Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Tools/GitHubGitHub/stuxctf/slythestx
Android SecurityStatic AnalysisDynamic Analysis (Sandboxing)iOS SecurityVulnerability AnalysisMobile App PentestingPenetration TestingMobile SecuritySecret Detection
GitHubstuxctf/slythestx

slythestx

Mobile app security auditing tool focused on automating SAST analysis, identifying underlying technologies (React Native, Flutter, Xamarin, native), and enabling deeper testing on rooted or jailbroken devices.

16220815 days agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
View Repository

🐍 Slythestx

Slythestx Logo

The Swiss Army Worm for Mobile Security
A unified framework for static code analysis and dynamic vulnerability hunting on iOS and Android.

Version Security

Docker Node Python Vite Platform License For Educational Purposes Only

Buy Me A Coffee


📖 Table of Contents

  • Overview
  • Key Features
  • Architecture
  • Analyzer Suite
  • Quick Start
  • Usage
  • Release Notes
  • Roadmap
  • Contributing
  • Disclaimer
  • License

⚡ Overview

Slythestx is a mobile-focused security toolkit that brings static analysis (SAST) and dynamic analysis (DAST) together under a single interface. It is built for security researchers and mobile pentesters who need to quickly fingerprint a target's technology stack, audit its source for known-bad patterns, and interact with a live device — all without juggling a dozen separate tools.

The engine ships as a containerized web application, exposing a browser-based dashboard (http://localhost:3000) backed by a Node.js/TypeScript analysis core.


✨ Key Features

CategoryCapability
Technology DetectionAutomatic identification of the underlying framework — React Native, Flutter, Xamarin, .NET MAUI, Cordova, or native iOS/Android
Static Analysis (SAST)Rule-based scanning engine driven by customizable JSON rule-sets for deep code auditing
Security Posture DetectionHeuristic regex engine that flags active protections such as root/jailbreak detection, SSL pinning, and debug/anti-tamper checks
Secret ScanningDetection of hardcoded credentials, API keys, and other sensitive strings embedded in app code
Permission & Manifest AuditingParsing of Android manifests and app permissions for over-privileged or risky declarations
Android Toolkit (ADB)Full ADB integration for package extraction and direct exploration of /data/data/ app storage
iOS ToolkitUSB/SSH connectivity to jailbroken devices via libimobiledevice, with automatic device detection
App EnumerationCross-platform listing of installed apps (bundle ID, package name, version)
Container & Sandbox MappingAutomatic resolution of app sandbox paths — Documents, Library, Preferences, Caches
IPA ExtractionOn-device IPA extraction with automatic Payload structure rebuilding and fast SFTP download
Live Log MonitoringReal-time Logcat streaming with custom filters for surgical debugging
Smart Tool SuggestionsContext-aware recommendations of external security tools based on the detected stack

🏗️ Architecture

Slythestx is organized around two core pillars: analyzers (static, tech-stack aware inspection modules) and device drivers (dynamic interaction with connected iOS/Android hardware).


🧩 Analyzer Suite

Each analyzer plugs into the core engine and runs when its corresponding technology is detected, keeping scans fast and noise-free.

AnalyzerTarget StackPurpose
technologyDetectorAllFingerprints the app's underlying framework
appInfoAnalyzerAllExtracts general app metadata
manifestAnalyzerAndroidParses AndroidManifest.xml
permissionAnalyzerAndroid / iOSAudits declared permissions
securityMeasuresAnalyzerAllDetects root/jailbreak checks, SSL pinning, anti-debug logic
secretScannerAllScans source and binaries for hardcoded secrets
nativeAnalyzerNative iOS/AndroidAnalyzes native code paths
reactAnalyzerReact NativeReact Native-specific static analysis
flutterAnalyzerFlutterFlutter-specific static analysis
xamarinAnalyzerXamarinXamarin-specific static analysis
dotnetMauiAnalyzer.NET MAUI.NET MAUI-specific static analysis
cordovaAnalyzerCordova/PhoneGapCordova-specific static analysis

🚀 Quick Start

Prerequisites

  • Docker & Docker Compose
  • Node.js v18+
  • Python 3.10+
  • (iOS analysis) A jailbroken iOS device with SSH enabled, or USB connectivity via libimobiledevice
  • (Android analysis) ADB enabled on the target device

Installation

# Clone the repository
git clone https://github.com/stuxctf/slythestx/
cd slythestx

# --- Windows ---
docker-compose.exe -f docker-compose.yml -f docker-compose.windows.yml build

# --- Linux ---
docker-compose -f docker-compose.yml -f docker-compose.linux.yml build

# Launch the engine
docker-compose up -d

Access the Dashboard

Once the containers are running, open your browser at:

http://localhost:3000

🖥️ Usage

  1. Connect a device — plug in an Android device with USB/WiFi debugging enabled, or an iOS device (USB or SSH for jailbroken devices).
  2. Enumerate apps — Slythestx lists installed applications with bundle/package ID, name, and version.
  3. Extract & analyze — pull the APK/IPA, or explore the app's sandbox directly, and let the technology detector route the package to the right analyzers.
  4. Review findings — inspect detected security measures, flagged secrets, permission issues, and SAST rule matches from the dashboard.
  5. Go dynamic — tail live device logs, browse the app's data container, or invoke suggested external tools for deeper manual testing.

📌 Release & Versioning

🟢 v1.0.2_PUBLIC_ALPHA — Darkapple

Download Tool