
mariana-trench
A security focused static analysis tool for Android and Java applications.

A security focused static analysis tool for Android and Java applications.

opensource repo for validating agentic AI applications: redteam, behavior, supply-chain, static analysis

Ghidra is a software reverse engineering (SRE) framework

All-in-One malware analysis tool.

Comprehensive OWASP guide for mobile app security testing, reverse engineering, and verifying MASVS/MASWE weaknesses through static, dynamic, and…

Hunt every Endpoint in your code, expose Shadow APIs, map the Attack Surface.

UNIX-like reverse engineering framework and command-line toolset

Command-line and GUI tool for decompiling Android Dex and APK files into readable Java source code, with resource decoding, deobfuscation, and Smali…

The reverse-engineering expert agent: plans its own analysis path, derives every fact from raw evidence, and converges under mechanical verification…

MCP server packaging a three-tier penetration-testing methodology: attack-surface reconnaissance, source-to-sink static analysis, and live finding…


An intelligent reverse engineering analysis tool designed for multiple target platforms, currently supporting HarmonyOS (HAP/APP/ABC) and Android…

A powerful decompiler that lets you reverse-engineer React Native mobile apps by converting their compiled Hermes bytecode (.hbc) files back into…

JADX plugin that extracts method names, class references, and source file paths from string constants found in DEX files and decompiled Android code.

Django application that performs SAST and Malware Analysis for Android APKs

Rule-based Android malware scoring engine that analyzes APKs using static and dynamic analysis to detect vulnerabilities, identify malware families,…

Decompiles Android APK/XAPK/JAR/AAR files and extracts HTTP APIs, authentication patterns, and call flows using jadx, with R8-resistant Kotlin name…

A collection of android security related resources