
DongTai
Open-source Interactive Application Security Testing (IAST) tool that passively instruments Java applications to detect vulnerabilities and…

Open-source Interactive Application Security Testing (IAST) tool that passively instruments Java applications to detect vulnerabilities and…

Automated mobile application security testing framework for Android, iOS, and Windows. Performs static and dynamic analysis, malware detection, and…

Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…

Firmware Analysis and Comparison Tool

Web application security scanner created by lcamtuf for google - Unofficial Mirror

Agentic C2-style MCP server for Frida instrumentation on rooted Android and jailbroken iOS.

Information flow analysis tool for Android applications

Web-based tool for browsing mobile application sandboxes, previewing SQLite databases and binary files, and downloading app data via Frida…

Comprehensive OWASP guide for mobile app security testing, reverse engineering, and verifying MASVS/MASWE weaknesses through static, dynamic, and…

A lightweight sandboxing tool for enforcing filesystem and network restrictions on arbitrary processes at the OS level, without requiring a container.

Some good resources for getting started with application security

Jackhammer - One Security vulnerability assessment/management tool to solve all the security team problems.

Stage two containers

Web Application Security Scanner Framework

Fermion, an electron wrapper for Frida & Monaco.

Static and dynamic Android application security analysis

Full-stack platform for authorized web application security scanning with a detector-based engine, async Celery workers, and a React dashboard for…

Security profiling for blackbox iOS