
mobileAudit
Django application that performs SAST and Malware Analysis for Android APKs

Django application that performs SAST and Malware Analysis for Android APKs

Formal inter-procedural taint analysis engine for application security. Tracks untrusted data across function boundaries, persistence layers, and…

Some good resources for getting started with application security

Static and dynamic Android application security analysis

A Framework for Integrating Application Security into Software Engineering (FIASSE) using the Securable Software Engineering Model (SSEM)

A TypeScript package that provides AI-powered agents for Application Security (AppSec) tasks, built on top of the frontier models.

Static analysis CLI tool that reduces Node.js application attack surface by constructing dependency graphs and removing unused modules and functions…

Demonstrates CVE-2015-10034 in a vulnerable Java application, including SARIF analysis results from J-TAS Action for educational security testing.

Example Vulnerable application for CVE-2025–57833

(deprecated) Android application vulnerability analysis and Android pentest tool

Comprehensive OWASP guide for mobile app security testing, reverse engineering, and verifying MASVS/MASWE weaknesses through static, dynamic, and…

Firmware Analysis and Comparison Tool

Static code analysis tool for Android apps based on OWASP MASVS, detecting security vulnerabilities in APK files with low false-positive rates and…

Semantic-aware SAST scanner for Node.js applications that detects insecure code patterns using libsast pattern matching and semgrep syntax-aware…

Information flow analysis tool for Android applications

Markdown XSS leads to RCE in VNote version <=3.18.1

.NET/PowerShell/VBA Offensive Security Obfuscator