
masvs
The OWASP MASVS (Mobile Application Security Verification Standard) is the industry standard for mobile app security.

The OWASP MASVS (Mobile Application Security Verification Standard) is the industry standard for mobile app security.

Makes reverse engineering Android apps easier, automating repetitive tasks like pulling, decoding, rebuilding and patching an APK.

The new bridge between Burp Suite and Frida!

WhatsApp OSINT tool for retrieving profile photos, verifying Business accounts, checking user status, analyzing linked devices, and reviewing privacy…

PenBox - A Penetration Testing Framework - The Tool With All The Tools , The Hacker's Repo

StaCoAn is a crossplatform tool which aids developers, bugbounty hunters and ethical hackers performing static code analysis on mobile applications.

FirmWire is a full-system baseband firmware emulation platform for fuzzing, debugging, and root-cause analysis of smartphone baseband firmwares

AI-driven CLI for testing Android and iOS apps using natural language. Generates, runs, and fixes end-to-end tests on emulators/simulators with…

Offline-first password manager with direct device-to-device sync

Collections of my POCs for android vendor CVEs

An exploit for CVE-2015-1538-1 - Google Stagefright ‘stsc’ MP4 Atom Integer Overflow Remote Code Execution


Automated bug bounty & recon framework — wraps Subfinder, Naabu, Httpx, Nuclei, Nmap, CVEMap, Gowitness, Katana & more behind a unified web UI

Exploit and writeup for installed app to root privilege escalation through CVE-2024-48336 (Magisk Bug #8279), Privileges Escalation / Arbitrary Code…

PoC and tools for exploiting CVE-2020-6516 (Chrome) and CVE-2021-24027 (WhatsApp)

RunAsAnyone: PoC and writeup for bypassing the initial patch of CVE-2024-0044, Android run-as any app vulnerability allowing privilege escalation…

android location service cache dumper

This is POC for IOS 0click CVE-2025-43300