
hermes-decomp
A powerful decompiler that lets you reverse-engineer React Native mobile apps by converting their compiled Hermes bytecode (.hbc) files back into…

A powerful decompiler that lets you reverse-engineer React Native mobile apps by converting their compiled Hermes bytecode (.hbc) files back into…

Datajack Proxy allows you to intercept TLS traffic in native x86 applications across platforms

C-based Android static analysis framework for decompilation, secret detection, endpoint discovery, permission analysis, and native library scanning…

Adaptation of CVE-2023-6241 for Google Pixel 7 from Google Pixel 8 taken from securitylab/SecurityExploits/Android/Mali/CVE_2023_6241


A tool that automates the mundane tasks of pentesting Android apps. It uses APKTool and Dex2Jar.

OPPO Find X6 Pro GhostLock (CVE-2026-43499) exploit adaptation

Android kernel CVE analysis and PoC for a MediaTek ION allocator type confusion, covering root-cause diffing, unprivileged trigger, and…

Android Reverse Engineering Framework

Proof-of-concept for CVE-2021-28476, a Hyper-V vmswitch.sys arbitrary pointer dereference allowing guest-to-host denial-of-service and potential RCE.

A vulnerable Android application that shows simple examples of vulnerabilities in a ctf style.

A curated list of CTF frameworks, libraries, resources and softwares

Penetration Testing Reference Bank - OSCP / PTP & PTX Cheatsheet

Bento Toolkit is a minimal fedora-based container for penetration tests and CTF with the sweet addition of GUI applications.

The Mobile App Pentest cheat sheet was created to provide concise collection of high value information on specific mobile application penetration…

Decompiles Android APK/XAPK/JAR/AAR files and extracts HTTP APIs, authentication patterns, and call flows using jadx, with R8-resistant Kotlin name…

A deliberately vulnerable mobile banking application designed for practicing mobile security testing. Features common vulnerabilities found in…

SSLPinDetect is a tool for analyzing Android APKs to detect SSL pinning implementations by scanning for known patterns in decompiled code. It helps…