
Mobile-Security-Framework-MobSF
Automated mobile application security testing framework for Android, iOS, and Windows. Performs static and dynamic analysis, malware detection, and…

Automated mobile application security testing framework for Android, iOS, and Windows. Performs static and dynamic analysis, malware detection, and…

Comprehensive OWASP guide for mobile app security testing, reverse engineering, and verifying MASVS/MASWE weaknesses through static, dynamic, and…


.NET deobfuscator and unpacker.

The Mobile App Pentest cheat sheet was created to provide concise collection of high value information on specific mobile application penetration…

A coding-agent skill for multi-phase security audits with independently verified, machine-readable findings

Firmware Analysis and Comparison Tool

Static code analysis tool for Android apps based on OWASP MASVS, detecting security vulnerabilities in APK files with low false-positive rates and…

Takes third-party HTML and produces HTML that is safe to embed in your web application. Fast and easy to configure.

A vulnerable version of Rails that follows the OWASP Top 10

iblessing is an iOS security exploiting toolkit, it mainly includes application information gathering, static analysis and dynamic analysis. It can…

A curated list of awesome iOS application security resources.

.NET/PowerShell/VBA Offensive Security Obfuscator

Semantic-aware SAST scanner for Node.js applications that detects insecure code patterns using libsast pattern matching and semgrep syntax-aware…

Modular software verification toolchain that translates LLVM IR into Boogie intermediate verification language for bounded and experimental unbounded…

(deprecated) Android application vulnerability analysis and Android pentest tool

Find authentication (authn) and authorization (authz) security bugs in web application routes.

A source code static analysis platform for AppSec enthusiasts.