
MobileApp-Pentest-Cheatsheet
The Mobile App Pentest cheat sheet was created to provide concise collection of high value information on specific mobile application penetration…

The Mobile App Pentest cheat sheet was created to provide concise collection of high value information on specific mobile application penetration…

Fermion, an electron wrapper for Frida & Monaco.

Proof Of Concept for Android. NoFrak is designed to prevent fracking attacks, as described in "Breaking and Fixing Origin-Based Access Control in…

ADT is a toolset designed to help model application behavior, research and test security vulnerabilities, and facilitate reversing hostile code.

A PoC application demonstrating the power of an Android kernel arbitrary R/W.

CVE-2026-12960 - Improper Export of Android Application Components in the ASUS Router app (com.asus.aihome). PoC, exploit APK, video, and vendor…

A deliberately vulnerable mobile banking application designed for practicing mobile security testing. Features common vulnerabilities found in…

Improper Hostname Verification in EagleEyes Lite Android Application

Cleartext Transmission of Sensitive Information in EagleEyes Lite Android Application

I'll submit the poc after blackhat

Improper Certificate Chain Validation in EagleEyes Lite Android Application


Android deeplink, Intent, and WebView bridge assessment helper for ethical hacking


CVE-2024-23729

Agentic C2-style MCP server for Frida instrumentation on rooted Android and jailbroken iOS.

Public advisory & PoC for CVE-2026-26897 — Deep Link Bypass in EcoOnline EHS Android (com.airsweb.v10), fixed in 0.2.500

🔗 Lightweight security orchestrator mobile application for URI vetting, providing a unified, multi-engine interface to aggregate and validate link…