📄️ Host Software Setup
The first step in any iOS assessment is building a usable host environment. This page covers the tools to install on a macOS or Parrot (Linux) host and how to get them onto the box.
📄️ Physical Device Setup
A physical iPhone/iPad is essential for realistic testing: real hardware security features, true ATS behavior, biometric prompts, and actual network stack quirks. This page walks through preparing a physical device for an assessment.
📄️ Simulator Setup
The iOS Simulator runs on macOS and is great for fast, repeatable testing without hardware. It is not a substitute for a physical device, but it is the fastest way to get an app running, patched, and instrumented.
📄️ Mobile Hacking Lab Setup
A mobile lab is a stack: host tools, a test target (device or simulator), an intercepting proxy, and the instrument tools that tie them together. This page describes how the pieces fit and the traffic flow through the lab.
📄️ Interacting With iOS Devices
The libimobiledevice suite is the Swiss-army knife for talking to iOS devices over USB without Apple tooling. This page is a cheat sheet of the commands you will use most.
📄️ SSH and libimobiledevice
Two ways of talking to the device under test: SSH (mostly on jailbroken devices) and the libimobiledevice suite over USB. This page covers both and how they combine for USB-tunneled SSH.
📄️ Burp Suite
Burp Suite is the primary intercepting proxy for iOS testing. This page covers proxy configuration on the device, installing and trusting the Burp CA, and the ATS bypass notes you will need when apps refuse to talk over plain HTTP.
📄️ Frida
Frida is the dynamic instrumentation engine at the heart of most iOS mobile testing. With it you hook methods at runtime, bypass SSL pinning and jailbreak detection, and trace crypto or network calls — no recompilation needed.
📄️ Objection
Objection is a runtime mobile-exploration toolkit that wraps Frida into a friendly REPL. It saves you from writing custom hooks for the common cases: SSL pinning, jailbreak detection, app storage browsing, and memory patching.
📄️ MobSF
MobSF (Mobile Security Framework) is an automated static-analysis platform for iOS (and Android) apps. Feed it an IPA and it produces a report covering permissions, hardcoded secrets, insecure API usage, transport security, and more. It is the first pass before you start manual and dynamic testing.