feat(mobile): binary/APK/IPA testing mode + 12 RE skills — v4.2.0

New `mobile` engagement mode: `neurosploit mobile <app.apk|app.ipa|binary>`
reverse-engineers a local artifact with a dedicated `mobile` agent set, all
headless and provisioned on demand (Ghidra analyzeHeadless, MobSF REST/Docker,
Frida, apktool/jadx, radare2).

Twelve original, generic skills (agents_md/mobile/, English): static binary
triage, APK static analysis, IPA static analysis, RASP & anti-tamper mapping,
root/jailbreak detection + bypass, TLS pinning detection + bypass, anti-debug
detection + bypass, obfuscation analysis & deobfuscation, code-integrity /
tamper-check bypass, hardcoded-secrets extraction, insecure local storage, and
mobile network traffic analysis. Findings are proven from the artifact
(decompilation or Frida trace), non-destructively.

- agents.rs: new `mobile` Library category (loaded, counted).
- pipeline.rs: run_mobile() mirroring the host pipeline with a mobile recon and
  headless tooling doctrine; exported from the crate.
- CLI: `Cmd::Mobile` + `Mode::Mobile`, wired in main and the TUI.
- README + TUTORIAL document the new test type; engagement-modes badge + table
  updated; "New in v4.2.0" note. Version bumped to 4.2.0 across the workspace.

383 tests.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
CyberSecurityUPandClaude Opus 5 committed 2026-09-20 21:08:14 -03:00
1 parent a4afd784c7
commit 4b71ac63a0
30 files changed
+416 -26

No files matched your search

+17
View File
@@ -487,6 +487,23 @@ engagement needs (a model API key or `--subscription`).
---
## 8a. Mobile / binary testing
```bash
neurosploit mobile <app.apk | app.ipa | binary> --subscription --model anthropic:claude-opus-4-8 -v
```
Analyses a LOCAL artifact with the `mobile` agent set — 12 reverse-engineering
skills covering static triage, APK/IPA analysis, RASP/anti-tamper mapping,
root/jailbreak, TLS pinning, anti-debug, obfuscation deobfuscation, integrity
checks, secret extraction, insecure storage and traffic analysis. Every tool
runs HEADLESS (Ghidra `analyzeHeadless`, MobSF REST/Docker, Frida, apktool,
jadx, radare2) and is provisioned on demand. Best run with `--sandbox` (Kali
container) so the heavy toolchain installs off your host. Findings are proven
from the artifact itself, non-destructively.
---
## 8b. Web console
A browser UI for the same harness — one `node` process serves the SPA and drives the compiled