257 results for “topic:mobile-security”
Mobile Security Framework (MobSF) is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis.
Source code for Hacker101.com - a free online web and mobile security class.
The OWASP Mobile Application Security Testing Guide (MASTG) is a comprehensive manual for mobile app security testing and reverse engineering. It describes technical processes for verifying the OWASP Mobile Security Weakness Enumeration (MASWE) weaknesses, which are in alignment with the OWASP MASVS.
The most powerful Android RPA agent framework, next generation of mobile automation robots.
Scanning APK file for URIs, endpoints & secrets.
the fastest and most powerful android decompiler(native tool working without Java VM) for the APK, DEX, ODEX, OAT, JAR, AAR, and CLASS file. which supports malicious behavior detection, privacy leaking detection, vulnerability detection, path solving, packer identification, variable tracking, deobfuscation, python&java scripts, device memory extraction, data decryption, and encryption, etc.
An effort to build a single place for all useful android and iOS security related stuff. All references and tools belong to their respective owners. I'm just maintaining it.
Runtime Mobile Security (RMS) 📱🔥 - is a powerful web interface that helps you to manipulate Android and iOS Apps at Runtime
Hand-crafted Frida examples
Flutter Reverse Engineering Framework
Documentation:
Flutter Reverse Engineering Framework
A Virtual Machine For Assessing Android applications, Reverse Engineering and Malware Analysis
[Official] Android reverse engineering tool focused on dynamic instrumentation automation leveraging Frida. It disassembles dex, analyzes it statically, generates hooks, discovers reflected methods, stores intercepted data and does new things from it. Its aim is to be an all-in-one Android reverse engineering platform.
A Huge Learning Resources with Labs For Offensive Security Players
(WIP) Runtime Mobile Application Pentest Tool for iOS and Android. Previously Passionfruit
Android security insights in full spectrum.
StaCoAn is a crossplatform tool which aids developers, bugbounty hunters and ethical hackers performing static code analysis on mobile applications.
Jackhammer - One Security vulnerability assessment/management tool to solve all the security team problems.
强大的 Frida 重打包工具,用于 iOS 和 Android。轻松修改 Frida 特征,增强隐蔽性,绕过检测。简化逆向工程和安全测试。Powerful Frida repackaging tool for iOS and Android. Easily modify Frida servers to enhance stealth and bypass detection. Streamlines reverse engineering and security testing.
Oversecured Vulnerable Android App
A Collection of Secure Mobile Development Best Practices
Unofficial frida extension for VSCode
Android Security Suite for in-depth reconnaissance and static bytecode analysis based on Ghera benchmarks.
Mobile penetration testing android & iOS command cheatsheet
Intentionally vulnerable Android application.
Web-based Frida framework and toolkit for Android & iOS penetration testing, mobile security, and dynamic analysis, featuring AI-assisted Frida script generation.
MCP server for JADX-AI Plugin
Intercept, modify, repeat and attack Android's Binder transactions using Burp Suite
🛡️ A React Native library to prevent and detect for screen capture, screenshots and app switcher for enhanced security. Fully compatible with both Expo and CLI.