Mobile Security Framework (MobSF) v3.6 Releases
Mobile Security Framework
Mobile Security Framework (MobSF) is an intelligent, all-in-one open source mobile application (Android/iOS/Windows) automated pen-testing framework capable of performing static and dynamic analysis. It can be used for effective and fast security analysis of Android, iOS and Windows Mobile Applications and supports both binaries (APK, IPA & APPX ) and zipped source code. MobSF can also perform Web API Security testing with it’s API Fuzzer that can do Information Gathering, analyze Security Headers, identify Mobile API specific vulnerabilities like XXE, SSRF, Path Traversal, IDOR, and other logical issues related to Session and API Rate Limiting.
Screenshots
Static Analysis – Android APK
Static Analysis – iOS IPA
Static Analysis – Windows APPX
Dynamic Analysis – Android APK
Web API Fuzzer
Changelog v3.6
- Features or Enhancements
- False Positive Triaging / Suppression Triaging Support for critical Android and iOS Security Analysis features.
- Android Binary & Source – Supports Code Analysis and Manifest Analysis
- iOS Binary – Supports Binary Code Analysis
- iOS Source – Supports Code Analysis
- New REST APIs for Suppression Support
- Android Certificate Analysis improvements
- Remove RELRO check from android binary analysis due to false positives
- iOS Bundle ID extraction improvements
- Feature parity – Allow IPA downloads from reports view
- Code QA: Reduce False positives in identified secrets
- Check for updates from Github releases
- M1 Mac support
- Disabled by default feature to support hotspots in AppSec Scorecard
- Dependency updates
- Added CodeQL scan on MobSF python code base
- False Positive Triaging / Suppression Triaging Support for critical Android and iOS Security Analysis features.
- Bug Fixes
Download & Tutorial
Copyright (C) 2015 Ajin Abraham