Mobile security is an intersection of AppSec, reverse engineering, platform-specific knowledge (Android/iOS) and network/transport security. The current authoritative standards are the OWASP MASVS (Mobile Application Security Verification Standard) and the OWASP MASTG (Mobile Application Security Testing Guide), which replaced the older MSTG in 2023.
- OWASP MASTG - Mobile Application Security Testing Guide (free) - The de-facto reference, replaces MSTG.
- OWASP MASVS - Mobile AppSec Verification Standard (free) - Requirement standard paired with MASTG.
- The Mobile Application Hacker's Handbook by Dominic Chell et al. - Classic, slightly dated but concepts are evergreen.
- Android Security Internals by Nikolay Elenkov (No Starch) - Deep internals, still highly regarded.
- iOS Application Security by David Thiel (No Starch) - Focused on iOS AppSec.
- Android Hacker's Handbook by Joshua J. Drake et al. - Lower-level Android exploitation.
- Hacking iOS Applications by Corellium / contributors - Vendor-led but good technical content.
- OWASP MAS Project videos
- Android App Reverse Engineering 101 by Maddie Stone
- iOS pentesting with Frida - playlist
- Mobile Hacking - Hextree.io by LiveOverflow / Fabian Faessler - Excellent modern Android RE content.
- DEF CON / Black Hat mobile security archives
- OffensiveCon - Android & iOS internals
- OWASP MAS training materials (free)
- Android App Reverse Engineering 101 (free) by Maddie Stone
- Hextree.io - Android Hacking courses - High-quality, recently refreshed.
- 8ksec - Mobile Security Bootcamps - Paid, practical Android/iOS.
- SANS SEC575: iOS and Android Application Security - Paid, industry standard.
- INE - Mobile Application Security and Penetration Testing
- TCM Security - Mobile Application Penetration Testing
- Practical DevSecOps - Certified Mobile Security Expert - (if available in their catalog).
- OWASP MASTG Crackmes / UnCrackable apps - Free Android/iOS crackmes aligned to MASTG.
- InsecureShop (vulnerable Android app)
- DIVA (Damn Insecure and Vulnerable App) - Classic Android training app.
- InjuredAndroid by B3nac
- Allsafe by t0thkr1s - Modern intentionally vulnerable Android app.
- DVIA-v2 (Damn Vulnerable iOS App) - Primary iOS training target.
- iGoat-Swift - OWASP iOS goat project.
- HackTheBox - Mobile challenges
- Root-Me - Mobile challenges
- pwnable.kr / pwnable.xyz - Android/ARM challenges
- MobSF (Mobile Security Framework) - The all-in-one OSS analyzer for APK/IPA.
- jadx - Decompile DEX to Java source.
- apktool - Decode/rebuild APK resources.
- Ghidra - SRE for native libraries (NDK, dylib).
- radare2 / Cutter - Reverse engineering framework.
- Hopper / IDA Pro - Commercial RE tools.
- Semgrep mobile rule packs - SAST for Android/iOS source.
- QARK by LinkedIn - Quick Android Review Kit (note: slower development).
- Frida - Dynamic instrumentation for Android/iOS/macOS/Linux/Windows. Essential.
- Objection - Runtime mobile exploration built on Frida.
- Drozer by WithSecure - Android attack surface analysis.
- Medusa - Framework of modular Frida scripts.
- RMS - Runtime Mobile Security
- Burp Suite / mitmproxy / Charles Proxy
- HTTP Toolkit - Easy mobile HTTPS interception.
- Proxyman
- Android Studio AVD + rooted emulator
- Genymotion
- Corellium - Virtual iOS / Android devices (paid).
- checkra1n / palera1n - iOS jailbreaks for testing.
- Magisk - Android rooting & module system.
- SANS GMOB - GIAC Mobile Device Security Analyst - Industry standard.
- eMAPT by INE/eLearnSecurity - Practical, affordable.
- OSMR by Offensive Security - Advanced macOS/iOS exploitation (not pure mobile but relevant).
- OSDA / Offensive Mobile certifications (various)
- 8kSec's Certified Mobile Security Testing Professional
- OWASP MAS project home
- OWASP Mobile Top 10 (2024)
- Google Project Zero research (Android, iOS)
- Maddie Stone - in-the-wild 0-days tracker
- NCC Group research - mobile
- 8kSec blog
- Frida CodeShare - Shared Frida scripts.
- HackTricks - Android/iOS pentesting
- Dana Wang / HexRays blog - iOS internals
- Android Security Bulletins
- Apple Security Releases
- NVISO labs blog - mobile RE
- r2frida - radare2 + Frida integration.
- NowSecure research
