
Evil-Droid
Framework to create, generate, and embed APK payloads for Android penetration testing, leveraging Metasploit for exploitation and Apktool for…

Framework to create, generate, and embed APK payloads for Android penetration testing, leveraging Metasploit for exploitation and Apktool for…

PoC for CVE-2021-39749, allowing starting arbitrary Activity on Android 12L Beta

Rust components for traffic interception and redirection, enabling WireGuard device proxying and local app redirection across macOS, Windows, and…

Command-line tool that allows searching and downloading app packages (known as ipa files) for iOS, iPadOS, tvOS, and visionOS from the App Store.

UNIX-like reverse engineering framework and command-line toolset

Frida-powered runtime mobile exploration toolkit for assessing iOS and Android app security. Bypass SSL pinning, dump keychains, manipulate heap…

Mobile Helper Framework (mhf) is a tool that automates the process of identifying the framework/technology used to create a mobile application.…

Runtime Mobile Security (RMS) 📱🔥 - is a powerful web interface that helps you to manipulate Android and iOS Apps at Runtime

The Mobile App Pentest cheat sheet was created to provide concise collection of high value information on specific mobile application penetration…

🤖 A CLI application that automatically prepares Android APK files for HTTPS inspection

Android Package Inspector - dynamic analysis with api hooks, start unexported activities and more. (Xposed Module)

A curated list of Android Security materials and resources For Pentesters and Bug Hunters

Extracts app settings, permissions, deeplinks, and SSL pinning bypass suggestions from Android APK files via static analysis of AndroidManifest.xml,…

Educational demonstration of CVE-2024-31317 Zygote Injection Vulnerability on Android

Frida scripts to rewrite mobile applications at runtime to directly MitM all HTTPS traffic

SecurityExplained is a new series after the previous learning challenge series #Learn365. The aim of #SecurityExplained series is to create…

Exploit I discovered in October of 2022 with androids Package manager binary (pm) and the way it handled debugging flags, patched out by march 2023.…

Cross-platform library to parse, modify, and abstract ELF, PE, and MachO executable formats. Supports C++, Python, and Rust APIs with disassembler,…