
mobileAudit
Django application that performs SAST and Malware Analysis for Android APKs

Django application that performs SAST and Malware Analysis for Android APKs

app that ports CVE-2019-2215 to arm32 and mounts a su binary to /sbin with denylist + root app installer. firehose/Magisk guide included

Android reverse engineering entirely on-device. Radare2 binary analysis, 8 Java decompilers, Flutter & Unity il2cpp support.

Decompiles Android APK/XAPK/JAR/AAR files and extracts HTTP APIs, authentication patterns, and call flows using jadx, with R8-resistant Kotlin name…

Educational demonstration of CVE-2024-31317 Zygote Injection Vulnerability on Android

Mobile Helper Framework (mhf) is a tool that automates the process of identifying the framework/technology used to create a mobile application.…

An intentionally vulnerable Android Application to demonstrate various vulnerabilities that airses in Android Components.

Fermion, an electron wrapper for Frida & Monaco.

a vulnerability affecting Android version 12 & 13

Damn Vulnerable iOS App (DVIA) is an iOS application that is damn vulnerable. Its main goal is to provide a platform to mobile security…

Exploit I discovered in October of 2022 with androids Package manager binary (pm) and the way it handled debugging flags, patched out by march 2023.…


Static analysis tool for iOS applications that extracts links, API keys, subdomains, binary info, linked libraries, and strings to aid mobile…

Android APK unpacker that dumps DEX files from running or installed apps on Android 5.0–12 without root, Xposed, or Frida, supporting deep unpacking…

LD_PRELOAD magic for Android's AssetManager

A vulnerable Android application that shows simple examples of vulnerabilities in a ctf style.

fsp - Firestore Database Vulnerability Scanner Using APKs

A tool that automates the mundane tasks of pentesting Android apps. It uses APKTool and Dex2Jar.