
frida-ios-dump
Extracts decrypted IPA files from jailbroken iOS devices using Frida for reverse engineering, security analysis, and mobile app pentesting.

Extracts decrypted IPA files from jailbroken iOS devices using Frida for reverse engineering, security analysis, and mobile app pentesting.

Kernel module for volatile memory acquisition from Linux and Android devices, producing forensically sound captures to disk or over the network.

Digital forensics engine that parses logs, files, and system artifacts to build super timelines, enabling chronological event correlation for…

Collaborative forensic timeline analysis platform for ingesting, searching, and annotating event logs to support incident response and DFIR…

Forensic collection and analysis toolkit for Android and iOS devices to identify potential compromise by known spyware using public and private…

Parses iOS and iPadOS forensic extractions into HTML, TSV, timeline, KML, and LAVA reports with modular artifact discovery and encrypted iTunes…


QCSuper is a tool communicating with Qualcomm-based phones and modems, allowing to capture raw 2G/3G/4G radio frames, among other things.

ELEGANTBOUNCER is a detection tool for file-based mobile exploits.

Android Connections Forensics

Manage WhatsApp .crypt12, .crypt14 and .crypt15 files.

Utility for recovering ES File Explorer encrypted files (.eslock)


Linux Distro for Mobile Security, Malware Analysis, and Forensics

This is the development tree. Production downloads are at:



Extract a concerning amount of user information from Unisoc ZTE devices using CVE-2022-38694.