This is the official GitHub Repository of the OWASP Mobile Application Security Testing Guide (MASTG). The MASTG is a comprehensive manual for mobile app security testing and reverse engineering. It describes technical processes for verifying the controls listed in the OWASP Mobile Application Verification Standard (MASVS).
![](/OWASP/owasp-mastg/raw/master/Document/Images/open_website.png)
- ⬇️ Download the latest PDF
- ✅ Get the latest Mobile App Security Checklists
- ⚡ Contribute!
- 💥 Play with our Crackmes
The OWASP MASVS and MASTG are trusted by the following platform providers and standardization, governmental and educational institutions. Learn more.
![](/OWASP/owasp-mastg/raw/master/Document/Images/Other/trusted-by-logos.png)
MAS Advocates are industry adopters of the OWASP MASVS and MASTG who have invested a significant and consistent amount of resources to push the project forward by providing consistent high-impact contributions and continuously spreading the word. Learn more.
![](/OWASP/owasp-mastg/raw/master/Document/Images/Other/nowsecure-logo.png)
GitHub Discussions
#project-mobile-app-security (Get Invitation)
@OWASP_MAS (Official Account)
@bsd_daemon (Sven Schleier, Project Lead)
@grepharder (Carlos Holguera, Project Lead)
- Get the printed version via lulu.com
- Get the e-book on leanpub.com (please consider purchasing it to support our project or make a donation)
- Check our Document generation scripts