
aotopsy
Static analyzer for Flutter/Dart AOT snapshots — recovers function names, class hierarchies, call graphs, and behavioral signals from libapp.so…

Static analyzer for Flutter/Dart AOT snapshots — recovers function names, class hierarchies, call graphs, and behavioral signals from libapp.so…

Python PoC for CVE-2026-18907 path traversal in TECNO Hi Browser's download handler. Includes malicious HTTP server and naive downloader to…


Educational Android lab for CVE-2023-31014 implicit intent hijacking

Educational Android lab for CVE-2020-23349 in Sina Weibo SDK 4.2.7

A flexible playground for Android CTF challenges.

Django application that performs SAST and Malware Analysis for Android APKs

PulseAPK Core: Cross-Platform tool for working with APK files: Decompilation, Analysis, Building

A curated list of Android Security materials and resources For Pentesters and Bug Hunters

VSCode extension for Frida-based mobile reverse engineering: runtime class/module inspection, Java/ObjC/native hook generation, autocomplete, and…

Android deeplink, Intent, and WebView bridge assessment helper for ethical hacking

Decompiles Android APK/XAPK/JAR/AAR files and extracts HTTP APIs, authentication patterns, and call flows using jadx, with R8-resistant Kotlin name…

PulseAPK is a WPF frontend for apktool and uber-signer with drag-and-drop support, live decompilation output, smali analysis, and integrated APK…

Blackbox Protobuf is a set of tools for working with encoded Protocol Buffers (protobuf) without the matching protobuf definition.

the fastest and most powerful android decompiler(native tool working without Java VM) for the APK, DEX, ODEX, OAT, JAR, AAR, and CLASS file. which…

The Leading Security Assessment Framework for Android.

Robust Frida-based tool to dump decrypted iOS apps as .ipa from a jailbroken device supports App Store, sideloaded and system.