Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Glass — Glass - a fast and free IDA Pro alternative | Kitploit
Tools/GitHubGitHub/azw413/glass
Android SecurityEmbedded Systems SecurityStatic AnalysisiOS SecurityReverse EngineeringScripting & AutomationDebuggersMobile SecurityBinary AnalysisFirmware Analysis
GitHubazw413/glass
19112171 month agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Glass

Glass - a fast and free IDA Pro alternative

View Repository

Glass

as in transparent and smooth

A fast, native, mobile-app first interactive disassembler. Spiritual successor to IDA Pro for the Android / iOS reverse engineering workflow, built around:

  • smali for APK / DEX / smali handling
  • armv8-encode for AArch64 and ARMv7 (A32 / Thumb) — native .so, iOS Mach-O
  • gpui (Zed) for GPU-accelerated native UI
  • redb for content-addressed persistence
  • An in-built MCP server so any MCP-aware host (Claude Desktop, Cursor, Zed) can drive Glass directly
  • rquickjs for scriptable plugins (planned)

License: GPL-3.0-only (inherited from smali).

Why?

We’ve all used IDA Pro — it’s the industry standard for reversing and has years of plugins behind it, but it’s slow, expensive, and dated. Glass is 100% Rust native with a GPU-accelerated UI for fluid interaction. It’s also 100% free and open source — please contribute.

Features

  • Buttery smooth 120fps GPU accelerated rendering
  • Lightning fast analysis: 1-2 seconds for most larger binaries compared with minutes on IDA Pro
  • AArch64 and ARMv7 (ARM mode + Thumb) disassembly — covers iOS arm64 / arm64e and both common Android ABIs.
  • Fully linked and annotated disassemblies with control flow lines, data literals in comments, clickable links to other functions. All coloured for easy visibility.
  • Control flow graphs showing basic blocks and clickable links to other functions
  • Full project search for symbols or string literals across DEX, code and data sections
  • Native binary layout overview with section data
  • Xref search of callers, references to data
  • Binary and instruction search across every native artifact in the bundle (so both arm64-v8a and armeabi-v7a copies of a library are searched in one query). Byte-pattern grammar with masking + gaps; typed-assembly grammar for AArch64 and ARMv7, with an ISA-aware autocomplete dropdown.
  • Annotate any line (code or data) with a colour and/or comment so you can easily find it again later.
  • In-place editing of instructions and data (double-click an item). Smali class editor + AArch64 / ARMv7 instruction editor; right-click any listing row to open a byte-level hex view at the same address as an escape hatch.
  • MCP server exposes every analysis verb as a tool for any MCP-aware host — Claude Desktop, Cursor, Zed.
  • Themes for Glass and also selectable background colours for each workspace.

Screenshots

A walk through the main views — click any thumbnail to see it full size.

AArch64 disassembly listing with arrow gutter, resolved string literals, clickable symbol references
Disassembly listing
colour-coded operands, control-flow arrows, resolved string literals inline
Control flow graph for a native function showing basic blocks, conditional and unconditional edges
Control flow graph
per-function CFG with dotted conditional edges and routed multi-rank lanes
DEX method call graph rooted at a smali method; hover-expandable callee nodes
DEX call graph
hover-to-expand callees, click to jump to the method's smali
Section-map overview of a native binary with coloured proportional bar and per-section detail
Section-map overview
proportional bar by section size, click to jump to listing / hex view

Scripting

Every analysis Glass does in the GUI is also exposed as a CLI verb that emits structured JSON. The same glass binary is the automation entry point — pick a subcommand and you get a one-shot, scriptable result, perfect for jq pipelines and CI.

# What classes ship in this APK?
glass classes ./app.apk --package com.example. --text

# Who calls glass::main, by address?
glass callers ./libfoo.so --artifact libfoo.so --symbol "glass::main"

# Every `onCreate` across DEX, machine-readable:
glass search ./app.apk onCreate | jq '.data.hits[] | select(.kind=="method")'

# All ObjC + Swift types in an iOS bundle (filter by kind if you like):
glass types ./app.ipa --kind swift-class --text

# Drill into one type — methods, ivars, properties for ObjC;
# fields + vtable for Swift:
glass type ./app.ipa --artifact app --name blackjack.ContentView

Pass --text for a human-readable rendering, omit it for JSON.

Full reference: docs/cli-api.md.

This means you can script and automate common operations.

Skills and MCP

Every CLI verb is also exposed as a tool through an inbuilt MCP (Model Context Protocol) server, so any MCP-aware host — Claude Desktop, Cursor, Zed, your own client — can drive Glass directly to help with reversing tasks.

# Print the machine-readable skill catalog (one JSON object listing
# every verb with its schema and an example invocation).
glass skills

# Run as an MCP stdio server. Plug into any MCP host's tool list.
glass mcp

To register with Claude Desktop, add Glass to ~/Library/Application Support/Claude/claude_desktop_config.json:

{
  "mcpServers": {
    "glass": { "command": "/usr/local/bin/glass", "args": ["mcp"] }
  }
}

The model can then call inspect, symbols, disasm, cfg-of, dex-callers, search and every other verb on any bundle you point it at. Tool results come back as the same JSON envelope you'd get from the CLI.

Searching

Three complementary engines, all available from the same ⌘F palette in the GUI and as CLI / MCP verbs.

Full text search

Bundle-wide fuzzy match across native symbols, DEX classes / methods / fields, and string literals in code and data sections. Live-filtered as you type; results dispatch to the right view (listing for native addresses, smali viewer for DEX targets, hex view for data hits). Indices build on a background thread after load — a progress chip shows while in flight.

glass search ./app.apk onCreate                 # all things named like "onCreate"
glass search ./libfoo.so init --limit 20

CLI reference: search verb in docs/cli-api.md.

Binary search

Byte-level pattern engine. Each atom is a 2-character hex mask (c0, e?, ?f, ??) or a gap (* = 0..=32 bytes, *(min..max) for explicit bounds). Matches don't span sections. In the GUI palette, ⌘2 switches to Binary mode; the Code only checkbox (default on) restricts the scan to text sections so you aren't drowning in data hits when looking for an instruction shape.

# returning-true stub finder — `mov w0, #1 ; ret`
glass bin-search ./libfoo.so --artifact libfoo.so --pattern '20 00 80 52 c0 03 5f d6'
Download Tool