
InjuredAndroid
A vulnerable Android application that shows simple examples of vulnerabilities in a ctf style.

A vulnerable Android application that shows simple examples of vulnerabilities in a ctf style.

Automated mobile application security testing framework for Android, iOS, and Windows. Performs static and dynamic analysis, malware detection, and…

Android Package Inspector - dynamic analysis with api hooks, start unexported activities and more. (Xposed Module)

Static analysis tool for iOS applications that extracts links, API keys, subdomains, binary info, linked libraries, and strings to aid mobile…

Hooker is an opensource project for dynamic analyses of Android applications. This project provides various tools and applications that can be use to…

iOS 15 0-day exploit (still works in 15.0.2)

Ghidra is a software reverse engineering (SRE) framework

An interactive TLS-capable intercepting HTTP proxy for penetration testers and software developers.

Tools to work with android .dex and java .class files

Decompiles Android APK/XAPK/JAR/AAR files and extracts HTTP APIs, authentication patterns, and call flows using jadx, with R8-resistant Kotlin name…

Cross-platform library to parse, modify, and abstract ELF, PE, and MachO executable formats. Supports C++, Python, and Rust APIs with disassembler,…

A curated list of Android Security materials and resources For Pentesters and Bug Hunters


Scanning APK file for URIs, endpoints & secrets.

Open-source Android client for browsing and downloading apps from Google Play with anonymous login, device/locale spoofing, and tracker detection.

Open-source mobile security testing suite for iOS and Android. Previously Passionfruit

Android security guides, roadmap, docs, courses, write-ups, and teryaagh.

Rust components for traffic interception and redirection, enabling WireGuard device proxying and local app redirection across macOS, Windows, and…