
ja4
JA4+ is a suite of network fingerprinting standards

JA4+ is a suite of network fingerprinting standards

C-based Android static analysis framework for decompilation, secret detection, endpoint discovery, permission analysis, and native library scanning…

Analysis and cleanup guide for BadBox malware on Allwinner H713 Android projectors: ADB access, infection proof, firmware backup, dropper removal,…

Open-source Android client for VirusTotal. Scan files, URLs, and installed apps against 70+ antivirus engines. View detailed reports with hashes,…

Malwoverview is a first response tool for threat hunting across VirusTotal, Hybrid Analysis, URLHaus, Polyswarm, Malshare, Alien Vault, Malpedia,…

JADX plugin that extracts method names, class references, and source file paths from string constants found in DEX files and decompiled Android code.

A Android malware analysis tool that creates comprehensive runtime profiles by hooking into application behavior across cryptography, file systems,…

Mobile Edge-Dynamic Unified Security Analysis

Scalable threat intelligence platform that enriches observables and files using 200+ analyzers, with built-in GUI, REST API, and automated workflows…

Automated pre-analysis tool for Android apps that disassembles samples, extracts properties via configurable pattern matching, and organizes output…

Automated bug bounty & recon framework — wraps Subfinder, Naabu, Httpx, Nuclei, Nmap, CVEMap, Gowitness, Katana & more behind a unified web UI

Android Malware Tracker

Suspicious DGA from PDNS and Sandbox.

Dynamic analysis sandbox for Android apps that monitors network traffic, file operations, cryptographic API usage, permission circumvention, and…

This is part of a module for the framework that i'm constantly developing. Currently only information of the C2 are disclosed here.

Simple framework to extract "actionable" data from Android malware (C&Cs, phone numbers etc.)