Per OWASP MASVS v2 MASVS-RESILIENCE: resilience against reverse engineering + tampering. Requirements include (a) understand resilience is defence in depth + not replacement for server-side controls + (b) implement anti-debugging + anti-tampering + anti-hooking + root/jailbreak detection appropriate to risk + (c) implement code + string + asset obfuscation where appropriate + (d) implement integrity checks for code + resources + (e) implement device binding + attestation for high-assurance scenarios + (f) maintain telemetry + detection for tampering attempts + (g) avoid hard-coded secrets + use server-side validation for sensitive logic + (h) maintain backup procedures resistant to ransomware + rollback.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.