community HTTP(S) interception and analysis 02-Lab-Setup/ · 11-Cheat-Sheets/
Frida Dynamic instrumentation, hooking, bypass 08-Exploitation-Labs/ · scripts/
Objection Frida-based runtime exploration toolkit 08-Exploitation-Labs/ · 11-Cheat-Sheets/
Drozer IPC, component, and content provider testing 05-Dynamic-Analysis/ · 11-Cheat-Sheets/
Magisk Device root and DenyList for bypass testing 02-Lab-Setup/
Uber APK Signer Re-signing patched APKs 04-Static-Analysis/
scrcpy Screen mirroring and device control 02-Lab-Setup/

Intentionally Vulnerable Apps

All exploitation labs target one or more of these applications. They are vulnerable by design.

Application Primary Focus Difficulty Source
InsecureBankv2 Broad: auth, storage, crypto, network, IPC Beginner–Intermediate GitHub
DIVA Insecure logging, storage, input validation, access control Beginner GitHub
AndroGoat OWASP Mobile Top 10 Beginner–Intermediate GitHub
InsecureShop Auth bypass, deep links, WebView Intermediate GitHub
OVAA Intent hijacking, path traversal, fragment injection Advanced GitHub
AllSafe Broad vulnerability set; tool practice Beginner–Intermediate GitHub
BugBazaar Marketplace scenario; broad OWASP coverage Intermediate GitHub
DodoVulnerableBank Banking scenario; includes backend server Intermediate GitHub
DVHMA Hybrid/WebView; JavaScript interface attacks Intermediate GitHub
OWASP MAS Crackmes Reverse engineering, instrumentation, bypass Intermediate–Advanced mas.owasp.org

Full app index and lab guides: 07-Android-Vulnerable-Apps/


Checklists & Cheat Sheets

Ready-to-use assessment checklists and command references:

  • 10-Checklists/ — Pre-engagement, static, dynamic, network, resilience, privacy, and full MASVS v2.1.0 checklists
  • 11-Cheat-Sheets/ — ADB, Frida, Objection, Drozer, Apktool, MobSF, Logcat, Burp Suite + Android

OWASP Mapping

This repository uses OWASP MASVS v2.1.0 as the primary vulnerability classification framework and references MASTG test cases throughout the lab guides.

  • MASVS defines what to verify (security requirements organized into eight categories)
  • MASTG defines how to test (specific test cases, tools, and techniques for each requirement)

The full mapping table — MASVS control → MASTG test case → local lab section — is in 09-OWASP-Mapping/.

Official resources: MASVS v2.1.0 · MASTG


Reporting

Professional assessment reporting templates and guidance:

  • Report structure template (executive summary, scope, findings, recommendations)
  • Finding template with CVSS v3.1 scoring, MASVS reference, reproduction steps, and evidence fields
  • Severity classification guide with mobile-context examples
  • Evidence organization guide

See 12-Reporting/.


Contributing

Contributions are welcome. Please read CONTRIBUTING.md before opening an issue or pull request.

Key points:

  • All exploitation labs must use intentionally vulnerable apps
  • Do not commit APK files, real credentials, or proprietary content
  • Commands should be tested against the stated Android version and tool version
  • Follow the Conventional Commits style for commit messages

Attribution & References

External tools, standards, and resources referenced throughout this repository are listed in REFERENCES.md, organized by:

  • OWASP Mobile Security (MASVS, MASTG, MAS Crackmes)
  • Android Official Documentation
  • Tools (static analysis, dynamic analysis, instrumentation, proxy, root)
  • Intentionally Vulnerable Applications
  • Books and Guides
  • Blogs and Research Sources

License

This repository is licensed under the MIT License.

Copyright (c) 2026 VoidCatalyst

The MIT License applies to the original content in this repository: guides, scripts, templates, and documentation. It does not grant rights to third-party tools, applications, or content referenced or linked herein — those are subject to their own respective licenses.

About

A complete Android penetration testing learning repository — OWASP MASVS v2.1.0 mapped, 12 exploitation labs, cheat sheets, checklists, and reporting templates.

Topics

Resources

Code of conduct

Contributing

Security policy

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages