
DVIA-v2
Damn Vulnerable iOS App (DVIA) is an iOS application that is damn vulnerable. Its main goal is to provide a platform to mobile security…

Damn Vulnerable iOS App (DVIA) is an iOS application that is damn vulnerable. Its main goal is to provide a platform to mobile security…

A test app to check if your device is vulnerable to CVE-2021-30955

Runtime Mobile Security (RMS) 📱🔥 - is a powerful web interface that helps you to manipulate Android and iOS Apps at Runtime

Blackbox tool to disable SSL certificate validation - including certificate pinning - within iOS and macOS applications.

AI-driven CLI for testing Android and iOS apps using natural language. Generates, runs, and fixes end-to-end tests on emulators/simulators with…

Comprehensive OWASP guide for mobile app security testing, reverse engineering, and verifying MASVS/MASWE weaknesses through static, dynamic, and…

Frida-powered runtime mobile exploration toolkit for assessing iOS and Android app security. Bypass SSL pinning, dump keychains, manipulate heap…

The Mobile App Pentest cheat sheet was created to provide concise collection of high value information on specific mobile application penetration…

The OWASP MASVS (Mobile Application Security Verification Standard) is the industry standard for mobile app security.

Web-based tool for browsing mobile application sandboxes, previewing SQLite databases and binary files, and downloading app data via Frida…

Non-decompiling iOS/Android app vulnerability scanner (DC25 demo lab, CB17)

Mobile app security auditing tool focused on automating SAST analysis, identifying underlying technologies (React Native, Flutter, Xamarin, native),…

Wrapper to maximize ISH iOS app capabilities without jailbreak

Command-line tool that allows searching and downloading app packages (known as ipa files) for iOS, iPadOS, tvOS, and visionOS from the App Store.

Extracts decrypted IPA files from jailbroken iOS devices using Frida for reverse engineering, security analysis, and mobile app pentesting.

Jailbreak-only iOS utility that decrypts installed app executables and dumps them as .ipa or raw binary files for security research and…

A privacy-focused iOS app that raises awareness about what native apps can see

OWASP iGoat - A Learning Tool for iOS App Pentesting and Security by Swaroop Yermalkar