
raptor
Web-based Source Code Vulnerability Scanner

一款适用于以HW行动/红队/渗透测试团队为场景的移动端(Android、iOS、WEB、H5、静态网站)信息收集扫描工具,可以帮助渗透测试工程师、攻击队成员、红队成员快速收集到移动端或者静态WEB站点中关键的资产信息并提供基本的信息输出,如:Title、Domain、CDN、指纹信息、状态信息等。

iblessing is an iOS security exploiting toolkit, it mainly includes application information gathering, static analysis and dynamic analysis. It can…

Universal mobile devtool for Agents & Humans - control iOS Simulators, Android Emulators, and real devices from a single dashboard and CLI

CVE-2026-82090 · CVSS 9.2 CRITICAL · 0-click stored XSS in Mozilla Pocket — all versions (v0 → v8.33.0.0) · 18-year forever-day · no patch · MITRE…

Main repo for hosting release binaries

Automated mobile application security testing framework for Android, iOS, and Windows. Performs static and dynamic analysis, malware detection, and…

Comprehensive OWASP guide for mobile app security testing, reverse engineering, and verifying MASVS/MASWE weaknesses through static, dynamic, and…

Forensic collection and analysis toolkit for Android and iOS devices to identify potential compromise by known spyware using public and private…

Cross-platform library to parse, modify, and abstract ELF, PE, and MachO executable formats. Supports C++, Python, and Rust APIs with disassembler,…

The Mobile App Pentest cheat sheet was created to provide concise collection of high value information on specific mobile application penetration…

An effort to build a single place for all useful android and iOS security related stuff. All references and tools belong to their respective owners.…

Generate Objective-C headers from Mach-O files.

iOS/macOS/Linux Remote Administration Tool

A collection of my Frida instrumentation scripts to reverse engineer mobile apps and more.

Open-source mobile security testing suite for iOS and Android. Previously Passionfruit

A tool that helps you easy trace classes, functions, and modify the return values of methods on iOS platform

Unofficial frida extension for VSCode