
aotopsy
Static analyzer for Flutter/Dart AOT snapshots — recovers function names, class hierarchies, call graphs, and behavioral signals from libapp.so…

Static analyzer for Flutter/Dart AOT snapshots — recovers function names, class hierarchies, call graphs, and behavioral signals from libapp.so…

Python PoC for CVE-2026-18907 path traversal in TECNO Hi Browser's download handler. Includes malicious HTTP server and naive downloader to…


Educational Android lab for CVE-2023-31014 implicit intent hijacking

Educational Android lab for CVE-2020-23349 in Sina Weibo SDK 4.2.7

Android penetration testing tool for Kali linux

VSCode extension for Frida-based mobile reverse engineering: runtime class/module inspection, Java/ObjC/native hook generation, autocomplete, and…

Fermion, an electron wrapper for Frida & Monaco.

SecurityExplained is a new series after the previous learning challenge series #Learn365. The aim of #SecurityExplained series is to create…

The ARTful library for dynamically modifying the Android Runtime

The repo contains a series of challenges for learning Frida for Android Exploitation.

Binder Trace is a tool for intercepting and parsing Android Binder messages. Think of it as "Wireshark for Binder".

Tool for finding URLs, paths, secrets and generating raw HTTP requests and OpenApi specifications from config files and annotations used in JAR / WAR…


LD_PRELOAD magic for Android's AssetManager

Blackbox Protobuf is a set of tools for working with encoded Protocol Buffers (protobuf) without the matching protobuf definition.

Utility to decrypt App Store apps on jailbroken iOS 11.x