
Evil-Droid
Framework to create, generate, and embed APK payloads for Android penetration testing, leveraging Metasploit for exploitation and Apktool for…

Framework to create, generate, and embed APK payloads for Android penetration testing, leveraging Metasploit for exploitation and Apktool for…

Intentionally vulnerable Android banking app for practicing mobile security testing, featuring root detection, anti-debugging, SSL pinning, and…

Unofficial frida extension for VSCode

Binder Trace is a tool for intercepting and parsing Android Binder messages. Think of it as "Wireshark for Binder".

OWASP iGoat (Swift) - A Damn Vulnerable Swift Application for iOS

Fermion, an electron wrapper for Frida & Monaco.

Django application that performs SAST and Malware Analysis for Android APKs

MCP server plugin for JEB Pro that enables AI-assisted decompilation, method/field inspection, and automated renaming during APK reverse engineering.

The ARTful library for dynamically modifying the Android Runtime

Intentionally vulnerable hybrid Android app for security professionals to test tools and techniques, and for developers to learn common hybrid mobile…

Penetration testing and auditing toolkit for Android apps.

An open source Android application that is intentionally vulnerable so as to act as a learning platform for Android application security beginners.

Tool for finding URLs, paths, secrets and generating raw HTTP requests and OpenApi specifications from config files and annotations used in JAR / WAR…

PulseAPK Core: Cross-Platform tool for working with APK files: Decompilation, Analysis, Building

Magisk module for Android 14 that adds user-installed CA certificates to the system's Conscrypt trust store, enabling HTTPS interception with proxy…

Android penetration testing tool for Kali linux

LD_PRELOAD magic for Android's AssetManager

PulseAPK is a WPF frontend for apktool and uber-signer with drag-and-drop support, live decompilation output, smali analysis, and integrated APK…