
SecurityShepherd
Web and mobile application security training platform

Web and mobile application security training platform

Automated mobile application security testing framework for Android, iOS, and Windows. Performs static and dynamic analysis, malware detection, and…

Comprehensive OWASP guide for mobile app security testing, reverse engineering, and verifying MASVS/MASWE weaknesses through static, dynamic, and…

CVE-2026-12960 - Improper Export of Android Application Components in the ASUS Router app (com.asus.aihome). PoC, exploit APK, video, and vendor…

Django application that performs SAST and Malware Analysis for Android APKs

OWASP IoT Security Verification Standard (ISVS)

WebKit NavigateEvent.canIntercept SOP bypass via cross-port interception — iOS 26.3.1 BSI (CVE-2026-20643)

This project shows the kind of data a rogue iPhone application can collect.

Public advisory & PoC for CVE-2026-26897 — Deep Link Bypass in EcoOnline EHS Android (com.airsweb.v10), fixed in 0.2.500

Agentic C2-style MCP server for Frida instrumentation on rooted Android and jailbroken iOS.

🔗 Lightweight security orchestrator mobile application for URI vetting, providing a unified, multi-engine interface to aggregate and validate link…

OWASP iGoat (Swift) - A Damn Vulnerable Swift Application for iOS

Improper Hostname Verification in EagleEyes Lite Android Application

Cleartext Transmission of Sensitive Information in EagleEyes Lite Android Application

Improper Certificate Chain Validation in EagleEyes Lite Android Application

A deliberately vulnerable mobile banking application designed for practicing mobile security testing. Features common vulnerabilities found in…

Static code analysis tool for Android apps based on OWASP MASVS, detecting security vulnerabilities in APK files with low false-positive rates and…

CVE-2024-23729