
masvs
The OWASP MASVS (Mobile Application Security Verification Standard) is the industry standard for mobile app security.

The OWASP MASVS (Mobile Application Security Verification Standard) is the industry standard for mobile app security.

Open-source mobile security testing suite for iOS and Android. Previously Passionfruit

Repository for the Smartphone Pentest Framework (SPF)

Bluetooth keystroke injection exploit PoCs for CVE-2023-45866, CVE-2024-21306, and CVE-2024-0230 targeting Android, Linux, macOS, and iOS via…

idb is a tool to simplify some common tasks for iOS pentesting and research

Unofficial frida extension for VSCode

OWASP iGoat (Swift) - A Damn Vulnerable Swift Application for iOS

Universal mobile devtool for Agents & Humans - control iOS Simulators, Android Emulators, and real devices from a single dashboard and CLI

a Ghidra framework for iOS kernelcache reverse engineering

Encrypted peer-to-peer mesh VPN for remote mobile forensics, enabling wireless ADB and libimobiledevice acquisition, network monitoring, and…

AI-driven CLI for testing Android and iOS apps using natural language. Generates, runs, and fixes end-to-end tests on emulators/simulators with…

Linux Distro for Mobile Security, Malware Analysis, and Forensics

Arcane is a simple script designed to backdoor iOS packages (iphone-arm) and create the necessary resources for APT repositories.

Memory modification tool for re-signed ipa supports iOS apps running on iPhone and Apple Silicon Mac without jailbreaking.

Static analysis tool for Android/iOS apps focusing on security issues outside the source code

Ghidra extension bridging static and dynamic analysis via Frida, enabling scriptable runtime instrumentation for reverse engineering binaries on…

This is POC for IOS 0click CVE-2025-43300

Agentic C2-style MCP server for Frida instrumentation on rooted Android and jailbroken iOS.