
jadx-ai-mcp
Plugin for JADX to integrate MCP server

Plugin for JADX to integrate MCP server

Main repo for hosting release binaries

A security focused static analysis tool for Android and Java applications.

UNIX-like reverse engineering framework and command-line toolset

Ghidra is a software reverse engineering (SRE) framework

mobsfscan is a static analysis tool that can find insecure code patterns in your Android and iOS source code. Supports Java, Kotlin, Swift, and…

An easy-to-learn/use static analysis framework for Java and Android

Static taint analysis platform for Android apps that detects vulnerabilities and compliance issues using customizable rule-based scanning and…

A powerful decompiler that lets you reverse-engineer React Native mobile apps by converting their compiled Hermes bytecode (.hbc) files back into…

JADX plugin that extracts method names, class references, and source file paths from string constants found in DEX files and decompiled Android code.

Django application that performs SAST and Malware Analysis for Android APKs

Advisory and proof-of-concept for OS command injection in an MCP ffmpeg helper, with root-cause analysis, detector guidance, and mitigations for an…

Proof-of-concept exploit for authenticated OS command injection (CWE-78) in Cacti ≤1.2.30, achieving remote code execution with CVSS 7.2.

Official code for the ISSTA 2026 paper: Is "Knowing It’s Malicious" Enough? Evaluating LLMs for Fine-Grained Malware Behavior Auditing

A Java 8+ Jar & Android APK Reverse Engineering Suite (Decompiler, Editor, Debugger & More)

Detailed CVE-2026-39938 vulnerability report for Cacti ≤1.2.30, demonstrating unauthenticated LFI chained to OS command injection RCE with PoC, root…

Technical writeup and Proof of Concept (PoC) for CVE-2026-11417: OS Command Injection / Remote Code Execution (RCE) in AWS CDK's NodejsFunction.

PoC and writeup for CVE-2026-46394: OS command injection in HAXcms Git.php (CWE-78). Authorized security research only.