#2Tools for observing malware behavior in isolated environments to understand its actions and impact.
Kitploit recommended

Mobile app security auditing tool focused on automating SAST analysis, identifying underlying technologies (React Native, Flutter, Xamarin, native),…
An interactive TLS-capable intercepting HTTP proxy for penetration testers and software developers.

Adaptive web scraping framework with anti-bot bypass, automatic element relocation, concurrent crawling, proxy rotation, and browser automation for…

Find, verify, and analyze leaked credentials

A Java 8+ Jar & Android APK Reverse Engineering Suite (Decompiler, Editor, Debugger & More)

Security scanner for AI agent skills. Detect vulnerabilities, malicious patterns, security risks, prompt injection, data exfiltration, and…

The ZAP Heads Up Display (HUD)

Python tool and library to help analyze files during malware triage and analysis.

Some good resources for getting started with application security

An effort to build a single place for all useful android and iOS security related stuff. All references and tools belong to their respective owners.…

An open-source user mode debugger for Windows. Optimized for reverse engineering and malware analysis.

Open-source Interactive Application Security Testing (IAST) tool that passively instruments Java applications to detect vulnerabilities and…

Parallel IDA Pro binary analysis with AI-powered function naming, Neo4j knowledge graph, and phantomrt emulation/hooking/fuzzing engine for automated…

Automated mobile application security testing framework for Android, iOS, and Windows. Performs static and dynamic analysis, malware detection, and…

Top-level repository for LFI: Practical, Efficient, and Secure Software-based Sandboxing

The fuzzer afl++ is afl with community patches, qemu 5.1 upgrade, collision-free coverage, enhanced laf-intel & redqueen, AFLfast++ power schedules,…

A lightweight sandboxing tool for enforcing filesystem and network restrictions on arbitrary processes at the OS level, without requiring a container.

Distributed, code-coverage guided snapshot-based fuzzer for user and kernel-mode targets on Windows and Linux, with emulator and hypervisor backends.