This is simply my research and the repo I've always wanted; made pretty just for you.
This maps how to test: Electron, Tauri, CEF/WebView2, .NET, Java, and native desktop apps, organized the way an attacker would move through one.
- Reconnaissance & Unpacking
- Secrets & Data at Rest
- Inter-Process Communication
- Embedded Web Layer
- Update Mechanism
- Binary Protections & Tampering
- Network & API
- Runtime, Memory & Instrumentation
- Auth, Licensing & Authorization
- Deep Links & Protocol Handlers
Fast index: CHECKLIST.md.
Built and maintained by pa7ch3s