
vuln-bank-mobile
A deliberately vulnerable mobile banking application designed for practicing mobile security testing. Features common vulnerabilities found in…

A deliberately vulnerable mobile banking application designed for practicing mobile security testing. Features common vulnerabilities found in…

Install and run Metasploit Framework 6 on Android via Termux with automated setup, payload generation (msfvenom), and full msfconsole access for…

Repository for the Smartphone Pentest Framework (SPF)

The Mobile App Pentest cheat sheet was created to provide concise collection of high value information on specific mobile application penetration…

Modular Android APK security analysis framework integrating static, dynamic, and reverse engineering tools for comprehensive vulnerability assessment…

Android exploit collection with C-based payloads for mobile device penetration testing and security research.

Frida scripts for mobile application dynamic-analysis.

Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…

Decompiles Android APK/XAPK/JAR/AAR files and extracts HTTP APIs, authentication patterns, and call flows using jadx, with R8-resistant Kotlin name…

Educational Android (Termux) toolkit for learning penetration testing, OSINT, social engineering, and network security through hands-on scripts,…

Framework to create, generate, and embed APK payloads for Android penetration testing, leveraging Metasploit for exploitation and Apktool for…

MARA is a Mobile Application Reverse engineering and Analysis Framework. It is a toolkit that puts together commonly used mobile application reverse…

Automated Android backdoor generator with crypter, IP poisoning, and Metasploit payload integration for penetration testing and red team operations.

Penetration testing and auditing toolkit for Android apps.

Android penetration testing tool for Kali linux

Aircrack, Airodump, Aireplay, MDK3 and Reaver GUI Application for Android

Frida-powered runtime mobile exploration toolkit for assessing iOS and Android app security. Bypass SSL pinning, dump keychains, manipulate heap…

The OWASP MASVS (Mobile Application Security Verification Standard) is the industry standard for mobile app security.