Methodology: iOS Dynamic Analysis
Attach vs Spawn
frida -U <bundle_id> # attach (app already running)
frida -U -f <bundle_id> --no-pause # spawn (intercept __start)
objection -g <bundle_id> explore # interactive REPL
objection -g <bundle_id> explore --startup-command 'ios sslpinning disable'Prefer spawn when bypasses must hook initialisation (SSL, jailbreak check, anti-debug).
Class & Method Discovery at Runtime
> ios hooking list classes
> ios hooking search classes <term>
> ios hooking list class_methods <Class>Method Watching
> ios hooking watch class <Class>
> ios hooking watch method "-[Class selector:]" --dump-args --dump-return --dump-backtrace
> ios hooking set return_value "-[Class boolSelector]" falseHeap / Ivar Inspection
In Frida REPL:
var cls = ObjC.classes.AuthManager;
ObjC.chooseSync(cls).forEach(i => console.log(i.$ivars));Common Hooks Library
See scripts/ — pre-built for SSL pinning, jailbreak, biometric, keychain, crypto, URL scheme, method tracer, anti-debug. Compose multiple -l flags on one frida invocation.
Session Hygiene
- After each test,
ios hooking unwatch allto avoid log noise. - Restart
frida-serverbetween targets if memory balloons:ssh root@device "killall -9 frida-server && /usr/sbin/frida-server &".