hypnguyen1209/offensive-claude

mobile-pentest

Use when pentesting an Android/iOS app — Frida 17 instrumentation, SSL-pinning & root/jailbreak bypass, Android 14/15 CA injection, exported-component/content-provider abuse, deep-link/WebView chains, biometric bypass, Flutter/React-Native RE

First seen May 24, 2026

Installation

$ npx skills add hypnguyen1209/offensive-claude --skill mobile-pentest

Similar popular skills

Related neighbors and high-traction skills in the same topics — useful to compare before installing.

Also in this package

Other skills from hypnguyen1209/offensive-claude · top by installs.

npx skills add hypnguyen1209/offensive-claude

Browse all from hypnguyen1209/offensive-claude

More details

Agent compatibility

Declared targets from SKILL.md / docs. Unmarked agents are not listed — the skill may still install via the CLI.

Claude Code Not declared
Cursor Not declared
Codex Not declared
GitHub Copilot Not declared
Windsurf Not declared
Gemini CLI Not declared
Cline Not declared
OpenCode Not declared

Repository health

Stars 357
License LICENSE
Default branch main
Open issues 0
Status Active

Skill metadata

Parsed from SKILL.md frontmatter.

More metadata
type
offensive
phase
exploitation
tools
frida, frida-tools, objection, jadx, apktool, reflutter, hermes-dec, hbctool, mitmproxy, burp, palera1n, dopamine, frida-ios-dump, bagbak, mobsf, drozer, nuclei
mitre
TA0001

Package contents

Files included with this skill beyond the listing page.

  • skill md SKILL.md 10,961 B
  • docs SUMMARY.md 266 B

History

  1. First seen on skills.sh
  2. First recorded snapshot · 29 installs

SKILL.md

Mobile Application Penetration Testing

When to Activate

  • Android/iOS application security assessment, bug-bounty mobile triage, or app-store reconnaissance
  • Need to intercept TLS traffic (SSL/cert pinning, Android 14/15 Conscrypt-APEX trust store, Flutter/RN stacks)
  • Bypass root/jailbreak or biometric-gating controls during dynamic analysis
  • Enumerate and exploit exported components, content providers, deep links, and WebViews
  • Extract secrets from insecure storage (SharedPrefs, SQLite, Keychain, Keystore) and reverse hybrid apps

Technique Map

Technique ATT&CK CWE Reference Script
Lab build + Frida 17 server/gadget T1635 CWE-1188 references/environment-interception.md -
Android 14/15 Conscrypt-APEX CA injection T1521.001 CWE-295 references/environment-interception.md scripts/androidcainject.sh
SSL/cert-pinning bypass (Java TM/OkHttp/native) T1521.001 CWE-295 references/environment-interception.md scripts/universal_unpin.js
Root detection bypass (RootBeer/native stat) T1633.001 CWE-693 references/environment-interception.md scripts/universal_unpin.js
Exported activity/service/receiver abuse T1626.001 CWE-926 references/android-component-attacks.md scripts/manifestattacksurface.py
Content-provider SQLi / path traversal (CVE-2025-48609) T1409 CWE-22, CWE-89 references/android-component-attacks.md scripts/component_fuzz.sh
Task hijacking / StrandHogg / TapTrap (USENIX '25) T1517 CWE-1021 references/android-component-attacks.md scripts/manifestattacksurface.py
Deep-link / intent-redirect / scheme hijack T1635, T1577 CWE-939 references/webview-deeplink-exploitation.md scripts/component_fuzz.sh
WebView JS-interface RCE + file:// theft T1577 CWE-749 references/webview-deeplink-exploitation.md scripts/component_fuzz.sh
OAuth custom-scheme callback interception T1635 CWE-940 references/webview-deeplink-exploitation.md -
Insecure storage (SharedPrefs/SQLite/external) T1409 CWE-312 references/insecure-storage-crypto.md scripts/manifestattacksurface.py
Keystore/Keychain misuse + dumping T1634 CWE-522 references/insecure-storage-crypto.md scripts/iosbypasssuite.js
Biometric bypass (BiometricPrompt/LAContext) T1634 CWE-287 references/insecure-storage-crypto.md scripts/iosbypasssuite.js
iOS jailbreak + JB-detection bypass T1635 CWE-693 references/ios-offensive.md scripts/iosbypasssuite.js
IPA decrypt / class-dump / URL-scheme abuse T1409, T1635 CWE-200 references/ios-offensive.md scripts/iosbypasssuite.js
Flutter RE / reFlutter pinning bypass T1521.001 CWE-295 references/crossplatform-re-instrumentation.md scripts/hermes_triage.py
React Native Hermes bytecode decompile T1640 CWE-656 references/crossplatform-re-instrumentation.md scripts/hermes_triage.py

Quick Start

# ---- ANDROID ----
# 0. Pull + statically triage the APK (manifest, secrets, exported surface, framework ID)
adb shell pm path com.target.app                              # locate split APKs
adb pull /data/app/.../base.apk .
python3 scripts/manifest_attack_surface.py base.apk -o surface.json
jadx -d src base.apk &  apktool d base.apk -o decoded

# 1. Frida 17: match server to host tools; push + run
frida --version                                              # e.g. 17.x  -> use matching server
adb push frida-server-17.x-android-arm64 /data/local/tmp/frida-server
adb shell "su -c 'chmod 755 /data/local/tmp/frida-server && /data/local/tmp/frida-server &'"

# 2. Trust Burp CA on Android 14/15 (APEX is immutable -> Zygote namespace bind-mount)
bash scripts/android_ca_inject.sh 9a5ba575.0 cacert.pem      # see reference for cert hashing

# 3. Spawn target with universal unpinning + root-detection bypass
frida -U -f com.target.app -l scripts/universal_unpin.js --no-pause

# 4. Hit the exported attack surface from surface.json
bash scripts/component_fuzz.sh com.target.app surface.json

# ---- iOS ----
frida-ios-dump -o app.ipa com.target.app                     # decrypt + pull (jailbroken)
frida -U -f com.target.app -l scripts/ios_bypass_suite.js --no-pause   # JB + pinning + biometric + keychain

# ---- HYBRID ----
file decoded/assets/index.android.bundle                     # "Hermes JavaScript bytecode" => RN
python3 scripts/hermes_triage.py base.apk                    # detect Flutter/RN, drive reFlutter/hermes-dec

OPSEC & Detection (summary)

Technique Telemetry / IOC Detection (Sigma / app-side) OPSEC note
Frida instrumentation frida-server/gadget ports (27042), re.frida.server, suspicious maps regions, named pipes linjector App scans /proc/self/maps for frida, checks D-Bus port, thread gum-js-loop; Play Integrity Use frida-gadget renamed lib, custom port frida-server -l 0.0.0.0:1337, magisk-hide / Shamiko
CA injection (APEX) New trust anchor in process trust store; cert CN mismatch on pinned hosts Network Security Config <trust-anchors> excludes user store; pinning catches it Mount lives only in Zygote ns, vanishes on Zygote crash — re-inject; nothing written to /system
SSL-pinning bypass TLS handshake to proxy IP; cert chain not app-pinned cert App-side pin failure callbacks fire (if logged); telemetry SDK sees proxy cert Hook before first request; for Flutter prefer reFlutter patch over runtime to avoid crash loops
Root/JB bypass getprop ro.debuggable, su binaries, magisk paths queried RootBeer/iXGuard SDK reports; SafetyNet/Play Integrity attestation server-side Bypass client checks only; server-side attestation (Play Integrity / DeviceCheck) is unaffected
Exported component abuse am start/startservice/broadcast from adb; foreign UID intent App logs unexpected caller UID; Binder.getCallingUid() checks Use on-device malicious app for realism; adb leaves shell history
Content-provider traversal content query with ../; openFile on out-of-dir path FileProvider canonical-path check; CVE-2025-48609 patched Mar 2026 SPL URL-encode ..%2f to dodge naive filters; read-only first
TapTrap / task hijack Transparent activity transition, taskAffinity overlap, animationScale abuse TapTrap fixed Dec 2025 SPL; check targetSdk, taskAffinity="" Zero-permission; works <Dec-2025 patch; user study: 100% missed at least one variant
Keychain/Keystore dump keychain_dumper, frida memory scrape, SecItemCopyMatching hooks Keychain items with .biometryCurrentSet resist hooking; SE-backed keys unextractable JB device dumps keychain plaintext regardless of ACL; flag SE vs SW keys in report
Biometric bypass LAContext evaluatePolicy / BiometricPrompt callback hook Only works on boolean-result pattern, NOT SecAccessControl-gated crypto Report root cause: auth result not bound to a crypto/keychain operation

Deep Dives

  • references/environment-interception.md — Rooted/jailbroken lab, Genymotion/AVD, Magisk+Shamiko, Frida 17 breaking changes (bridge removal, frida-pm, frida-compile), gadget mode for non-root, Android 14/15 Conscrypt-APEX CA injection via Zygote namespace bind-mount, universal SSL-pinning bypass (Java TrustManager/OkHttp/Network Security Config/native BoringSSL), root-detection bypass.
  • references/android-component-attacks.md — Manifest attack-surface enumeration, exported activity/service/broadcast/provider exploitation, content-provider SQLi & path traversal (CVE-2025-48609 MmsProvider), intent:// redirection to non-exported components, task hijacking (StrandHogg 1.0/2.0 CVE-2020-0096) and TapTrap animation-driven tapjacking (USENIX Security '25), drozer + adb workflows.
  • references/webview-deeplink-exploitation.mdaddJavascriptInterface RCE, setAllowUniversalAccessFromFileURLs/file:// local-file theft, deep-link → WebView open-redirect/XSS chains, intent:// browsable-activity pivots, OAuth custom-scheme callback hijack (RFC 8252), iOS URL-scheme & Universal Link abuse, one-click browser-to-WebView exploitation.
  • references/insecure-storage-crypto.md — Android SharedPreferences/SQLite/internal+external storage, Android Keystore misuse (non-hardware-backed keys, no setUserAuthenticationRequired), iOS Keychain ACLs & keychain_dumper, NSUserDefaults/plist leaks, biometric bypass (BiometricPrompt CryptoObject vs result-only, LAContext evaluatePolicy), hardcoded secrets & Firebase/S3 misconfig, MASVS-STORAGE mapping.
  • references/ios-offensive.md — Jailbreak tooling matrix (palera1n checkm8 A8–A11/T2 iOS 15–18.x, Dopamine A8–A16 iOS 15–16.6.1, Dopamine HideJailbreak), JB-detection bypass (Frida stat/fopen/dlopen hooks + Shadow), IPA decryption (frida-ios-dump/bagbak), class-dump/Swift demangling, entitlements & URL-scheme analysis, Frida-version pinning gotchas.
  • references/crossplatform-re-instrumentation.md — Flutter Dart-stack interception (reFlutter libflutter.so patch of sslcryptox509sessionverifycertchain, iptables/proxydroid fallback), React Native Hermes bytecode RE (hermes-dec, hbctool patch/reassemble, hermes-decomp, CatalystInstanceImpl.loadScriptFromAssets Frida hook), native .so JNI/JNI_OnLoad analysis in Ghidra/IDA.