
Mobile-Security-Framework-MobSF
Automated mobile application security testing framework for Android, iOS, and Windows. Performs static and dynamic analysis, malware detection, and…

Automated mobile application security testing framework for Android, iOS, and Windows. Performs static and dynamic analysis, malware detection, and…

The IoT Security Testing Guide (ISTG) provides a comprehensive methodology for penetration tests in the IoT field, offering flexibility to adapt…

Comprehensive OWASP guide for mobile app security testing, reverse engineering, and verifying MASVS/MASWE weaknesses through static, dynamic, and…

An on-path blackbox network traffic security testing tool

The OWASP MASVS (Mobile Application Security Verification Standard) is the industry standard for mobile app security.

Autonomous AI red team agent for penetration testing with 13+ specialized agents, 120+ OWASP test cases, and MITRE ATT&CK integration. Supports 15+…

Web and mobile application security training platform

Static code analysis tool for Android apps based on OWASP MASVS, detecting security vulnerabilities in APK files with low false-positive rates and…

Deliberately insecure OpenWrt-based firmware for hands-on IoT security training. Features vulnerability challenges mapped to the OWASP IoT Top 10 for…


MARA is a Mobile Application Reverse engineering and Analysis Framework. It is a toolkit that puts together commonly used mobile application reverse…

Burp Plugin to decrypt AES encrypted traffic on the fly

This experimetal fuzzer is meant to be used for API in-memory fuzzing.

OWASP iGoat - A Learning Tool for iOS App Pentesting and Security by Swaroop Yermalkar

OWASP iGoat (Swift) - A Damn Vulnerable Swift Application for iOS

Nightingale Docker for Pentesters is a comprehensive Dockerized environment tailored for penetration testing and vulnerability assessment. It comes…

OWASP IoT Security Verification Standard (ISVS)

OWASP Secure Agent Playbook Project