
mastg
Comprehensive OWASP guide for mobile app security testing, reverse engineering, and verifying MASVS/MASWE weaknesses through static, dynamic, and…

Comprehensive OWASP guide for mobile app security testing, reverse engineering, and verifying MASVS/MASWE weaknesses through static, dynamic, and…

Flutter Mobile Application Reverse Engineering Tool

Open-source mobile security testing suite for iOS and Android. Previously Passionfruit

Android Application Identifier for Packers, Protectors, Obfuscators and Oddities - PEiD for Android

The tool is used to analyze the content of the android application in local storage.

Disassemble ANY files including .so (NDK, JNI), Windows PE(EXE, DLL, SYS, etc), linux binaries, libraries, and any other files such as pictures,…

Agentic C2-style MCP server for Frida instrumentation on rooted Android and jailbroken iOS.

An updated Frida iOS dump tool supporting the latest Frida 17.5.2 APIs

Open-source, cross platform Qt6 based IDE for reverse-engineering Android application packages. It features a friendly IDE-like layout including code…

OWASP iGoat (Swift) - A Damn Vulnerable Swift Application for iOS

Mobile Helper Framework (mhf) is a tool that automates the process of identifying the framework/technology used to create a mobile application.…

Intentionally vulnerable Android application.

FairPlay decryptor (dump iPA) for iOS Application that running on macOS with SIP-enabled, using CVE-2025-24204. Support macOS 15.0-15.2

iOS and macOS Decompiler

A deliberately vulnerable mobile banking application designed for practicing mobile security testing. Features common vulnerabilities found in…

Fermion, an electron wrapper for Frida & Monaco.

An automatic obfuscation tool for Android apps that works in a black-box fashion, supports advanced obfuscation features and has a modular…

Static and dynamic Android application security analysis