
Mandela-Classic
iOS customization app powered by CVE-2022-46689. No jailbreak required.

iOS customization app powered by CVE-2022-46689. No jailbreak required.

Frida-powered runtime mobile exploration toolkit for assessing iOS and Android app security. Bypass SSL pinning, dump keychains, manipulate heap…

Blackbox tool to disable SSL certificate validation - including certificate pinning - within iOS and macOS applications.

Open-source mobile security testing suite for iOS and Android. Previously Passionfruit

Damn Vulnerable iOS App (DVIA) is an iOS application that is damn vulnerable. Its main goal is to provide a platform to mobile security…

Comprehensive OWASP guide for mobile app security testing, reverse engineering, and verifying MASVS/MASWE weaknesses through static, dynamic, and…

Unofficial frida extension for VSCode

Automated mobile application security testing framework for Android, iOS, and Windows. Performs static and dynamic analysis, malware detection, and…

Runtime Mobile Security (RMS) 📱🔥 - is a powerful web interface that helps you to manipulate Android and iOS Apps at Runtime

idb is a tool to simplify some common tasks for iOS pentesting and research

Proof-of-concept app to overwrite fonts on iOS using CVE-2022-46689.

iOS Application w/Implementation of CVE-2024-27804

Next Generation SSLKillSwitch with much more support!

Command-line and GUI tool for decompiling Android Dex and APK files into readable Java source code, with resource decoding, deobfuscation, and Smali…

An interactive TLS-capable intercepting HTTP proxy for penetration testers and software developers.

A tool for reverse engineering Android apk files

Main repo for hosting release binaries

Tools to work with android .dex and java .class files