Manual Testing
Authorized training/testing use only. DVMA is intentionally vulnerable. Do not run these steps against apps or infrastructure you are not authorized to test.
These checklists cover what the in-app automated integration_test/ suite structurally cannot validate: checks that need an external tool (an active MITM proxy, a Frida hook, static analysis of the compiled APK/IPA, an attacking companion app). Modules fully proven in-app omit a manual step and don’t appear here.
The steps are generated from the registry (manual_test: on each module) and split by the module’s platforms, so they never drift from the catalog. Pick your platform:
- Android — root/
adb/drozer/apksigner-driven checks. - iOS — jailbreak/objection/Keychain/App-Intents checks.
Common tooling: Frida, objection, mitmproxy / Burp Suite, drozer, jadx, adb, apksigner.