
Mobile-Security-Framework-MobSF
Automated mobile application security testing framework for Android, iOS, and Windows. Performs static and dynamic analysis, malware detection, and…

Automated mobile application security testing framework for Android, iOS, and Windows. Performs static and dynamic analysis, malware detection, and…

Cross-platform library to parse, modify, and abstract ELF, PE, and MachO executable formats. Supports C++, Python, and Rust APIs with disassembler,…

The Mobile App Pentest cheat sheet was created to provide concise collection of high value information on specific mobile application penetration…

An effort to build a single place for all useful android and iOS security related stuff. All references and tools belong to their respective owners.…

Radare2 and Frida better together.

A tool that helps you easy trace classes, functions, and modify the return values of methods on iOS platform

A curated list of awesome iOS application security resources.

VSCode extension for Frida-based mobile reverse engineering: runtime class/module inspection, Java/ObjC/native hook generation, autocomplete, and…

mobsfscan is a static analysis tool that can find insecure code patterns in your Android and iOS source code. Supports Java, Kotlin, Swift, and…

An IDA Toolkit for analyzing iOS kernelcaches.

cerberus-re is a local Apple-focused reverse-engineering workbench for building a repeatable three-headed static/dynamic/instrumentation loop around…

An IDA Toolkit for analyzing iOS kernelcaches.

AI-driven vulnerability discovery and live validation

A powerful decompiler that lets you reverse-engineer React Native mobile apps by converting their compiled Hermes bytecode (.hbc) files back into…

Analysis of CVE-2025-43529 (WebKit UAF) + CVE-2025-14174 (ANGLE OOB) exploit chain - iOS Safari

Arcane is a simple script designed to backdoor iOS packages (iphone-arm) and create the necessary resources for APT repositories.

Glass - a fast and free IDA Pro alternative

ELEGANTBOUNCER is a detection tool for file-based mobile exploits.