
grapefruit
Open-source mobile security testing suite for iOS and Android. Previously Passionfruit

Open-source mobile security testing suite for iOS and Android. Previously Passionfruit


A collection of my Frida instrumentation scripts to reverse engineer mobile apps and more.

A powerful decompiler that lets you reverse-engineer React Native mobile apps by converting their compiled Hermes bytecode (.hbc) files back into…

Extract the managed (.NET) assemblies out of a MAUI Android assembly store.

Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…

Automated Penetration Testing Framework - Open-Source Vulnerability Scanner - Vulnerability Management

The Mobile App Pentest cheat sheet was created to provide concise collection of high value information on specific mobile application penetration…

Automatic SQL injection and database takeover tool

Automatic SSTI detection tool with interactive interface

Fast YAML-based vulnerability scanner with template-driven detection engine for automated security testing across web apps, APIs, networks, DNS, and…

Fast, multi-probe HTTP toolkit for reconnaissance and information gathering. Probes TLS, CSP, headers, tech stack, and CDN. Supports matchers,…

Self-hosted WAF and reverse proxy that filters malicious HTTP traffic, blocks SQL injection, XSS, and bot attacks, with rate limiting and dynamic…


A next-generation crawling and spidering framework.

A fast, simple, recursive content discovery tool written in Rust.

Web vulnerability scanner written in Python3