测试工具

关于下方列出的工具

OWASP MASTG 包含许多用于执行测试用例的工具,使您能够执行静态分析、动态分析、网络拦截等。这些工具旨在帮助您进行自己的评估,而不是提供关于应用程序安全状态的最终结果。仔细审查这些工具的输出非常重要,因为它可能包含误报和漏报。

这些工具已在添加到列表时进行测试,但兼容性可能因您的操作系统版本、您正在测试的设备或您是否使用已root或越狱的设备而异。工具的功能也可能受到root/越狱方法或工具本身特定版本的影响。OWASP MASTG 不保证工具的功能。如果您遇到问题,请尝试在线搜索解决方案或联系工具所有者(例如,通过 GitHub Issues)。

在通过 GitHub Issues/Pull Requests 提出新工具之前,请查看我们的贡献指南

ID 名称 平台
MASTG-TOOL-0112 pidcat platform:android
MASTG-TOOL-0002 MobSF for Android platform:android
MASTG-TOOL-0125 Apkleaks platform:android
MASTG-TOOL-0028 radare2 for Android platform:android
MASTG-TOOL-0116 Blutter platform:android
MASTG-TOOL-0022 Proguard platform:android
MASTG-TOOL-0024 Scrcpy platform:android
MASTG-TOOL-0120 ProxyDroid platform:android
MASTG-TOOL-0005 Android NDK platform:android
MASTG-TOOL-0018 jadx platform:android
MASTG-TOOL-0003 nm - Android platform:android
MASTG-TOOL-0016 gplaycli platform:android
MASTG-TOOL-0009 APKiD platform:android
MASTG-TOOL-0017 House platform:android
MASTG-TOOL-0011 Apktool platform:android
MASTG-TOOL-0001 Frida for Android platform:android
MASTG-TOOL-0004 adb platform:android
MASTG-TOOL-0124 aapt2 platform:android
MASTG-TOOL-0012 apkx platform:android
MASTG-TOOL-0019 jdb platform:android
MASTG-TOOL-0099 FlowDroid platform:android
MASTG-TOOL-0103 uber-apk-signer platform:android
MASTG-TOOL-0020 JustTrustMe platform:android
MASTG-TOOL-0006 Android SDK platform:android
MASTG-TOOL-0130 blint platform:android
MASTG-TOOL-0021 Magisk platform:android
MASTG-TOOL-0023 RootCloak Plus platform:android
MASTG-TOOL-0025 SSLUnpinning platform:android
MASTG-TOOL-0107 JNITrace platform:android
MASTG-TOOL-0010 APKLab platform:android
MASTG-TOOL-0007 Android Studio platform:android
MASTG-TOOL-0030 Angr platform:android
MASTG-TOOL-0026 Termux platform:android
MASTG-TOOL-0008 Android-SSL-TrustKiller platform:android
MASTG-TOOL-0029 objection for Android platform:android
MASTG-TOOL-0140 frida-multiple-unpinning platform:android
MASTG-TOOL-0123 apksigner platform:android
MASTG-TOOL-0027 Xposed platform:android
MASTG-TOOL-0015 drozer platform:android
MASTG-TOOL-0013 Busybox platform:android
MASTG-TOOL-0014 Bytecode Viewer platform:android
MASTG-TOOL-0108 Corellium platform:generic
MASTG-TOOL-0101 disable-flutter-tls-verification platform:generic
MASTG-TOOL-0034 LIEF platform:generic
MASTG-TOOL-0037 RMS Runtime Mobile Security platform:generic
MASTG-TOOL-0133 Visual Studio Code (vscode) platform:generic
MASTG-TOOL-0104 hermes-dec platform:generic
MASTG-TOOL-0038 objection platform:generic
MASTG-TOOL-0032 Frida CodeShare platform:generic
MASTG-TOOL-0132 dependency-track platform:generic
MASTG-TOOL-0110 semgrep platform:generic
MASTG-TOOL-0036 r2frida platform:generic
MASTG-TOOL-0031 Frida platform:generic
MASTG-TOOL-0098 iaito platform:generic
MASTG-TOOL-0100 reFlutter platform:generic
MASTG-TOOL-0134 cdxgen platform:generic
MASTG-TOOL-0131 dependency-check platform:generic
MASTG-TOOL-0106 Fridump platform:generic
MASTG-TOOL-0035 MobSF platform:generic
MASTG-TOOL-0129 rabin2 platform:generic
MASTG-TOOL-0033 Ghidra platform:generic
MASTG-TOOL-0039 Frida for iOS platform:ios
MASTG-TOOL-0060 otool platform:ios
MASTG-TOOL-0061 Grapefruit platform:ios
MASTG-TOOL-0127 AppSync Unified platform:ios
MASTG-TOOL-0126 libimobiledevice suite platform:ios
MASTG-TOOL-0044 class-dump-z platform:ios
MASTG-TOOL-0056 Keychain-Dumper platform:ios
MASTG-TOOL-0049 Frida-cycript platform:ios
MASTG-TOOL-0135 PlistBuddy platform:ios
MASTG-TOOL-0047 Cydia platform:ios
MASTG-TOOL-0045 class-dump-dyld platform:ios
MASTG-TOOL-0065 simctl platform:ios
MASTG-TOOL-0102 ios-app-signer platform:ios
MASTG-TOOL-0062 Plutil platform:ios
MASTG-TOOL-0069 Usbmuxd platform:ios
MASTG-TOOL-0053 iOSbackup platform:ios
MASTG-TOOL-0042 BinaryCookieReader platform:ios
MASTG-TOOL-0114 codesign platform:ios
MASTG-TOOL-0055 iproxy platform:ios
MASTG-TOOL-0050 Frida-ios-dump platform:ios
MASTG-TOOL-0074 objection for iOS platform:ios
MASTG-TOOL-0054 ios-deploy platform:ios
MASTG-TOOL-0040 MobSF for iOS platform:ios
MASTG-TOOL-0058 MachoOView platform:ios
MASTG-TOOL-0046 Cycript platform:ios
MASTG-TOOL-0051 gdb platform:ios
MASTG-TOOL-0073 radare2 for iOS platform:ios
MASTG-TOOL-0072 xcrun platform:ios
MASTG-TOOL-0136 plistlib platform:ios
MASTG-TOOL-0137 GlobalWebInspect platform:ios
MASTG-TOOL-0070 Xcode platform:ios
MASTG-TOOL-0122 c++filt platform:ios
MASTG-TOOL-0064 Sileo platform:ios
MASTG-TOOL-0066 SSL Kill Switch 3 platform:ios
MASTG-TOOL-0139 ElleKit platform:ios
MASTG-TOOL-0138 ipainstaller platform:ios
MASTG-TOOL-0048 dsdump platform:ios
MASTG-TOOL-0105 ipsw platform:ios
MASTG-TOOL-0121 objdump - iOS platform:ios
MASTG-TOOL-0142 Choicy platform:ios
MASTG-TOOL-0071 Xcode Command Line Tools platform:ios
MASTG-TOOL-0111 ldid platform:ios
MASTG-TOOL-0059 optool platform:ios
MASTG-TOOL-0043 class-dump platform:ios
MASTG-TOOL-0141 IOSSecuritySuite platform:ios
MASTG-TOOL-0057 lldb platform:ios
MASTG-TOOL-0068 SwiftShield platform:ios
MASTG-TOOL-0128 Filza platform:ios
MASTG-TOOL-0067 swift-demangle platform:ios
MASTG-TOOL-0118 Sideloadly platform:ios
MASTG-TOOL-0041 nm - iOS platform:ios
MASTG-TOOL-0063 security platform:ios
MASTG-TOOL-0117 fastlane platform:ios
MASTG-TOOL-0080 tcpdump platform:network
MASTG-TOOL-0143 badssl platform:network
MASTG-TOOL-0075 Android tcpdump platform:network
MASTG-TOOL-0079 ZAP platform:network
MASTG-TOOL-0097 mitmproxy platform:network
MASTG-TOOL-0077 Burp Suite platform:network
MASTG-TOOL-0076 bettercap platform:network
MASTG-TOOL-0115 HTTP Toolkit platform:network
MASTG-TOOL-0109 Nope-Proxy platform:network
MASTG-TOOL-0078 MITM Relay platform:network
MASTG-TOOL-0081 Wireshark platform:network