
dexfinder
Cross-platform APK/DEX method finder with call chain tracing, ProGuard deobfuscation, and hidden API detection

Cross-platform APK/DEX method finder with call chain tracing, ProGuard deobfuscation, and hidden API detection

Blue Pigeon is a Bluetooth-based data exfiltration and proxy tool to enable communication between a remote Command and Control (C2) server and a…

Android client for Adaptix C2 framework enabling remote agent management, interactive command shells, listener control, payload generation, and…

Writeup and exploit for CVE-2024-49746: Android's Parcel::continueWrite closing File Descriptors that are later used

Extracts and investigates infrastructure (IPs, domains) from APK files, with manifest parsing and WHOIS lookup for mobile application reconnaissance.

A tool that enumerates Android devices for information useful in understanding its internals and for exploit development. It supports android 4.2 to…


Educational reverse engineering study of a Unity/IL2CPP Android game. Documents gateway protocol decoding, native anti-tampering SDK analysis, SSL…

JADX plugin that extracts method names, class references, and source file paths from string constants found in DEX files and decompiled Android code.

Android deeplink, Intent, and WebView bridge assessment helper for ethical hacking

A tool that automates the mundane tasks of pentesting Android apps. It uses APKTool and Dex2Jar.

Technical analysis and safety-conscious research harness for CVE-2019-6447 in ES File Explorer for Android

This package is not a complete root. It flips SELinux to Permissive and holds reclaim long enough for follow-on work. Host `uid=0` is not achieved…

Open-source Android client for VirusTotal. Scan files, URLs, and installed apps against 70+ antivirus engines. View detailed reports with hashes,…

AndroRAT is a capability that can be used to inject a root exploit as a silent installation to perform a malicious task on the device. This AndroRAT…

The official Sentinel Edition v7.11 - Hypervisor Detection & Kernel Memory Audit Suite for Honor Magic V2. Investigating CVE-2025-38352 and EL2 RKP…

Proof of concept code to exploit flaw in adb that allowed opening network connections on the host to arbitrary destinations

🔗 Lightweight security orchestrator mobile application for URI vetting, providing a unified, multi-engine interface to aggregate and validate link…