
zaproxy
Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…

Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…

UNIX-like reverse engineering framework and command-line toolset

Comprehensive OWASP guide for mobile app security testing, reverse engineering, and verifying MASVS/MASWE weaknesses through static, dynamic, and…

Manage WhatsApp .crypt12, .crypt14 and .crypt15 files.

Non-decompiling iOS/Android app vulnerability scanner (DC25 demo lab, CB17)

Android Antivirus which doesn't require root, adb, ca install and cloud with many features and ways to detect more zero-day malware

Django application that performs SAST and Malware Analysis for Android APKs

Glass - a fast and free IDA Pro alternative

mobsfscan is a static analysis tool that can find insecure code patterns in your Android and iOS source code. Supports Java, Kotlin, Swift, and…

Plugin for JADX to integrate MCP server

Mobile app security auditing tool focused on automating SAST analysis, identifying underlying technologies (React Native, Flutter, Xamarin, native),…

A Magisk module that simplifies running the Frida server on Android, with easy management commands to download specific versions, enable or disable…

FluxER - The bash script which installs and runs the Fluxion tool inside Termux. The wireless security auditing tool used to perform WPA/WPA2…

translating original python exploit to C

WPair is a defensive security research tool that demonstrates the CVE-2025-36911 (eg WhisperPair) vulnerability in Google's Fast Pair protocol. This…

Curated collection of security conference slide decks covering Android rooting, kernel exploitation, browser memory corruption, JIT mitigations, and…

CVE-2025-48593

Static code analysis tool for Android apps based on OWASP MASVS, detecting security vulnerabilities in APK files with low false-positive rates and…