
truegaze
Static analysis tool for Android/iOS apps focusing on security issues outside the source code

Static analysis tool for Android/iOS apps focusing on security issues outside the source code

The above investigation of the ES file browser security weakness allows us to see the issue in its entirety

Extract endpoints from apk files.

Penetration testing and auditing toolkit for Android apps.

CVE-2024-0044: a "run-as any app" high-severity vulnerability affecting Android versions 12 and 13

Python exploit for CVE-2019-6447 enabling arbitrary file read on ES File Explorer 4.1.9.7.4 for Android. Demonstrates mobile vulnerability…

Exploiting Android Vulnerability in ES File Explorer

backdoor-apk is a shell script that simplifies the process of adding a backdoor to any Android APK file. Users of this shell script should have…

Scanning APK file for URIs, endpoints & secrets.

Builds flashable installer ZIPs that deploy a mobile penetration-testing environment on Android, including kernel boot patching, rootfs integration,…

the fastest and most powerful android decompiler(native tool working without Java VM) for the APK, DEX, ODEX, OAT, JAR, AAR, and CLASS file. which…

All-in-One malware analysis tool.

Python script to generate a malicious MP4 file and start a CherryPy web server hosting a simple HTML page with the embedded file. Exploits another…

Android Remote Access Trojan

Extracts app settings, permissions, deeplinks, and SSL pinning bypass suggestions from Android APK files via static analysis of AndroidManifest.xml,…

Utility for recovering ES File Explorer encrypted files (.eslock)

In-depth analysis and proof-of-concept for CVE-2026-27280, an out-of-bounds write in Adobe DNG SDK's dng_render_task::ProcessArea, reachable via…

JADX plugin that extracts method names, class references, and source file paths from string constants found in DEX files and decompiled Android code.