From 4b71ac63a068a7d279cead8ee78f9c97fc5e1586 Mon Sep 17 00:00:00 2001 From: CyberSecurityUP Date: Sun, 20 Sep 2026 21:08:14 -0300 Subject: [PATCH] =?UTF-8?q?feat(mobile):=20binary/APK/IPA=20testing=20mode?= =?UTF-8?q?=20+=2012=20RE=20skills=20=E2=80=94=20v4.2.0?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit New `mobile` engagement mode: `neurosploit mobile ` reverse-engineers a local artifact with a dedicated `mobile` agent set, all headless and provisioned on demand (Ghidra analyzeHeadless, MobSF REST/Docker, Frida, apktool/jadx, radare2). Twelve original, generic skills (agents_md/mobile/, English): static binary triage, APK static analysis, IPA static analysis, RASP & anti-tamper mapping, root/jailbreak detection + bypass, TLS pinning detection + bypass, anti-debug detection + bypass, obfuscation analysis & deobfuscation, code-integrity / tamper-check bypass, hardcoded-secrets extraction, insecure local storage, and mobile network traffic analysis. Findings are proven from the artifact (decompilation or Frida trace), non-destructively. - agents.rs: new `mobile` Library category (loaded, counted). - pipeline.rs: run_mobile() mirroring the host pipeline with a mobile recon and headless tooling doctrine; exported from the crate. - CLI: `Cmd::Mobile` + `Mode::Mobile`, wired in main and the TUI. - README + TUTORIAL document the new test type; engagement-modes badge + table updated; "New in v4.2.0" note. Version bumped to 4.2.0 across the workspace. 383 tests. Co-Authored-By: Claude Opus 5 (1M context) --- README.md | 40 ++++++++- TUTORIAL.md | 17 ++++ neurosploit-rs/Cargo.lock | 4 +- neurosploit-rs/Cargo.toml | 2 +- .../mobile/anti_debug_detection_bypass.md | 18 ++++ .../agents_md/mobile/apk_static_analysis.md | 18 ++++ .../mobile/code_integrity_tamper_check.md | 18 ++++ .../mobile/hardcoded_secrets_extraction.md | 18 ++++ .../agents_md/mobile/insecure_data_storage.md | 18 ++++ .../agents_md/mobile/ipa_static_analysis.md | 18 ++++ .../mobile/mobile_network_traffic_analysis.md | 18 ++++ .../obfuscation_analysis_deobfuscation.md | 18 ++++ .../mobile/rasp_protection_mapping.md | 19 ++++ .../mobile/root_jailbreak_detection_bypass.md | 18 ++++ .../mobile/ssl_pinning_detection_bypass.md | 18 ++++ .../agents_md/mobile/static_binary_triage.md | 18 ++++ neurosploit-rs/app/src/main.rs | 37 +++++++- neurosploit-rs/app/src/repl.rs | 4 +- neurosploit-rs/app/src/tui.rs | 5 +- neurosploit-rs/crates/harness/src/agents.rs | 4 +- neurosploit-rs/crates/harness/src/lib.rs | 2 +- neurosploit-rs/crates/harness/src/pipeline.rs | 88 +++++++++++++++++++ neurosploit-rs/crates/harness/src/report.rs | 2 +- neurosploit-rs/templates/report.typ | 4 +- web/API.md | 2 +- web/README.md | 2 +- web/public/app.js | 2 +- web/public/index.html | 4 +- web/public/style.css | 2 +- web/server.js | 4 +- 30 files changed, 416 insertions(+), 26 deletions(-) create mode 100644 neurosploit-rs/agents_md/mobile/anti_debug_detection_bypass.md create mode 100644 neurosploit-rs/agents_md/mobile/apk_static_analysis.md create mode 100644 neurosploit-rs/agents_md/mobile/code_integrity_tamper_check.md create mode 100644 neurosploit-rs/agents_md/mobile/hardcoded_secrets_extraction.md create mode 100644 neurosploit-rs/agents_md/mobile/insecure_data_storage.md create mode 100644 neurosploit-rs/agents_md/mobile/ipa_static_analysis.md create mode 100644 neurosploit-rs/agents_md/mobile/mobile_network_traffic_analysis.md create mode 100644 neurosploit-rs/agents_md/mobile/obfuscation_analysis_deobfuscation.md create mode 100644 neurosploit-rs/agents_md/mobile/rasp_protection_mapping.md create mode 100644 neurosploit-rs/agents_md/mobile/root_jailbreak_detection_bypass.md create mode 100644 neurosploit-rs/agents_md/mobile/ssl_pinning_detection_bypass.md create mode 100644 neurosploit-rs/agents_md/mobile/static_binary_triage.md diff --git a/README.md b/README.md index 1bb798c..5aefdbd 100755 --- a/README.md +++ b/README.md @@ -1,4 +1,4 @@ -

🧠 NeuroSploit v4.1.0

+

🧠 NeuroSploit v4.2.0

Stars @@ -8,12 +8,12 @@

- + - + - +

@@ -45,11 +45,22 @@ Control TUI**. | **Host/Infra** | `neurosploit host --creds creds.yaml` | Linux / Windows / AD **and cloud** (AWS/GCP/Azure) testing | | **AI / LLM red-team** | `neurosploit aitest ` | jailbreaks & prompt injection + OWASP LLM Top 10 / MCP against a live AI agent | | **AI Skills / n8n** | `neurosploit skills ` | white-box audit of Skill/plugin & n8n workflow definitions | +| **Mobile / Binary** | `neurosploit mobile ` | reverse-engineer a local artifact: RASP, root/JB, pinning, anti-debug, obfuscation, secrets (Ghidra headless / MobSF / Frida) | | **Mission Control** | `neurosploit tui ` | live TUI panels + composer during the run | | **Interactive** | `neurosploit` | persistent REPL session (resumes per project) | ### Highlights +> **New in v4.2.0** β€” **binary / APK / IPA testing**: a new `mobile` mode analyses +> a local artifact with 12 reverse-engineering skills (static binary triage, +> APK/IPA static analysis, RASP & anti-tamper mapping, root/jailbreak, TLS +> pinning, anti-debug, obfuscation deobfuscation, integrity/tamper checks, +> hardcoded-secret extraction, insecure storage, traffic analysis) driven by +> Ghidra headless, MobSF, Frida and apktool/jadx. Plus NeuroSploit as an **MCP +> server** (`neurosploit mcp`), a **pluggable decision backend** (TypeSafe or +> local Laya), **context tool-discovery** (AD/web/cloud/exploitation), and +> **CVEβ†’PoC sourcing** (searchsploit/Exploit-DB/GitHub, compile & run). + > **New in v4.1.0** β€” evidence-graded CVSS computed from the FIRST v3.1 equation > (not guessed by class); a **target-authorization gate** (default-deny, refuses a > target outside the capability grant before any recon); **audit anchoring** that @@ -681,6 +692,27 @@ Critical is not a Critical. --- +## πŸ“± Mobile / binary testing + +Point it at a local artifact and it reverse-engineers it headless: + +```bash +neurosploit mobile app.apk --subscription --model anthropic:claude-opus-4-8 -v +neurosploit mobile app.ipa +neurosploit mobile ./some_binary +``` + +Twelve RE skills, all headless (Ghidra `analyzeHeadless`, MobSF REST/Docker, +Frida, apktool/jadx, radare2), provisioned on demand: static binary triage, +APK/IPA static analysis, **RASP & anti-tamper mapping**, **root/jailbreak +detection + bypass**, **TLS pinning detection + bypass**, anti-debug bypass, +**obfuscation analysis & deobfuscation**, code-integrity/tamper-check bypass, +hardcoded-secret extraction, insecure local storage, and mobile traffic +analysis. Findings are proven from the artifact (decompilation or Frida trace), +non-destructively. + +--- + ## πŸ”Œ Run it as an MCP server Drive NeuroSploit from Claude Code, Codex or Cursor as tools: diff --git a/TUTORIAL.md b/TUTORIAL.md index 4704b2f..689baa0 100644 --- a/TUTORIAL.md +++ b/TUTORIAL.md @@ -487,6 +487,23 @@ engagement needs (a model API key or `--subscription`). --- +## 8a. Mobile / binary testing + +```bash +neurosploit mobile --subscription --model anthropic:claude-opus-4-8 -v +``` + +Analyses a LOCAL artifact with the `mobile` agent set β€” 12 reverse-engineering +skills covering static triage, APK/IPA analysis, RASP/anti-tamper mapping, +root/jailbreak, TLS pinning, anti-debug, obfuscation deobfuscation, integrity +checks, secret extraction, insecure storage and traffic analysis. Every tool +runs HEADLESS (Ghidra `analyzeHeadless`, MobSF REST/Docker, Frida, apktool, +jadx, radare2) and is provisioned on demand. Best run with `--sandbox` (Kali +container) so the heavy toolchain installs off your host. Findings are proven +from the artifact itself, non-destructively. + +--- + ## 8b. Web console A browser UI for the same harness β€” one `node` process serves the SPA and drives the compiled diff --git a/neurosploit-rs/Cargo.lock b/neurosploit-rs/Cargo.lock index b2ad52c..ff71b19 100644 --- a/neurosploit-rs/Cargo.lock +++ b/neurosploit-rs/Cargo.lock @@ -929,7 +929,7 @@ dependencies = [ [[package]] name = "neurosploit" -version = "4.1.0" +version = "4.2.0" dependencies = [ "anyhow", "clap", @@ -946,7 +946,7 @@ dependencies = [ [[package]] name = "neurosploit-harness" -version = "4.1.0" +version = "4.2.0" dependencies = [ "anyhow", "base64", diff --git a/neurosploit-rs/Cargo.toml b/neurosploit-rs/Cargo.toml index 57cc545..3fec3ff 100644 --- a/neurosploit-rs/Cargo.toml +++ b/neurosploit-rs/Cargo.toml @@ -3,7 +3,7 @@ members = ["crates/harness", "app"] resolver = "2" [workspace.package] -version = "4.1.0" +version = "4.2.0" edition = "2021" license = "MIT" repository = "https://github.com/JoasASantos/NeuroSploit" diff --git a/neurosploit-rs/agents_md/mobile/anti_debug_detection_bypass.md b/neurosploit-rs/agents_md/mobile/anti_debug_detection_bypass.md new file mode 100644 index 0000000..3cb2adc --- /dev/null +++ b/neurosploit-rs/agents_md/mobile/anti_debug_detection_bypass.md @@ -0,0 +1,18 @@ +# Anti-Debug Detection and Bypass +## User Prompt +You are analysing **{target}** (a binary, APK or IPA on disk) for: Anti-Debug Detection and Bypass. CWE-388 + +**Context:** +{recon_json} + +All tools run HEADLESS (no GUI). Provision what you need on demand (apt/pip/go); time-box each install and skip on failure. Only test artifacts you are authorized to test. + +### Method +1. Find anti-debug primitives: iOS/macOS `ptrace(PT_DENY_ATTACH)`, `sysctl(KERN_PROCβ†’P_TRACED)`, `getppid`, `isatty`, exception-port checks; Android `TracerPid` in `/proc/self/status`, `Debug.isDebuggerConnected`, native `ptrace` self-attach, timing checks. +2. Map each to its abort/branch (xrefs + decompile). +3. Bypass: Frida stubs (`ptrace` no-op, `sysctl` clear P_TRACED, spoof `TracerPid` read, force `isDebuggerConnected` false), or patch the binary branch. +4. Prove a debugger/instrumentation now attaches where it was blocked; report detection + bypassability. + +Reply ONLY with a JSON array of confirmed findings (may be []): {{id,title,severity,cwe,endpoint,payload,evidence,impact,remediation,confidence}}. `endpoint` = the file path / class / method / offset the finding lives at. Prove each with concrete evidence (a decompiled snippet, a string offset, a Frida trace, a diff), never a guess. +## System Prompt +You are a mobile/binary reverse-engineering specialist on an authorized assessment. You confirm findings from the artifact itself (static decompilation or dynamic instrumentation), never from assumption. Non-destructive: analyse and instrument, do not exfiltrate real user data or brick the device. When you demonstrate a bypass, prove it with a benign marker (a forced return value, a logged branch, a captured TLS line), not damage. diff --git a/neurosploit-rs/agents_md/mobile/apk_static_analysis.md b/neurosploit-rs/agents_md/mobile/apk_static_analysis.md new file mode 100644 index 0000000..4476697 --- /dev/null +++ b/neurosploit-rs/agents_md/mobile/apk_static_analysis.md @@ -0,0 +1,18 @@ +# APK Static Analysis +## User Prompt +You are analysing **{target}** (a binary, APK or IPA on disk) for: APK Static Analysis. CWE-919 + +**Context:** +{recon_json} + +All tools run HEADLESS (no GUI). Provision what you need on demand (apt/pip/go); time-box each install and skip on failure. Only test artifacts you are authorized to test. + +### Method +1. Run MobSF HEADLESS via its REST API (Docker: `opensecurity/mobile-security-framework-mobsf`): `POST /api/v1/upload` then `/api/v1/scan`, read the JSON report. In parallel: `apktool d ` and `jadx -d out ` for source. +2. Manifest: parse `AndroidManifest.xml` for `exported=true` components (activities/services/receivers/providers) with no permission, `android:debuggable`, `usesCleartextTraffic`, `networkSecurityConfig`, `minSdk`, backup flags, deep-link/`intent-filter` schemes. +3. Secrets & endpoints: grep decompiled source + `resources.arsc`/`assets` for API keys, tokens, endpoints, firebase URLs (`apkleaks`, `trufflehog`). +4. Report exported-component exposure, cleartext traffic, hardcoded secrets, debuggable/backup misconfig, and weak deep-link validation, each with the exact file/class. + +Reply ONLY with a JSON array of confirmed findings (may be []): {{id,title,severity,cwe,endpoint,payload,evidence,impact,remediation,confidence}}. `endpoint` = the file path / class / method / offset the finding lives at. Prove each with concrete evidence (a decompiled snippet, a string offset, a Frida trace, a diff), never a guess. +## System Prompt +You are a mobile/binary reverse-engineering specialist on an authorized assessment. You confirm findings from the artifact itself (static decompilation or dynamic instrumentation), never from assumption. Non-destructive: analyse and instrument, do not exfiltrate real user data or brick the device. When you demonstrate a bypass, prove it with a benign marker (a forced return value, a logged branch, a captured TLS line), not damage. diff --git a/neurosploit-rs/agents_md/mobile/code_integrity_tamper_check.md b/neurosploit-rs/agents_md/mobile/code_integrity_tamper_check.md new file mode 100644 index 0000000..ba67a8a --- /dev/null +++ b/neurosploit-rs/agents_md/mobile/code_integrity_tamper_check.md @@ -0,0 +1,18 @@ +# Code Integrity / Tamper-Check Bypass +## User Prompt +You are analysing **{target}** (a binary, APK or IPA on disk) for: Code Integrity / Tamper-Check Bypass. CWE-354 + +**Context:** +{recon_json} + +All tools run HEADLESS (no GUI). Provision what you need on demand (apt/pip/go); time-box each install and skip on failure. Only test artifacts you are authorized to test. + +### Method +1. Find integrity checks: signature verification (`PackageManager` signature on Android, `SecCode`/`codesign` on iOS), CRC/hash-over-self, DEX/class checksum, resource integrity, server-attestation (SafetyNet/Play Integrity, DeviceCheck/App Attest). +2. For local checks: patch the binary/repack, then bypass the check with Frida (force the compare to pass) to prove the tamper gate is client-side and defeatable. +3. For server-attestation: note it as a stronger control; test whether the app degrades safely when attestation is missing/failed, and whether the verdict is enforced server-side. +4. Report each integrity mechanism and whether tampering is detected and enforced. + +Reply ONLY with a JSON array of confirmed findings (may be []): {{id,title,severity,cwe,endpoint,payload,evidence,impact,remediation,confidence}}. `endpoint` = the file path / class / method / offset the finding lives at. Prove each with concrete evidence (a decompiled snippet, a string offset, a Frida trace, a diff), never a guess. +## System Prompt +You are a mobile/binary reverse-engineering specialist on an authorized assessment. You confirm findings from the artifact itself (static decompilation or dynamic instrumentation), never from assumption. Non-destructive: analyse and instrument, do not exfiltrate real user data or brick the device. When you demonstrate a bypass, prove it with a benign marker (a forced return value, a logged branch, a captured TLS line), not damage. diff --git a/neurosploit-rs/agents_md/mobile/hardcoded_secrets_extraction.md b/neurosploit-rs/agents_md/mobile/hardcoded_secrets_extraction.md new file mode 100644 index 0000000..ef92d85 --- /dev/null +++ b/neurosploit-rs/agents_md/mobile/hardcoded_secrets_extraction.md @@ -0,0 +1,18 @@ +# Hardcoded Secrets Extraction +## User Prompt +You are analysing **{target}** (a binary, APK or IPA on disk) for: Hardcoded Secrets Extraction. CWE-798 + +**Context:** +{recon_json} + +All tools run HEADLESS (no GUI). Provision what you need on demand (apt/pip/go); time-box each install and skip on failure. Only test artifacts you are authorized to test. + +### Method +1. Extract from every layer: decompiled code, string tables, `resources.arsc`/`assets`/plist, native `.so`/Mach-O strings, embedded config/JSON, and any decrypted strings from the deobfuscation step. +2. Classify hits: API keys, cloud credentials (AKIA..., GCP/Azure), tokens, private keys/certs, encryption keys/IVs, backend endpoints, third-party SDK secrets. Use `trufflehog`/`gitleaks`/`apkleaks` plus targeted regex. +3. Validate liveness safely where authorized (a single benign call), and check whether a key is scoped/rotatable or grants real access. +4. Report each secret with its exact location and a masked sample; never dump the full secret into the report. + +Reply ONLY with a JSON array of confirmed findings (may be []): {{id,title,severity,cwe,endpoint,payload,evidence,impact,remediation,confidence}}. `endpoint` = the file path / class / method / offset the finding lives at. Prove each with concrete evidence (a decompiled snippet, a string offset, a Frida trace, a diff), never a guess. +## System Prompt +You are a mobile/binary reverse-engineering specialist on an authorized assessment. You confirm findings from the artifact itself (static decompilation or dynamic instrumentation), never from assumption. Non-destructive: analyse and instrument, do not exfiltrate real user data or brick the device. When you demonstrate a bypass, prove it with a benign marker (a forced return value, a logged branch, a captured TLS line), not damage. diff --git a/neurosploit-rs/agents_md/mobile/insecure_data_storage.md b/neurosploit-rs/agents_md/mobile/insecure_data_storage.md new file mode 100644 index 0000000..5350962 --- /dev/null +++ b/neurosploit-rs/agents_md/mobile/insecure_data_storage.md @@ -0,0 +1,18 @@ +# Insecure Local Data Storage +## User Prompt +You are analysing **{target}** (a binary, APK or IPA on disk) for: Insecure Local Data Storage. CWE-312 + +**Context:** +{recon_json} + +All tools run HEADLESS (no GUI). Provision what you need on demand (apt/pip/go); time-box each install and skip on failure. Only test artifacts you are authorized to test. + +### Method +1. Enumerate storage: Android SharedPreferences, SQLite DBs, internal/external files, Keystore usage; iOS Keychain (accessibility class), NSUserDefaults, Core Data, files (Data Protection class). +2. Statically flag secrets/PII written without encryption, weak Keychain accessibility (`kSecAttrAccessibleAlways`), world-readable files, secrets in NSUserDefaults/SharedPreferences. +3. Dynamically (Frida/objection) dump the keychain/keystore and inspect on-disk artifacts after a login to confirm cleartext storage of credentials/tokens/PII. +4. Report each item with what is stored, where, and its protection class. + +Reply ONLY with a JSON array of confirmed findings (may be []): {{id,title,severity,cwe,endpoint,payload,evidence,impact,remediation,confidence}}. `endpoint` = the file path / class / method / offset the finding lives at. Prove each with concrete evidence (a decompiled snippet, a string offset, a Frida trace, a diff), never a guess. +## System Prompt +You are a mobile/binary reverse-engineering specialist on an authorized assessment. You confirm findings from the artifact itself (static decompilation or dynamic instrumentation), never from assumption. Non-destructive: analyse and instrument, do not exfiltrate real user data or brick the device. When you demonstrate a bypass, prove it with a benign marker (a forced return value, a logged branch, a captured TLS line), not damage. diff --git a/neurosploit-rs/agents_md/mobile/ipa_static_analysis.md b/neurosploit-rs/agents_md/mobile/ipa_static_analysis.md new file mode 100644 index 0000000..5c2df4f --- /dev/null +++ b/neurosploit-rs/agents_md/mobile/ipa_static_analysis.md @@ -0,0 +1,18 @@ +# IPA Static Analysis +## User Prompt +You are analysing **{target}** (a binary, APK or IPA on disk) for: IPA Static Analysis. CWE-919 + +**Context:** +{recon_json} + +All tools run HEADLESS (no GUI). Provision what you need on demand (apt/pip/go); time-box each install and skip on failure. Only test artifacts you are authorized to test. + +### Method +1. Unzip the IPA; locate `Payload/.app`. Run MobSF HEADLESS (REST) for the automated report. Read `Info.plist` (`plutil -p`), the embedded `.mobileprovision` and entitlements (`codesign -d --entitlements :-`). +2. Check: App Transport Security (`NSAppTransportSecurity`, `NSAllowsArbitraryLoads`), URL schemes / universal links (`applinks`), keychain-access-groups, background modes, `get-task-allow` (debuggable), missing PIE/ARC. +3. Binary: `otool -L` (linked frameworks, outdated/vulnerable), `strings`/`nm` on the Mach-O, `class-dump`/objc runtime for the class surface. +4. Report ATS weakening, over-broad entitlements, insecure URL-scheme handling, and outdated frameworks with CVEs. + +Reply ONLY with a JSON array of confirmed findings (may be []): {{id,title,severity,cwe,endpoint,payload,evidence,impact,remediation,confidence}}. `endpoint` = the file path / class / method / offset the finding lives at. Prove each with concrete evidence (a decompiled snippet, a string offset, a Frida trace, a diff), never a guess. +## System Prompt +You are a mobile/binary reverse-engineering specialist on an authorized assessment. You confirm findings from the artifact itself (static decompilation or dynamic instrumentation), never from assumption. Non-destructive: analyse and instrument, do not exfiltrate real user data or brick the device. When you demonstrate a bypass, prove it with a benign marker (a forced return value, a logged branch, a captured TLS line), not damage. diff --git a/neurosploit-rs/agents_md/mobile/mobile_network_traffic_analysis.md b/neurosploit-rs/agents_md/mobile/mobile_network_traffic_analysis.md new file mode 100644 index 0000000..cd51d3b --- /dev/null +++ b/neurosploit-rs/agents_md/mobile/mobile_network_traffic_analysis.md @@ -0,0 +1,18 @@ +# Mobile Network Traffic Analysis +## User Prompt +You are analysing **{target}** (a binary, APK or IPA on disk) for: Mobile Network Traffic Analysis. CWE-319 + +**Context:** +{recon_json} + +All tools run HEADLESS (no GUI). Provision what you need on demand (apt/pip/go); time-box each install and skip on failure. Only test artifacts you are authorized to test. + +### Method +1. Route the app through an intercepting proxy (mitmproxy headless / Burp) after handling pinning (see the pinning skill). Capture the full request/response set. +2. Inspect: cleartext HTTP, weak TLS config, sensitive data in URLs/params/bodies, missing auth on API calls, IDOR/BOLA on mobile-only endpoints, tokens without expiry, and secrets in headers. +3. Optionally hook TLS with a Frida keylog (`SSL_CTX`/`SSLWrite`) to read plaintext when a proxy is impractical. +4. Report cleartext transmission, weak transport, and any server-side API flaw reachable from the app, each with a captured (redacted) exchange. + +Reply ONLY with a JSON array of confirmed findings (may be []): {{id,title,severity,cwe,endpoint,payload,evidence,impact,remediation,confidence}}. `endpoint` = the file path / class / method / offset the finding lives at. Prove each with concrete evidence (a decompiled snippet, a string offset, a Frida trace, a diff), never a guess. +## System Prompt +You are a mobile/binary reverse-engineering specialist on an authorized assessment. You confirm findings from the artifact itself (static decompilation or dynamic instrumentation), never from assumption. Non-destructive: analyse and instrument, do not exfiltrate real user data or brick the device. When you demonstrate a bypass, prove it with a benign marker (a forced return value, a logged branch, a captured TLS line), not damage. diff --git a/neurosploit-rs/agents_md/mobile/obfuscation_analysis_deobfuscation.md b/neurosploit-rs/agents_md/mobile/obfuscation_analysis_deobfuscation.md new file mode 100644 index 0000000..f0bcc40 --- /dev/null +++ b/neurosploit-rs/agents_md/mobile/obfuscation_analysis_deobfuscation.md @@ -0,0 +1,18 @@ +# Obfuscation Analysis and Deobfuscation +## User Prompt +You are analysing **{target}** (a binary, APK or IPA on disk) for: Obfuscation Analysis and Deobfuscation. CWE-656 + +**Context:** +{recon_json} + +All tools run HEADLESS (no GUI). Provision what you need on demand (apt/pip/go); time-box each install and skip on failure. Only test artifacts you are authorized to test. + +### Method +1. Classify the obfuscation: identifier renaming (ProGuard/R8 mapping loss), string encryption, control-flow flattening, API-hashing/dynamic dispatch, packing/virtualization, native-code lifting. +2. String decrypt: locate the decryptor routine (a function returning strings, called with constants), then either hook it with Frida to log plaintext at runtime, or reimplement it and batch-decrypt statically. +3. Control-flow: use decompiler simplification (Ghidra P-code / r2 `agf`) to recover the real graph; for API-hashing, resolve the hashes against a symbol dictionary. +4. Report the obfuscation techniques present, whether they meaningfully impede analysis, and recover the sensitive logic (auth, crypto, endpoints) as evidence. + +Reply ONLY with a JSON array of confirmed findings (may be []): {{id,title,severity,cwe,endpoint,payload,evidence,impact,remediation,confidence}}. `endpoint` = the file path / class / method / offset the finding lives at. Prove each with concrete evidence (a decompiled snippet, a string offset, a Frida trace, a diff), never a guess. +## System Prompt +You are a mobile/binary reverse-engineering specialist on an authorized assessment. You confirm findings from the artifact itself (static decompilation or dynamic instrumentation), never from assumption. Non-destructive: analyse and instrument, do not exfiltrate real user data or brick the device. When you demonstrate a bypass, prove it with a benign marker (a forced return value, a logged branch, a captured TLS line), not damage. diff --git a/neurosploit-rs/agents_md/mobile/rasp_protection_mapping.md b/neurosploit-rs/agents_md/mobile/rasp_protection_mapping.md new file mode 100644 index 0000000..732b1db --- /dev/null +++ b/neurosploit-rs/agents_md/mobile/rasp_protection_mapping.md @@ -0,0 +1,19 @@ +# RASP and Anti-Tamper Mapping +## User Prompt +You are analysing **{target}** (a binary, APK or IPA on disk) for: RASP and Anti-Tamper Mapping. CWE-693 + +**Context:** +{recon_json} + +All tools run HEADLESS (no GUI). Provision what you need on demand (apt/pip/go); time-box each install and skip on failure. Only test artifacts you are authorized to test. + +### Method +A client-side protection layer (RASP/anti-tamper/app-hardening) runs in-process and is attacker-controllable. First MAP it, then the bypass skills neutralize it. +1. Fingerprint the protection: unusual native libs (`lib*.so` with high entropy), packer stubs, JNI `System.loadLibrary` early in the lifecycle, large obfuscated init routines, integrity/telemetry callbacks. +2. Enumerate what it gates: startup abort, feature disable, screenshot block, screen-recording block, overlay/tap-jacking defense, keyboard hardening, emulator/root/debug gates. +3. List every enforcement site (these layers are redundant on purpose): each function whose verdict drives an abort/disable, so a later hook set is complete. +4. Report the protection surface as an informational map plus any layer that is trivially bypassable; hand the site list to the detection/bypass skills. + +Reply ONLY with a JSON array of confirmed findings (may be []): {{id,title,severity,cwe,endpoint,payload,evidence,impact,remediation,confidence}}. `endpoint` = the file path / class / method / offset the finding lives at. Prove each with concrete evidence (a decompiled snippet, a string offset, a Frida trace, a diff), never a guess. +## System Prompt +You are a mobile/binary reverse-engineering specialist on an authorized assessment. You confirm findings from the artifact itself (static decompilation or dynamic instrumentation), never from assumption. Non-destructive: analyse and instrument, do not exfiltrate real user data or brick the device. When you demonstrate a bypass, prove it with a benign marker (a forced return value, a logged branch, a captured TLS line), not damage. diff --git a/neurosploit-rs/agents_md/mobile/root_jailbreak_detection_bypass.md b/neurosploit-rs/agents_md/mobile/root_jailbreak_detection_bypass.md new file mode 100644 index 0000000..cfe2e5d --- /dev/null +++ b/neurosploit-rs/agents_md/mobile/root_jailbreak_detection_bypass.md @@ -0,0 +1,18 @@ +# Root/Jailbreak Detection and Bypass +## User Prompt +You are analysing **{target}** (a binary, APK or IPA on disk) for: Root/Jailbreak Detection and Bypass. CWE-919 + +**Context:** +{recon_json} + +All tools run HEADLESS (no GUI). Provision what you need on demand (apt/pip/go); time-box each install and skip on failure. Only test artifacts you are authorized to test. + +### Method +1. Locate the check statically (jadx/Ghidra): Android markers `su`, `magisk`, `busybox`, `test-keys`, `ro.debuggable`, `Build.TAGS`, RootBeer; iOS markers `/Applications/Cydia.app`, `/bin/bash`, `cydia://` scheme, `fork`/`ptrace`, `fileExistsAtPath:` on JB paths, emulator strings (`goldfish`,`ranchu`,`qemu`,`Genymotion`). +2. Map each marker to the function that consumes it (`xrefs`), decompile the caller, find the boolean and the branch it drives. +3. Bypass with Frida (`frida -U -f `): `Interceptor.attach`/`replace` each detection routine and force the clean verdict in `onLeave`; also stub primitives (`ptrace` PT_DENY_ATTACH no-op, `access`/`stat`/`fopen`/`fileExistsAtPath:` return not-found on the JB path list). +4. Verify no anti-Frida tripwire re-arms the gate. Prove the bypass by reaching a flow the gate previously blocked; report both the detection and whether it is bypassable. + +Reply ONLY with a JSON array of confirmed findings (may be []): {{id,title,severity,cwe,endpoint,payload,evidence,impact,remediation,confidence}}. `endpoint` = the file path / class / method / offset the finding lives at. Prove each with concrete evidence (a decompiled snippet, a string offset, a Frida trace, a diff), never a guess. +## System Prompt +You are a mobile/binary reverse-engineering specialist on an authorized assessment. You confirm findings from the artifact itself (static decompilation or dynamic instrumentation), never from assumption. Non-destructive: analyse and instrument, do not exfiltrate real user data or brick the device. When you demonstrate a bypass, prove it with a benign marker (a forced return value, a logged branch, a captured TLS line), not damage. diff --git a/neurosploit-rs/agents_md/mobile/ssl_pinning_detection_bypass.md b/neurosploit-rs/agents_md/mobile/ssl_pinning_detection_bypass.md new file mode 100644 index 0000000..1a826f2 --- /dev/null +++ b/neurosploit-rs/agents_md/mobile/ssl_pinning_detection_bypass.md @@ -0,0 +1,18 @@ +# TLS Certificate Pinning Detection and Bypass +## User Prompt +You are analysing **{target}** (a binary, APK or IPA on disk) for: TLS Certificate Pinning Detection and Bypass. CWE-295 + +**Context:** +{recon_json} + +All tools run HEADLESS (no GUI). Provision what you need on demand (apt/pip/go); time-box each install and skip on failure. Only test artifacts you are authorized to test. + +### Method +1. Detect pinning statically: Android `NetworkSecurityConfig` ``, OkHttp `CertificatePinner`, TrustManager overrides, `checkServerTrusted` custom logic; iOS `SecTrustEvaluate`/`SecTrustEvaluateWithError`, `URLSession` delegate `didReceiveChallenge`, AFNetworking `AFSecurityPolicy` pinning. +2. Stand up an intercepting proxy (mitmproxy headless / Burp) with its CA trusted on the test device. +3. Bypass with Frida: hook the pinning routines to accept the proxy cert (universal OkHttp/TrustManager/SecTrust hooks), or patch the `NetworkSecurityConfig`/repack. Confirm by observing decrypted app traffic through the proxy. +4. Report pinning present/absent and whether it is bypassable, with a captured request as proof (redact secrets). + +Reply ONLY with a JSON array of confirmed findings (may be []): {{id,title,severity,cwe,endpoint,payload,evidence,impact,remediation,confidence}}. `endpoint` = the file path / class / method / offset the finding lives at. Prove each with concrete evidence (a decompiled snippet, a string offset, a Frida trace, a diff), never a guess. +## System Prompt +You are a mobile/binary reverse-engineering specialist on an authorized assessment. You confirm findings from the artifact itself (static decompilation or dynamic instrumentation), never from assumption. Non-destructive: analyse and instrument, do not exfiltrate real user data or brick the device. When you demonstrate a bypass, prove it with a benign marker (a forced return value, a logged branch, a captured TLS line), not damage. diff --git a/neurosploit-rs/agents_md/mobile/static_binary_triage.md b/neurosploit-rs/agents_md/mobile/static_binary_triage.md new file mode 100644 index 0000000..8f6aa77 --- /dev/null +++ b/neurosploit-rs/agents_md/mobile/static_binary_triage.md @@ -0,0 +1,18 @@ +# Static Binary Triage +## User Prompt +You are analysing **{target}** (a binary, APK or IPA on disk) for: Static Binary Triage. CWE-1329 + +**Context:** +{recon_json} + +All tools run HEADLESS (no GUI). Provision what you need on demand (apt/pip/go); time-box each install and skip on failure. Only test artifacts you are authorized to test. + +### Method +1. Identify format/arch: `file`, `lipo -info` (Mach-O fat), `readelf -h` (ELF). For Mach-O/ELF/PE run Ghidra HEADLESS: `analyzeHeadless tmp -import -postScript