
apkprobe
APK decompiler & secrets scanner for Android security research! Extract leaked API keys, hardcoded credentials, endpoints from APK files. apk2url,…

APK decompiler & secrets scanner for Android security research! Extract leaked API keys, hardcoded credentials, endpoints from APK files. apk2url,…

Automated scanner that detects Unity runtime injection vulnerability CVE-2025-59489 in Android APKs by extracting Unity version and checking against…

Mobile app security auditing tool focused on automating SAST analysis, identifying underlying technologies (React Native, Flutter, Xamarin, native),…

Android Antivirus which doesn't require root, adb, ca install and cloud with many features and ways to detect more zero-day malware

Static analyzer for Flutter/Dart AOT snapshots — recovers function names, class hierarchies, call graphs, and behavioral signals from libapp.so…

The Mobile App Pentest cheat sheet was created to provide concise collection of high value information on specific mobile application penetration…

Framework for hashing declared permissions in Chromium extensions and APKs, enabling clustering, hunting, and pivoting across potentially malicious…

Tool for finding URLs, paths, secrets and generating raw HTTP requests and OpenApi specifications from config files and annotations used in JAR / WAR…

Official code for the ISSTA 2026 paper: Is "Knowing It’s Malicious" Enough? Evaluating LLMs for Fine-Grained Malware Behavior Auditing

Image-based Android malware detection framework tackling obfuscation and concept drift. Includes curated datasets and Python code for training…

Memory-free continual learning framework for malware classification using mode connectivity-based interpolation. Supports class-incremental and…

Mobile Application Vulnerability Detection

Simple framework to extract "actionable" data from Android malware (C&Cs, phone numbers etc.)

Triggering and Analyzing Android Kernel Vulnerability CVE-2019-2215

Glass - a fast and free IDA Pro alternative

A powerful decompiler that lets you reverse-engineer React Native mobile apps by converting their compiled Hermes bytecode (.hbc) files back into…

Proof-of-concept exploit for CVE-2022-0219, an XXE vulnerability in Jadx that allows local file disclosure when exporting malicious APK files via the…

To determine if an APK is vulnerable to CVE-2017-13156