Workflow: Complete iOS Application Assessment
End-to-end assessment aligned to OWASP MASTG. Expect 1-3 days per app.
Phase 1 — Recon (parallelizable)
ideviceinstaller -l # enumerate installed apps
idevice_id -l # UDID
ideviceinfo | grep -iE 'ProductVersion|ProductType'
objection -g <bundle_id> explore
> ios info binary
> ios bundles list_frameworks
> env # data/bundle pathsPhase 2 — Acquire & Decrypt IPA
# Jailbroken pull:
ssh root@<device> "cp -r /var/containers/Bundle/Application/<UUID>/App.app /tmp/"
scp -r root@<device>:/tmp/App.app ./
# App Store encrypted binary: decrypt
frida-ios-dump <bundle_id> # or: python3 dump.py <bundle_id>
# Verify: otool -l App.app/App | grep -A4 LC_ENCRYPTION_INFO (cryptid 0 = decrypted)Phase 3 — Static Analysis (parallelize the three tools)
class-dump -H App.app/App -o headers/ &
otool -L App.app/App &
strings -a App.app/App | grep -iE 'api|key|secret|password|token|bearer' &
wait
plutil -p App.app/Info.plist # URL schemes, ATS, entitlements
codesign -d --entitlements :- App.appPhase 4 — Bypass Protections (sequential; each hook must land before next)
objection -g <bundle_id> explore --startup-command 'ios sslpinning disable'
> ios jailbreak disable
> ios jailbreak simulate
# Or Frida:
frida -U -f <bundle_id> -l scripts/ssl_pinning_bypass.js -l scripts/jailbreak_bypass.js --no-pausePhase 5 — Dynamic Analysis
> ios keychain dump --json > keychain.json
> ios nsuserdefaults get
> ios cookies get
> ios nsurlcredentialstorage dump
> ios hooking watch class AuthManager
> ios hooking watch method "-[AuthManager authenticate:]" --dump-args --dump-returnPhase 6 — Network Testing
Configure device Wi-Fi HTTP proxy to Burp host; install Burp CA via Safari; trust in Settings > General > About > Certificate Trust Settings. Validate interception then replay/modify.
Phase 7 — Reporting
Emit findings per schemas/finding.json. Tag each with mastg_id and MASVS category.