Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
frida-snippets — Hand-crafted Frida examples | Kitploit
Tools/GitHubGitHub/iddoeldor/frida-snippets
Android SecurityDynamic Analysis (Sandboxing)iOS SecurityReverse EngineeringDebuggersMobile SecurityBinary Analysis
GitHubiddoeldor/frida-snippets

frida-snippets

Hand-crafted Frida examples

View Repository
2.5k439201 year agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

PRs Welcome & also output examples

Table of Contents

Native
  • Load C/C++ module
  • One time watchpoint
  • Socket activity
  • Intercept open
  • Execute shell command
  • List modules
  • Log SQLite query
  • Log method arguments
  • Intercept entire module
  • Dump memory segments
  • Memory scan
  • Stalker
  • Cpp Demangler
  • Early hook
Android
  • Binder transactions
  • Get system property
  • Reveal manually registered native symbols
  • Enumerate loaded classes
  • Class description
  • Turn WiFi off
  • Set proxy
  • Get IMEI
  • Hook io InputStream
  • Android make Toast
  • Await for specific module to load
  • Webview URLS
  • Print all runtime strings & stacktrace
  • Print shared preferences updates
  • String comparison
  • Hook JNI by address
  • Hook constructor
  • Hook Java reflection
  • Trace class
  • Hooking Unity3d
  • Get Android ID
  • Change location
  • Bypass FLAG_SECURE
  • Shared Preferences update
  • Hook all method overloads
  • Register broadcast receiver
  • Increase step count
  • list classes implements interface with class loaders
  • File system access hook $ frida --codeshare FrenchYeti/android-file-system-access-hook -f com.example.app --no-pause
  • How to remove/disable java hooks ? Assign null to the implementation property.
iOS
  • OS Log
  • iOS alert box
  • File access
  • Observe class
  • Find application UUID
  • Extract cookies
  • Describe class members
  • Class hierarchy
  • Hook refelaction
  • Device properties
  • Take screenshot
  • Log SSH commands
Windows

HAHAHA. No.

Sublime snippets
{
    "scope": "source.js",
    "completions": [
	{"trigger": "fridainterceptor", "contents": "Interceptor.attach(\n    ptr,\n    {\n        onEnter:function(args) {\n\n        },\n        onLeave: function(retval) {\n\n        }\n    }\n)"},
	{"trigger": "fridaperform", "contents": "function main(){\n    console.log('main()');\n}\n\nconsole.log('script loaded');\nJava.perform(main);"},
	{"trigger": "fridause", "contents": "var kls = Java.use('kls');"},
	{"trigger": "fridahex", "contents": "hexdump(\n    ptr,\n    {\n         offset: 0,\n         length: ptr_size\n     }\n);" },
	{"trigger": "fridabacktrace", "contents": "console.log('called from:\\n' +\n        Thread.backtrace(this.context, Backtracer.ACCURATE)\n        .map(DebugSymbol.fromAddress).join('\\n') + '\\n'\n);"},
	{"trigger": "fridamods", "contents": "var mods = Process.enumerateModules().filter(function(mod){\n    return mod.name.includes(\"<name>\");\n});"},
	{"trigger": "fridaexport", "contents": "Module.findExportByName(null, \"<export_name>\");"},
	{"trigger": "fridabase", "contents": "Module.findBaseAddress(name);"},
	{"trigger": "fridaoverload", "contents": "kls.method_name.overload().implementation=function(){}"}
    ]
}
Vim snippets

To list abbreviations :ab

Expand by writing key and <Space>

  • Add to ~/.vimrc
ab fridaintercept Interceptor.attach(ptr, {<CR><Tab>onEnter: function(args) {<CR><CR>},<CR>onLeave: function(retval) {<CR><CR>}<CR><BS>})
ab fridabacktrace console.warn(Thread.backtrace(this.context, Backtracer.ACCURATE).map(DebugSymbol.fromAddress).join('\n'));<ESC>F(3;
ab fridadescribe console.log(Object.getOwnPropertyNames(Java.use('$').__proto__).join('\n\t'))<Esc>F$
JEB

Java method hook generator using keyboard shortcut

  1. curl -o ~/$JEB$/scripts/FridaCodeGenerator.py https://raw.githubusercontent.com/iddoeldor/frida-snippets/master/scripts/FridaCodeGenerator.py
  2. Place cursor at Java method's signature
  3. Press Ctrl+Shift+Z
  4. Code is copied to system clipboard (using xclip)

Fetch SSL keys

var keylog_callback = new NativeCallback((ssl, line) => {
  send(Memory.readCString(line));
}, 'void', ['pointer', 'pointer']);

if (ObjC.available) {
  var CALLBACK_OFFSET = 0x2A8
  if (Memory.readDouble(Module.findExportByName('CoreFoundation', 'kCFCoreFoundationVersionNumber')) >= 1751.108) {
    CALLBACK_OFFSET = 0x2B8
  }
  Interceptor.attach(Module.findExportByName('libboringssl.dylib', 'SSL_CTX_set_info_callback'), {
    onEnter(args) {
      ptr(args[0]).add(CALLBACK_OFFSET).writePointer(keylog_callback)
    }
  })
} else if (Java.available) {
  var set_keylog_callback = new NativeFunction(Module.findExportByName('libssl.so', 'SSL_CTX_set_keylog_callback'), 'void', ['pointer', 'pointer']);
  Interceptor.attach(Module.findExportByName('libssl.so', 'SSL_CTX_new'), {
    onLeave(retval) {
      set_keylog_callback(retval, keylog_callback)
    }
  })
}


⬆ Back to top

Load CPP module

#include <iostream>
#include <string>

extern "C" {
  void* create_stdstr(char *data, int size) {
    std::string* s = new std::string();
    (*s).assign(data, size);		  
    return s;
  }
}
$ ./android-ndk/toolchains/llvm/prebuilt/linux-x86_64/bin/aarch64-linux-android21-clang++ a.cpp -o a -shared -static-libstdc++ && adb push a /data/local/tmp/a
[device]-> 
function readStdString(str) {
  if ((str.readU8() & 1) === 1) { // size LSB (=1) indicates if it's a long string
    return str.add(2 * Process.pointerSize).readPointer().readUtf8String();    
  }
  return str.add(1).readUtf8String();  
}
[device]-> Module.load('/data/local/tmp/a');
[device]-> var fp_create_stdstr = Module.findExportByName('a', 'create_stdstr');
[device]-> var createStdString = new NativeFunction(fp_create_stdstr, 'pointer', ['pointer', 'int']);
[device]-> var stdstr1 = createStdString(Memory.allocUtf8String("abcd"), 3);
"0x07691234567"
[device]-> readStdString(stdstr1);
"abc"

Load C module

  • https://frida.re/docs/javascript-api/#cmodule
  • https://frida.re/news/2019/09/18/frida-12-7-released/
$ ./aarch64-linux-android21-clang /tmp/b.c -o /tmp/a -shared ../sysroot/usr/lib/aarch64-linux-android/21/liblog.so && adb push /tmp/a /data/local/tmp/a
#include <stdio.h>
#include <stdlib.h>
#include <android/log.h>    

#define TAG "TEST1"
#define LOGI(...) __android_log_print(ANDROID_LOG_INFO, TAG, __VA_ARGS__)
#define LOGE(...) __android_log_print(ANDROID_LOG_ERROR, TAG, __VA_ARGS__)
Download Tool