Example: SSL Pinning Bypass Blueprint
Trigger: "bypass SSL pinning on iPhone for com.example.app".
Steps:
Bash: objection -g com.example.app explore --startup-command 'ios sslpinning disable'- Drive the app; check Burp history populates with decrypted HTTPS.
- If traffic still opaque: run Frida universal script:
Bash: frida -U -f com.example.app -l scripts/ssl_pinning_bypass.js --no-pause - If still failing: enumerate pinning classes via
class-dump+ grep; write a targeted hook. - Emit finding per
schemas/finding.jsononly if pinning is absent/weak; successful bypass by itself is not a finding — it's a tool outcome.