Example: Keychain Dump Blueprint
Trigger: "extract keychain data from com.example.app".
Steps:
Bash: objection -g com.example.app explore --startup-command 'ios keychain dump --json'→ redirect stdout tokeychain.json.- Parse JSON; for each entry, record:
service,account,accessibleflag,access_control. - Classify severity using the accessibility table in
workflows/keychain_extraction.md. - For any MEDIUM+ accessibility holding a secret, open a finding with:
mastg_id: MASTG-TEST-0011owasp: MASVS-STORAGE-1evidence.keychain_dump: redacted entryaffected.bundle_id,affected.ios_version.
- Recommend
kSecAttrAccessibleWhenPasscodeSetThisDeviceOnly+SecAccessControlwith.biometryCurrentSet.