# tanprathan/MobileApp-Pentest-Cheatsheet

The Mobile App Pentest cheat sheet was created to provide concise collection of high value information on specific mobile application penetration testing topics.

Repository: https://github.com/tanprathan/MobileApp-Pentest-Cheatsheet
Canonical: https://ross.abutalabs.com/products/mobileapp-pentest-cheatsheet
License Family: other
Topics: mobile-app, pentesting, android-application, ios-app, runtime-analysis, network-analysis, static-analysis, reverse-engineers, dynamic-analysis
Last push: 2024-02-08T14:18:04+00:00

## Health v2 (maintenance only)
Score: 32/100 (v2, computed 2026-09-02T17:46:02.011165+00:00)
- activity 0, release rhythm 35, longevity 100
- inputs: {"age_days": 3989, "days_push": 937, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: no_releases, no_license
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 5257, forks 1330 (observed 2026-08-28T04:09:13.788546+00:00)

## What it is
A curated cheat sheet and checklist of high-value tools and techniques for mobile application penetration testing, mapped to the OWASP Mobile Risk Top 10. It covers Android and iOS topics including static and dynamic analysis, reverse engineering, network analysis, and bypassing root detection and SSL pinning.

## Use cases
- find tools for android app penetration testing
- learn how to do ios app security assessment
- bypass ssl pinning in mobile apps
- set up a mobile pentesting lab
- checklist for owasp mobile top 10 testing
- reverse engineer an android apk
- analyze ios app runtime with frida

## When to choose
- you need a quick reference of mobile pentesting tools and techniques
- you are building a mobile app security assessment checklist
- you want curated links for android or ios security testing distributions and frameworks

## When to avoid
- you need an actual testing tool rather than a list of links
- you need automated mobile security scanning (use MobSF instead)
- you need up-to-date tooling with active maintenance guarantees

## Facets
- artifact type: learning-resource
- maturity: maintenance
- function: penetration-testing, security, reverse-engineering, developer-tools
- domain: security, penetration-testing, mobile-development, android-tools, apple-ecosystem
- platform: cross-platform
- tags: cheatsheet, mobile-security, owasp-mobile, android-pentesting, ios-pentesting, awesome-list, static-analysis, dynamic-analysis, android, ios

## Member repositories
- tanprathan/MobileApp-Pentest-Cheatsheet (main) score 32

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:09:13.788546+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-29T17:59:31.975471+00:00, confidence not recorded.
  - readme: https://github.com/tanprathan/MobileApp-Pentest-Cheatsheet (fetched 2026-08-28T04:09:13.788546+00:00, sha 1ac2d4c2b3f7)
- Data as of 2026-08-30T08:39:29.467469+00:00.
