
radare2
UNIX-like reverse engineering framework and command-line toolset

UNIX-like reverse engineering framework and command-line toolset

Static code analysis tool for Android apps based on OWASP MASVS, detecting security vulnerabilities in APK files with low false-positive rates and…

Ghidra is a software reverse engineering (SRE) framework

Patches Flutter engine libraries to enable runtime reverse engineering, traffic interception, and SSL pinning bypass for Android and iOS apps without…

Automated mobile application security testing framework for Android, iOS, and Windows. Performs static and dynamic analysis, malware detection, and…

PoC and red team app for CVE-2026-28576, a zero-permission SQL injection in the Android Contacts Provider enabling full contacts database…

An easy-to-learn/use static analysis framework for Java and Android

Frida-powered runtime mobile exploration toolkit for assessing iOS and Android app security. Bypass SSL pinning, dump keychains, manipulate heap…

C-based Android static analysis framework for decompilation, secret detection, endpoint discovery, permission analysis, and native library scanning…

CVE-2025-48595 Android Framework Integer Overflow PoC - 优化版

Mobile Reconnaissance Framework is a powerful, lightweight and platform-independent offensive mobile security tool designed to help hackers and…

Official code for the ISSTA 2026 paper: Is "Knowing It’s Malicious" Enough? Evaluating LLMs for Fine-Grained Malware Behavior Auditing

Memory-free continual learning framework for malware classification using mode connectivity-based interpolation. Supports class-incremental and…

Modular Android APK security analysis framework integrating static, dynamic, and reverse engineering tools for comprehensive vulnerability assessment…

PoC de CVE-2025-48595: desbordamiento de entero en multiples ubicaciones del Framework de Android.

The Leading Security Assessment Framework for Android.

Android client for Adaptix C2 framework enabling remote agent management, interactive command shells, listener control, payload generation, and…

Android deeplink misconfiguration detector and exploitation tool