Mobile pentest
Offensive security toolkit for Claude Code covering red team, exploit dev, AD attacks, EDR bypass, mobile pentest
npx -y skills add hypnguyen1209/offensive-claude --skill mobile-pentestAssembled from the repository path, not quoted from the project. Check it against their README if it does not work.
What its author says it does
Copied from the file, not written here
Use when pentesting an Android/iOS app — Frida 17 instrumentation, SSL-pinning & root/jailbreak bypass, Android 14/15 CA injection, exported-component/content-provider abuse, deep-link/WebView chains, biometric bypass, Flutter/React-Native RE
SKILL.md
10.7 KB, as published. Nobody here has run it
Mobile Application Penetration Testing
When to Activate
- Android/iOS application security assessment, bug-bounty mobile triage, or app-store reconnaissance
- Need to intercept TLS traffic (SSL/cert pinning, Android 14/15 Conscrypt-APEX trust store, Flutter/RN stacks)
- Bypass root/jailbreak or biometric-gating controls during dynamic analysis
- Enumerate and exploit exported components, content providers, deep links, and WebViews
- Extract secrets from insecure storage (SharedPrefs, SQLite, Keychain, Keystore) and reverse hybrid apps
Technique Map
| Technique | ATT&CK | CWE | Reference | Script |
|---|---|---|---|---|
| Lab build + Frida 17 server/gadget | T1635 | CWE-1188 | references/environment-interception.md | - |
| Android 14/15 Conscrypt-APEX CA injection | T1521.001 | CWE-295 | references/environment-interception.md | scripts/android_ca_inject.sh |
| SSL/cert-pinning bypass (Java TM/OkHttp/native) | T1521.001 | CWE-295 | references/environment-interception.md | scripts/universal_unpin.js |
| Root detection bypass (RootBeer/native stat) | T1633.001 | CWE-693 | references/environment-interception.md | scripts/universal_unpin.js |
| Exported activity/service/receiver abuse | T1626.001 | CWE-926 | references/android-component-attacks.md | scripts/manifest_attack_surface.py |
| Content-provider SQLi / path traversal (CVE-2025-48609) | T1409 | CWE-22, CWE-89 | references/android-component-attacks.md | scripts/component_fuzz.sh |
| Task hijacking / StrandHogg / TapTrap (USENIX '25) | T1517 | CWE-1021 | references/android-component-attacks.md | scripts/manifest_attack_surface.py |
| Deep-link / intent-redirect / scheme hijack | T1635, T1577 | CWE-939 | references/webview-deeplink-exploitation.md | scripts/component_fuzz.sh |
| WebView JS-interface RCE + file:// theft | T1577 | CWE-749 | references/webview-deeplink-exploitation.md | scripts/component_fuzz.sh |
| OAuth custom-scheme callback interception | T1635 | CWE-940 | references/webview-deeplink-exploitation.md | - |
| Insecure storage (SharedPrefs/SQLite/external) | T1409 | CWE-312 | references/insecure-storage-crypto.md | scripts/manifest_attack_surface.py |
| Keystore/Keychain misuse + dumping | T1634 | CWE-522 | references/insecure-storage-crypto.md | scripts/ios_bypass_suite.js |
| Biometric bypass (BiometricPrompt/LAContext) | T1634 | CWE-287 | references/insecure-storage-crypto.md | scripts/ios_bypass_suite.js |
| iOS jailbreak + JB-detection bypass | T1635 | CWE-693 | references/ios-offensive.md | scripts/ios_bypass_suite.js |
| IPA decrypt / class-dump / URL-scheme abuse | T1409, T1635 | CWE-200 | references/ios-offensive.md | scripts/ios_bypass_suite.js |
| Flutter RE / reFlutter pinning bypass | T1521.001 | CWE-295 | references/crossplatform-re-instrumentation.md | scripts/hermes_triage.py |
| React Native Hermes bytecode decompile | T1640 | CWE-656 | references/crossplatform-re-instrumentation.md | scripts/hermes_triage.py |
Quick Start
# ---- ANDROID ----
# 0. Pull + statically triage the APK (manifest, secrets, exported surface, framework ID)
adb shell pm path com.target.app # locate split APKs
adb pull /data/app/.../base.apk .
python3 scripts/manifest_attack_surface.py base.apk -o surface.json
jadx -d src base.apk & apktool d base.apk -o decoded
# 1. Frida 17: match server to host tools; push + run
frida --version # e.g. 17.x -> use matching server
adb push frida-server-17.x-android-arm64 /data/local/tmp/frida-server
adb shell "su -c 'chmod 755 /data/local/tmp/frida-server && /data/local/tmp/frida-server &'"
# 2. Trust Burp CA on Android 14/15 (APEX is immutable -> Zygote namespace bind-mount)
bash scripts/android_ca_inject.sh 9a5ba575.0 cacert.pem # see reference for cert hashing
# 3. Spawn target with universal unpinning + root-detection bypass
frida -U -f com.target.app -l scripts/universal_unpin.js --no-pause
# 4. Hit the exported attack surface from surface.json
bash scripts/component_fuzz.sh com.target.app surface.json
# ---- iOS ----
frida-ios-dump -o app.ipa com.target.app # decrypt + pull (jailbroken)
frida -U -f com.target.app -l scripts/ios_bypass_suite.js --no-pause # JB + pinning + biometric + keychain
# ---- HYBRID ----
file decoded/assets/index.android.bundle # "Hermes JavaScript bytecode" => RN
python3 scripts/hermes_triage.py base.apk # detect Flutter/RN, drive reFlutter/hermes-dec
OPSEC & Detection (summary)
| Technique | Telemetry / IOC | Detection (Sigma / app-side) | OPSEC note |
|---|---|---|---|
| Frida instrumentation | frida-server/gadget ports (27042), re.frida.server, suspicious maps regions, named pipes linjector | App scans /proc/self/maps for frida, checks D-Bus port, thread gum-js-loop; Play Integrity | Use frida-gadget renamed lib, custom port frida-server -l 0.0.0.0:1337, magisk-hide / Shamiko |
| CA injection (APEX) | New trust anchor in process trust store; cert CN mismatch on pinned hosts | Network Security Config <trust-anchors> excludes user store; pinning catches it | Mount lives only in Zygote ns, vanishes on Zygote crash — re-inject; nothing written to /system |
| SSL-pinning bypass | TLS handshake to proxy IP; cert chain not app-pinned cert | App-side pin failure callbacks fire (if logged); telemetry SDK sees proxy cert | Hook before first request; for Flutter prefer reFlutter patch over runtime to avoid crash loops |
| Root/JB bypass | getprop ro.debuggable, su binaries, magisk paths queried | RootBeer/iXGuard SDK reports; SafetyNet/Play Integrity attestation server-side | Bypass client checks only; server-side attestation (Play Integrity / DeviceCheck) is unaffected |
| Exported component abuse | am start/startservice/broadcast from adb; foreign UID intent | App logs unexpected caller UID; Binder.getCallingUid() checks | Use on-device malicious app for realism; adb leaves shell history |
| Content-provider traversal | content query with ../; openFile on out-of-dir path | FileProvider canonical-path check; CVE-2025-48609 patched Mar 2026 SPL | URL-encode ..%2f to dodge naive filters; read-only first |
| TapTrap / task hijack | Transparent activity transition, taskAffinity overlap, animationScale abuse | TapTrap fixed Dec 2025 SPL; check targetSdk, taskAffinity="" | Zero-permission; works <Dec-2025 patch; user study: 100% missed at least one variant |
| Keychain/Keystore dump | keychain_dumper, frida memory scrape, SecItemCopyMatching hooks | Keychain items with .biometryCurrentSet resist hooking; SE-backed keys unextractable | JB device dumps keychain plaintext regardless of ACL; flag SE vs SW keys in report |
| Biometric bypass | LAContext evaluatePolicy / BiometricPrompt callback hook | Only works on boolean-result pattern, NOT SecAccessControl-gated crypto | Report root cause: auth result not bound to a crypto/keychain operation |
Deep Dives
- references/environment-interception.md — Rooted/jailbroken lab, Genymotion/AVD, Magisk+Shamiko, Frida 17 breaking changes (bridge removal, frida-pm, frida-compile), gadget mode for non-root, Android 14/15 Conscrypt-APEX CA injection via Zygote namespace bind-mount, universal SSL-pinning bypass (Java TrustManager/OkHttp/Network Security Config/native BoringSSL), root-detection bypass.
- references/android-component-attacks.md — Manifest attack-surface enumeration, exported activity/service/broadcast/provider exploitation, content-provider SQLi & path traversal (CVE-2025-48609 MmsProvider),
intent://redirection to non-exported components, task hijacking (StrandHogg 1.0/2.0 CVE-2020-0096) and TapTrap animation-driven tapjacking (USENIX Security '25), drozer + adb workflows. - references/webview-deeplink-exploitation.md —
addJavascriptInterfaceRCE,setAllowUniversalAccessFromFileURLs/file://local-file theft, deep-link → WebView open-redirect/XSS chains,intent://browsable-activity pivots, OAuth custom-scheme callback hijack (RFC 8252), iOS URL-scheme & Universal Link abuse, one-click browser-to-WebView exploitation. - references/insecure-storage-crypto.md — Android SharedPreferences/SQLite/internal+external storage, Android Keystore misuse (non-hardware-backed keys, no
setUserAuthenticationRequired), iOS Keychain ACLs &keychain_dumper, NSUserDefaults/plist leaks, biometric bypass (BiometricPrompt CryptoObject vs result-only, LAContextevaluatePolicy), hardcoded secrets & Firebase/S3 misconfig, MASVS-STORAGE mapping. - references/ios-offensive.md — Jailbreak tooling matrix (palera1n checkm8 A8–A11/T2 iOS 15–18.x, Dopamine A8–A16 iOS 15–16.6.1, Dopamine HideJailbreak), JB-detection bypass (Frida stat/fopen/dlopen hooks + Shadow), IPA decryption (frida-ios-dump/bagbak), class-dump/Swift demangling, entitlements & URL-scheme analysis, Frida-version pinning gotchas.
- references/crossplatform-re-instrumentation.md — Flutter Dart-stack interception (reFlutter
libflutter.sopatch ofssl_crypto_x509_session_verify_cert_chain, iptables/proxydroid fallback), React Native Hermes bytecode RE (hermes-dec, hbctool patch/reassemble, hermes-decomp,CatalystInstanceImpl.loadScriptFromAssetsFrida hook), native.soJNI/JNI_OnLoadanalysis in Ghidra/IDA.