Using MobSF for static analysis
Given that the application binaries for Android and iOS have been obtained, we can perform further analysis using automated techniques. A great open source Python tool that can be leveraged for both Android and iOS is the Mobile Security Framework (MobSF). There are several features and capabilities MobSF can automate for us, particularly for Android apps. This recipe will demonstrate MobSF's automated static analysis features for both Android and iOS. Static analysis typically requires access to source code, however, decompiling Android and iOS applications can give us a form of pseudocode close to the original source.
Getting ready
MobSF is included in the accompanied virtual machine with version 0.9.5.2 beta. MobSF is constantly being updated and can be downloaded via https://github.com/MobSF/Mobile-Security-Framework-MobSF. Ensure all dependencies have been installed as listed in MobSF's documentation.
Ensure target APKs and decrypted iOS IPA applications...