
PhoneSploit-Pro
An all-in-one hacking tool to remotely take over Android devices.

An all-in-one hacking tool to remotely take over Android devices.

Mobile app security auditing tool focused on automating SAST analysis, identifying underlying technologies (React Native, Flutter, Xamarin, native),…

An interactive TLS-capable intercepting HTTP proxy for penetration testers and software developers.

A native APK and DEX decompiler written in Rust

Natural-language Android automation agent that drives real devices via ADB, captures Logcat and screenshots, and exposes an MCP server for AI IDEs…

Main repo for hosting release binaries

Automated mobile application security testing framework for Android, iOS, and Windows. Performs static and dynamic analysis, malware detection, and…

Rust components for traffic interception and redirection, enabling WireGuard device proxying and local app redirection across macOS, Windows, and…

The reverse-engineering expert agent: plans its own analysis path, derives every fact from raw evidence, and converges under mechanical verification…

Fast Android APK decompiler front-end that queries compiled DEX artifacts directly, extracting classes and cross-references in milliseconds without…

Root an Android Studio emulator by patching its ramdisk with Magisk — in pure Go.

Open-source mobile security testing suite for iOS and Android. Previously Passionfruit

Blackbox tool to disable SSL certificate validation - including certificate pinning - within iOS and macOS applications.

Frida toolkit that bypasses SSL/TLS certificate pinning on Android apps, hooking Java TrustManager, OkHttp, Conscrypt, and native OpenSSL/BoringSSL…

OWASP hands-on Android security training lab with 78 MASVS/MASTG modules pairing vulnerable, secure, and attacker apps to demonstrate mobile…

Framework to create, generate, and embed APK payloads for Android penetration testing, leveraging Metasploit for exploitation and Apktool for…

Browser-local security monorepo with six modules for mobile APK/IPA triage, client-side DAST fuzzing, OSINT directories, offline AI threat scoring,…

An Android HW Attestation demo