Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
RMS-Runtime-Mobile-Security — Runtime Mobile Security (RMS) 📱🔥 - is a powerful web interface that helps you to manipulate Android and iOS Apps at Runtime | Kitploit
Tools/GitHubGitHub/m0bilesecurity/rms-runtime-mobile-security
Android SecurityDynamic Analysis (Sandboxing)iOS SecurityMobile App PentestingReverse EngineeringDebuggersMobile ForensicsFuzzingPenetration Testing

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
Mobile Security
Top in Android Security #10
Top in iOS Security #8
Top in Mobile App Pentesting #10
Top in Mobile Forensics #14
Top in Mobile Security #10
GitHubm0bilesecurity/rms-runtime-mobile-security

RMS-Runtime-Mobile-Security

Runtime Mobile Security (RMS) 📱🔥 - is a powerful web interface that helps you to manipulate Android and iOS Apps at Runtime

View RepositoryWebsite
3.1k413343 months agoReviewed by Kitploit

Runtime Mobile Security (RMS) 📱🔥

RMS_logo

npm version npm downloads bundle size license GitHub stars GitHub forks

by @mobilesecurity_

Runtime Mobile Security (RMS), powered by FRIDA, is a powerful web interface that helps you to manipulate Android and iOS Apps at Runtime.

With RMS you can easily dump all loaded classes and relative methods, hook everything on the fly, trace methods args and return value, load custom scripts and many other useful stuff.

iOS DEMO - VIDEO

RMS - iOS DEMO

Android DEMO - VIDEO

RMS - Android DEMO

Tutorial - Android

  • Solving OWASP UnCrackable Android App Level 1 with Runtime Mobile Security (RMS)
  • Solving OWASP UnCrackable Android App Level 2 with Runtime Mobile Security (RMS)
  • Solving SANS Holiday Hack Challenge 2024 with Runtime Mobile Security (RMS) by Andrea Lamonato
    • Writeup
    • Video

Prerequisites

  1. NodeJS installed on your computer
  2. FRIDA's CLI tools installed on your computer
  3. FRIDA server up and running on the target device
    • Android - Official Tutorial
    • iOS - Official Tutorial

Quick smoke-test

As suggested by the official FRIDA doc, please perform a quick smoke-test to make sure FRIDA is working properly on your test device.

By running the frida-ps -U command from your desktop, you should receive the list of the processes running on your connected mobile device.

Android                    | iOS
  PID NAME                 |  PID NAME
 1590 com.facebook.katana  |  488 Clock
 3282 com.twitter.android  |  116 Facebook
 …                            …

Tips

Some cool projects that can help you to auto install, update and run FRIDA on Android devices are:

  • MagiskFrida - Android
  • FridaLoader - Android

They are not needed on iOS devices, since FRIDA starts just after the boot of the device (jailbreak mode).

Installation

  1. Open the terminal and run the following command to install the npm package
    • npm install -g rms-runtime-mobile-security
    • If you can't install the frida-node dependency, please check this troubleshooting post written by Chichou to choose another version of Node.js
  2. Make sure frida-server is up and running on the target device.
    • Instructions are here: prerequisites / quick smoke-test
  3. Launch RMS via the following command
    • rms (or RMS-Runtime-Mobile-Security)
  4. Open your browser at http://127.0.0.1:5491/
  5. Start enjoying RMS 📱🔥

NOTE
Default RMS port has been changed from 5000 to 5491 because since MacOS Ventura, port 5000 is the Control Center's default port. If you wish to change the default port, you can also run RMS with the --port parameter followed by the desired port number e.g. rms --port 9000

Notes and possibile issues

  1. In case of issues with the npm package installed as a global cli app, please try the local installation (development mode)
  2. In case of issues with your favorite Browser (e.g. logs not printed in the web console), please use Google Chrome (fully supported)
  3. If RMS is not able to detect your device, please perform the following checks:
    • double check if frida-server is up and running on the target device. Instructions are here: prerequisites / quick smoke-test
    • RMS must be started after frida-server
    • make sure that only 1 device is connected to your computer. RMS is currently not able to detect multiple devices
    • kill RMS and start it again

Development mode

Follow the steps below if you want to develop new features for RMS 😉

  1. git clone https://github.com/m0bilesecurity/RMS-Runtime-Mobile-Security.git
  2. cd RMS-Runtime-Mobile-Security
  3. npm install (local installation)
  4. Launch RMS via node rms.js
  5. You can also install RMS as global package by running the following commands:
    • npm install -g to install dependencies
    • npm run compile to compile the frida-agent
    • rms to run RMS (anywhere)

NOTE: If you add new features to the agent (/agent/RMS_core.js), please remember to recompile the code by running npm run compile or directly via the frida-compile command (frida-compile agent/RMS_core.js -o agent/compiled_RMS_core.js)

General Info

Runtime Mobile Security (RMS) supports Android and iOS devices.

It has been tested on MacOS and with the following devices:

  • AVD emulator
  • Genymotion emulator
  • Amazon Fire Stick 4K
  • iPhone 7
  • Chrome (Web Interface)

It should also work well on Windows and Linux but some minor adjustments may be needed.

Known issues and improvements

  • Sometime RMS fails to load complex methods. Use a filter when this happens or feel free to improve the algo (agent/RMS_core.js)
  • Socket are not working on Safari, please use Chrome instead
  • RMS is not able to recognize multiple devices. Please do not connect more than one device at the same time
  • Code is not optimized
  • Feel free to send me your best JS script via a Pull Request. I'll be happy to bundle all the best as default scripts in the next RMS release (e.g. root detection bypass, ssl pinning, etc)

Usage

1. Run your favorite app by simply inserting its package name

NOTE RMS attachs a persistence process called com.android.systemui on Android and SpringBoard on iOS devices to get the list of all the classes that are already loaded in memory before the launch of the target app. If you have an issue with them, try to find a different default package that works well on your device. You can set another default package via the Config Tab or by simply editing the /config/config.json file.

DEMO_1_Android

Download Tool