Skip to content
KitploitKITPLOIT
HerramientasBlog
Enviar
HerramientasBlog
Enviar

¡Herramientas de Hacking, PenTest y Ciberseguridad para tu Arsenal de Seguridad!

Kitploit es un directorio de herramientas de hacking, ciberseguridad y pentesting. Descubre las últimas actualizaciones de proyectos para encontrar vulnerabilidades, analizar sistemas, automatizar pruebas y fortalecer tu seguridad.

··Feeds·Contacto·Privacidad·© 2026 Kitploit

Directorio de Herramientas

Categorías

Ver todas las categorías
Loading categories
awesome-android-security — Una lista curada de materiales y recursos de seguridad de Android para pentesters y cazadores de bugs | Kitploit
Herramientas/GitHubGitHub/saeidshirazi/awesome-android-security
Seguridad AndroidAnálisis EstáticoPentesting de Apps MóvilesIngeniería InversaAnálisis de MalwarePruebas de PenetraciónSeguridad MóvilAprendizaje y EducaciónRecursos Curados

Más Populares

Ver todos →

Descubre las herramientas más usadas por nuestra comunidad.

Explora todas las herramientas

Explora nuestra colección de herramientas

Ver todas las herramientas →
Compartir
GitHubsaeidshirazi/awesome-android-security

awesome-android-security

Una lista curada de materiales y recursos de seguridad de Android para pentesters y cazadores de bugs

Ver Repositorio
2.0k2951hace 1 mesRevisado por Kitploit

Awesome-Android-Security awesome

Screenshot

Table of Contents

  • Blog
  • How To's
  • Papers
  • Books
  • Trainings
  • Tools
    • Static Analysis Tools
    • Dynamic Analysis Tools
    • Online APK Analyzers
    • Online APK Decompiler
    • Forensic Analysis Tools
  • Labs
  • Talks
  • Misc
  • Bug Bounty & Writeups
  • Cheat Sheet
  • Checklist
  • Bug Bounty Report

Blogs

  • 1-click Exploit in South Korea's biggest mobile chat app
  • 20 Security Issues Found in Xiaomi Devices
  • Bypass Instagram and Threads SSL pinning on Android
  • Reverse Engineering Android game Coin Hunt World and its communication protocol to cheat the app
  • Discovering vendor-specific vulnerabilities in Android
  • Technical analysis of Alien android malware
  • Lock Screen Bypass Exploit of Android Devices (CVE-2022–20006)
  • Analysis of Android banking Trojan MaliBot that is based on S.O.V.A banker
  • Pending Intents: A Pentester’s view
  • Android security checklist: theft of arbitrary files
  • Protecting Android users from 0-Day attacks
  • Reversing an Android sample which uses Flutter
  • Step-by-step guide to reverse an APK protected with DexGuard using Jadx
  • Use cryptography in mobile apps the right way
  • Android security checklist: WebView
  • Common mistakes when using permissions in Android
  • Two weeks of securing Samsung devices: Part 2
  • Why dynamic code loading could be dangerous for your apps: a Google example
  • Two weeks of securing Samsung devices: Part 1
  • How to exploit insecure WebResourceResponse configurations + an example of the vulnerability in Amazon apps
  • Exploiting memory corruption vulnerabilities on Android + an example of such vulnerability in PayPal apps
  • Capture all android network traffic
  • Reverse Engineering Clubhouse
  • Escape the Chromium sandbox on Android Devices
  • Android Penetration Testing: Frida
  • Android: Gaining access to arbitrary* Content Providers
  • Getting root on a 4G LTE mobile hotspot
  • Exploiting new-era of Request forgery on mobile applications
  • Deep Dive into an Obfuscation-as-a-Service for Android Malware
  • Evernote: Universal-XSS, theft of all cookies from all sites, and more
  • Interception of Android implicit intents
  • AAPG - Android application penetration testing guide
  • TikTok: three persistent arbitrary code executions and one theft of arbitrary files
  • Persistent arbitrary code execution in Android's Google Play Core Library: details, explanation and the PoC - CVE-2020-8913
  • Android: Access to app protected components
  • Android: arbitrary code execution via third-party package contexts
  • Android Pentesting Labs - Step by Step guide for beginners
  • An Android Hacking Primer
  • An Android Security tips
  • OWASP Mobile Security Testing Guide
  • Security Testing for Android Cross Platform Application
  • Dive deep into Android Application Security
  • Pentesting Android Apps Using Frida
  • Mobile Security Testing Guide
  • Android Applications Reversing 101
  • Android Security Guidelines
  • Android WebView Vulnerabilities
  • OWASP Mobile Top 10
  • Practical Android Phone Forensics
  • Mobile Pentesting With Frida
  • Zero to Hero - Mobile Application Testing - Android Platform
  • Detecting Dynamic Loading in Android Applications
  • Static Analysis for Android and iOS
  • Dynamic Analysis for Android and iOS
  • Exploring intent-based Android security vulnerabilities on Google Play (part 1/3)
  • Hunting intent-based Android security vulnerabilities with Snyk Code (part 2/3)
  • Mitigating and remediating intent-based Android security vulnerabilities (part 3/3)
  • Strengthening Android Security: Mitigating Banking Trojan Threats

How To's

  • How to analyze mobile malware: a Cabassous/FluBot Case study
  • How to Bypasses Iframe Sandboxing
  • How To Configuring Burp Suite With Android Nougat
  • How To Bypassing Xamarin Certificate Pinning
  • How To Bypassing Android Anti-Emulation
  • How To Secure an Android Device
  • Android Root Detection Bypass Using Objection and Frida Scripts
  • Root Detection Bypass By Manual Code Manipulation.
  • Magisk Systemless Root - Detection and Remediation
  • How to use FRIDA to bruteforce Secure Startup with FDE-encryption on a Samsung G935F running Android 8

Papers

  • A systematic analysis of commercial Android packers
  • A Large-Scale Study on the Adoption of Anti-Debugging and Anti-Tampering Protections in Android Apps
  • Things You May Not Know About Android (Un)Packers
  • Happer: Unpacking Android Apps via a Hardware-Assisted Approach
  • AndrODet: An adaptive Android obfuscation detector
  • GEOST BOTNET - the discovery story of a new Android banking trojan
  • Dual-Level Android Malware Detection
  • An Investigation of the Android Kernel Patch Ecosystem

Books

  • SEI CERT Android Secure Coding Standard
  • Android Security Internals
  • Android Cookbook
  • Android Hacker's Handbook
  • Android Security Cookbook
  • The Mobile Application Hacker's Handbook
  • Android Malware and Analysis
  • Android Security: Attacks and Defenses
  • Learning Penetration Testing For Android Devices
  • Android Hacking 2020 Edition

Trainings

  • SEC575: Mobile Device Security and Ethical Hacking
  • Android Reverse Engineering_pt-BR
  • Learning-Android-Security
  • Advanced Android Development
  • Learn the art of mobile app development
  • Learning Android Malware Analysis
  • Android App Reverse Engineering 101
  • MASPT V2
  • Android Pentration Testing(Persian)

Tools

Static Analysis

  • BlackDex is an Android unpack(dexdump) tool
  • Deoptfuscator - Deobfuscator for Android Application
  • Android Reverse Engineering WorkBench for VS Code
  • Apktool:A tool for reverse engineering Android apk files
  • Defeat Java packers via Frida instrumentation
  • quark-engine - An Obfuscation-Neglect Android Malware Scoring System
  • DeGuard:Statistical Deobfuscation for Android
  • jadx - Dex to Java decompiler
  • Amandroid – A Static Analysis Framework
  • Androwarn – Yet Another Static Code Analyzer
  • Droid Hunter – Android application vulnerability analysis and Android pentest tool
  • Error Prone – Static Analysis Tool
  • Findbugs – Find Bugs in Java Programs
  • Find Security Bugs – A SpotBugs plugin for security audits of Java web applications.
  • Flow Droid – Static Data Flow Tracker
  • Smali/Baksmali – Assembler/Disassembler for the dex format
  • Smali-CFGs – Smali Control Flow Graph’s
  • SPARTA – Static Program Analysis for Reliable Trusted Apps
  • Gradle Static Analysis Plugin
  • Checkstyle – A tool for checking Java source code

Dynamic Analysis

  • Mobile-Security-Framework MobSF
  • Magisk v23.0 - Root & Universal Systemless Interface
  • Runtime Mobile Security (RMS) - is a powerful web interface that helps you to manipulate Android and iOS Apps at Runtime
  • House: A runtime mobile application analysis toolkit with a Web GUI
  • Objection - Runtime Mobile Exploration toolkit, powered by Frida
  • NullKia - Mobile security framework supporting 18 manufacturers with baseband exploitation, TEE/TrustZone research, cellular security, and eSIM tools
  • Spectre - Radio frequency scanner with recon and offensive capabilities
  • Droid-FF - Android File Fuzzing Framework
  • Drozer
  • Slicer-automate APK Recon
  • Inspeckage
  • PATDroid - Collection of tools and data structures for analyzing Android applications
  • Radare2 - Unix-like reverse engineering framework and commandline tools
  • Cutter - Free and Open Source RE Platform powered by radare2
  • ByteCodeViewer - Android APK Reverse Engineering Suite (Decompiler, Editor, Debugger)
  • MPT - Mobile Pentest Toolkit (MPT) is a must-have solution for your android penetration testing workflows.

Online APK Analyzers

  • Guardsquare AppSweep
  • Oversecured
  • Android Observatory APK Scan
  • AndroTotal
  • VirusTotal
  • Scan Your APK
  • AVC Undroid
  • OPSWAT
  • ImmuniWeb Mobile App Scanner
  • Ostor Lab
  • Quixxi
  • TraceDroid
  • Visual Threat
  • App Critique
  • Jotti's malware scan
  • kaspersky scanner
  • Hudson Rock

Online APK Decompiler

  • Android APK Decompiler
  • Java Decompiler APk
  • APK DECOMPILER APP
  • DeAPK is an open-source, online APK decompiler
  • apk and dex decompilation back to Java source code
  • APK Decompiler Tools#### Análisis Forense
  • Análisis Forense para Aplicaciones Móviles (FAMA)
  • Andriller
  • Autopsy
  • bandicoot
  • Fridump: Volcador de memoria universal usando Frida
  • LiME - Extractor de Memoria Linux

Laboratorios

  • Damn-Vulnerable-Bank
  • OVAA (Aplicación Android Vulnerable Oversecured)
  • DIVA (Aplicación insegura y vulnerable)
  • OWASP Security Shepherd
  • Damn Vulnerable Hybrid Mobile App (DVHMA)
  • OWASP-mstg (Aplicaciones Móviles Irrompibles)
  • VulnerableAndroidAppOracle
  • Android InsecureBankv2
  • Aplicación Android Intencionalmente Insegura y Vulnerable (PIIVA)
  • Sieve app (Una aplicación Android que explota a través de componentes de Android)
  • DodoVulnerableBank (Aplicación Android Insegura y Vulnerable para aprender hacking y seguridad)
  • Digitalbank (Aplicación Móvil Vulnerable de Banco Digital Android)
  • Aplicación Vulnerable de AppKnox
  • Aplicación Android Vulnerable
  • Laboratorios de Seguridad Android
  • Sandbox de seguridad Android
  • VulnDroid (Aplicación Android Vulnerable estilo CTF)
  • FridaLab
  • Santoku Linux - MV de Seguridad Móvil
  • AndroL4b - Una Máquina Virtual para Evaluar Aplicaciones Android, Ingeniería Inversa y Análisis de Malware

Charlas

  • Un paso adelante de los tramposos: Instrumentalizando emuladores Android
  • Vulnerable de fábrica: Una evaluación de dispositivos Android de operadores
  • Rock alrededor del reloj: Rastreando desarrolladores de malware mediante Android
  • Chaosdata - Fantasma en el Droid: Poseyendo aplicaciones Android con ParaSpectre
  • Comprometiendo Android e iOS de forma remota mediante un error en los chips Wi-Fi de Broadcom
  • Cariño, encogí la superficie de ataque – Aventuras en el endurecimiento de seguridad Android
  • Ocultar aplicaciones Android en imágenes
  • Código aterrador en el corazón de Android
  • Fuzzing en Android: Una receta para descubrir vulnerabilidades en componentes del sistema en Android
  • Desempaquetando el desempaquetador empaquetado: Ingeniería inversa de una librería nativa de anti-análisis en Android
  • Recorrido por la vulnerabilidad FakeID en Android
  • Desatando D* en los controladores del kernel de Android
  • La inteligencia detrás del hacking de dispositivos tontos
  • Resumen de vulnerabilidades comunes en aplicaciones Android
  • Habilidades avanzadas de Bug Bounty en Android
  • Arquitectura de seguridad Android
  • Obtén el privilegio máximo de un teléfono Android

Miscelánea

  • PhoneSploit con integración Metasploit
  • Aventuras de malware Android
  • Android-Reports-and-Resources
  • Seguridad de API móvil práctica
  • Cursos de pruebas de penetración en Android
  • Herramientas menos conocidas para pruebas de penetración en aplicaciones Android
  • android-device-check - un conjunto de scripts para verificar la configuración de seguridad de dispositivos Android
  • apk-mitm - una aplicación CLI que prepara archivos APK de Android para inspección HTTPS
  • Andriller - una utilidad de software con una colección de herramientas forenses para smartphones
  • Dexofuzzy: Método de agrupación de similitud de malware Android usando secuencia de opcodes - Paper
  • Persiguiendo al Joker
  • Ataques de canal lateral en redes celulares 4G y 5G - Diapositivas
  • Shodan.io-mobile-app para Android
  • Malware Android popular 2019
  • Malware Android popular 2020
  • Malware Android popular 2021

Bug Bounty y Writeups

  • Hacker101 CTF: Writeups de desafíos Android

  • Ejecución de código arbitrario en Facebook para Android a través de la función de descarga

  • RCE a través de la aplicación Samsung Galaxy Store

Hoja de referencia

  • Hoja de referencia de pruebas de penetración en aplicaciones móviles
  • Hoja de referencia ADB (Android Debug Bridge)
  • Hoja de referencia de Frida y fragmentos de código para Android

Listas de verificación

  • Lista de verificación de pruebas de penetración en Android
  • Guía de pruebas de seguridad móvil OWASP (MSTG)
  • Estándar de verificación de seguridad de aplicaciones móviles OWASP (MASVS)

Informes de Bug Bounty

  • Lista de informes divulgados de Android en Hackerone
  • Cómo reportar problemas de seguridad
Descargar herramienta
  • PMD – An extensible multilanguage static code analyzer
  • Soot – A Java Optimization Framework
  • Android Quality Starter
  • QARK – Quick Android Review Kit
  • Infer – A Static Analysis tool for Java, C, C++ and Objective-C
  • Android Check – Static Code analysis plugin for Android Project
  • FindBugs-IDEA Static byte code analysis to look for bugs in Java code
  • APK Leaks – Scanning APK file for URIs, endpoints & secrets
  • Trueseeing – fast, accurate and resillient vulnerabilities scanner for Android apps
  • StaCoAn – crossplatform tool which aids developers, bugbounty hunters and ethical hackers
  • APKScanner
  • Vulert - Vulert can scan Gradle lockfiles gradle.lockfile to detect the existing vulnerabilities in your dependencies and monitor for future vulnerabilities as new CVEs emerge, this helps keep your Android apps safe from supply chain threats.
  • Mobile Audit – Web application for performing Static Analysis and detecting malware in Android APKs
  • mariana-trench - Our security focused static analysis tool for Android and Java applications.
  • semgrep-rules-android-security
  • Asegurando el sistema: Un análisis profundo de la ingeniería inversa de aplicaciones preinstaladas en Android
  • Bad Binder: Encontrando un 0day de Android en el mundo real
  • Inmersión profunda en ART (Android Runtime) para análisis binario dinámico
  • Malware Android popular 2022