Skip to content
KitploitKITPLOIT
도구블로그
제출
도구블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

··피드·문의·개인정보·© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
awesome-mobile-security — 유용한 Android 및 iOS 보안 관련 자료를 한곳에 모으려는 노력입니다. 모든 참고 자료와 도구는 해당 소유자의 소유입니다. 저는 단지 유지 관리만 하고 있습니다. | Kitploit
도구/GitHubGitHub/vaib25vicky/awesome-mobile-security
Android SecurityStatic AnalysisVulnerability ScannersDynamic Analysis (Sandboxing)iOS SecurityReverse EngineeringPenetration TestingMobile SecurityLearning & Education

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
공유
Curated Resources
Labs & Practice
GitHubvaib25vicky/awesome-mobile-security

awesome-mobile-security

유용한 Android 및 iOS 보안 관련 자료를 한곳에 모으려는 노력입니다. 모든 참고 자료와 도구는 해당 소유자의 소유입니다. 저는 단지 유지 관리만 하고 있습니다.

저장소 보기
3.5k3785년 전Kitploit 검토 완료

awesome-mobile-security awesome

유지 관리: @vaib25vicky와 보안 및 개발자 커뮤니티의 기여로 운영됩니다.

Android

일반 - 블로그, 논문, 방법론

  • Android: Gaining access to arbitrary* Content Providers
  • Evernote: Universal-XSS, theft of all cookies from all sites, and more
  • Interception of Android implicit intents
  • TikTok: three persistent arbitrary code executions and one theft of arbitrary files
  • Persistent arbitrary code execution in Android's Google Play Core Library: details, explanation and the PoC - CVE-2020-8913
  • Android: Access to app protected components
  • Android: arbitrary code execution via third-party package contexts
  • Android Pentesting Labs - Step by Step guide for beginners
  • An Android Hacking Primer
  • Secure an Android Device
  • Security tips
  • OWASP Mobile Security Testing Guide
  • Security Testing for Android Cross Platform Application
  • Dive deep into Android Application Security
  • Pentesting Android Apps Using Frida
  • Mobile Security Testing Guide
  • Mobile Application Penetration Testing Cheat Sheet
  • Android Applications Reversing 101
  • Android Security Guidelines
  • Android WebView Vulnerabilities
  • OWASP Mobile Top 10
  • Practical Android Phone Forensics
  • Mobile Reverse Engineering Unleashed
  • Android Root Detection Bypass Using Objection and Frida Scripts
  • quark-engine - An Obfuscation-Neglect Android Malware Scoring System
  • Root Detection Bypass By Manual Code Manipulation.
  • Application and Network Usage in Android
  • GEOST BOTNET - the discovery story of a new Android banking trojan
  • Mobile Pentesting With Frida
  • Magisk Systemless Root - Detection and Remediation
  • AndrODet: An adaptive Android obfuscation detector
  • Hands On Mobile API Security
  • Zero to Hero - Mobile Application Testing - Android Platform
  • How to use FRIDA to bruteforce Secure Startup with FDE-encryption on a Samsung G935F running Android 8
  • Android Malware Adventures
  • AAPG - Android application penetration testing guide
  • Bypassing Android Anti-Emulation
  • Bypassing Xamarin Certificate Pinning
  • Configuring Burp Suite With Android Nougat

서적

  • SEI CERT Android Secure Coding Standard
  • Android Security Internals
  • Android Cookbook
  • Android Hacker's Handbook
  • Android Security Cookbook
  • The Mobile Application Hacker's Handbook
  • Android Malware and Analysis
  • Android Security: Attacks and Defenses

강좌

  • Learning-Android-Security
  • Mobile Application Security and Penetration Testing
  • Advanced Android Development
  • Learn the art of mobile app development
  • Learning Android Malware Analysis
  • Android App Reverse Engineering 101
  • Android Pentesting for Beginners

도구

정적 분석

  • Amandroid – A Static Analysis Framework
  • Androwarn – Yet Another Static Code Analyzer
  • APK Analyzer – Static and Virtual Analysis Tool
  • APK Inspector – A Powerful GUI Tool
  • Droid Hunter – Android application vulnerability analysis and Android pentest tool
  • Error Prone – Static Analysis Tool
  • Findbugs – Find Bugs in Java Programs
  • Find Security Bugs – A SpotBugs plugin for security audits of Java web applications.
  • Flow Droid – Static Data Flow Tracker
  • Smali/Baksmali – Assembler/Disassembler for the dex format
  • Smali-CFGs – Smali Control Flow Graph’s
  • SPARTA – Static Program Analysis for Reliable Trusted Apps
  • Thresher – To check heap reachability properties
  • Vector Attack Scanner – To search vulnerable points to attack
  • Gradle Static Analysis Plugin
  • Checkstyle – A tool for checking Java source code
  • PMD – An extensible multilanguage static code analyzer
  • Soot – A Java Optimization Framework
  • Android Quality Starter
  • QARK – Quick Android Review Kit

동적 분석

  • Adhrit - Android Security Suite for in-depth reconnaissance and static bytecode analysis based on Ghera benchmarks
  • Android Hooker - Opensource project for dynamic analyses of Android applications
  • AppAudit - Online tool ( including an API) uses dynamic and static analysis
  • AppAudit - A bare-metal analysis tool on Android devices
  • CuckooDroid - Extension of Cuckoo Sandbox the Open Source software
  • DroidBox - Dynamic analysis of Android applications
  • Droid-FF - Android File Fuzzing Framework
  • Drozer
  • Marvin - Analyzes Android applications and allows tracking of an app
  • Inspeckage
  • PATDroid - Collection of tools and data structures for analyzing Android applications
  • AndroL4b - Android security virtual machine based on ubuntu-mate
  • Radare2 - Unix-like reverse engineering framework and commandline tools
  • Cutter - Free and Open Source RE Platform powered by radare2
  • ByteCodeViewer - Android APK Reverse Engineering Suite (Decompiler, Editor, Debugger)
  • Mobile-Security-Framework MobSF
  • CobraDroid - Custom build of the Android operating system geared specifically for application security
  • Magisk v20.2 - Root & Universal Systemless Interface

Android 온라인 APK 분석기

  • Oversecured - 90개 이상의 취약점 범주를 포함한 Android 앱(APK 파일)용 정적 취약점 스캐너
  • Android Observatory APK Scan
  • Android APK Decompiler
  • AndroTotal
  • NVISO ApkScan
  • VirusTotal
  • Scan Your APK
  • AVC Undroid
  • OPSWAT
  • ImmuniWeb Mobile App Scanner
  • Ostor Lab
  • Quixxi
  • TraceDroid
  • Visual Threat
  • App Critique

실습 환경 (Labs)

  • OVAA (Oversecured Vulnerable Android App)
  • DIVA (Damn insecure and vulnerable App)
  • SecurityShepherd
  • Damn Vulnerable Hybrid Mobile App (DVHMA)
  • OWASP-mstg
  • VulnerableAndroidAppOracle
  • Android InsecureBankv2
  • Purposefully Insecure and Vulnerable Android Application (PIIVA)
  • Sieve app
  • DodoVulnerableBank
  • Digitalbank
  • OWASP GoatDroid
  • AppKnox Vulnerable Application
  • Vulnerable Android Application
  • MoshZuk
  • Hackme Bank
  • Android Security Labs
  • Android-InsecureBankv2
  • Android-security
  • VulnDroid
  • FridaLab
  • Santoku Linux - Mobile Security VM

발표 영상

  • Blowing the Cover of Android Binary Fuzzing (Slides)
  • One Step Ahead of Cheaters -- Instrumenting Android Emulators
  • Vulnerable Out of the Box: An Evaluation of Android Carrier Devices
  • Rock appround the clock: Tracking malware developers by Android
  • Chaosdata - Ghost in the Droid: Possessing Android Applications with ParaSpectre
  • Remotely Compromising Android and iOS via a Bug in Broadcom's Wi-Fi Chipsets
  • Honey, I Shrunk the Attack Surface – Adventures in Android Security Hardening
  • Hide Android Applications in Images
  • Scary Code in the Heart of Android
  • Fuzzing Android: A Recipe For Uncovering Vulnerabilities Inside System Components In Android
  • Unpacking the Packed Unpacker: Reverse Engineering an Android Anti-Analysis Native Library
  • Android FakeID Vulnerability Walkthrough
  • Unleashing D* on Android Kernel Drivers
  • The Smarts Behind Hacking Dumb Devices
  • Overview of common Android app vulnerabilities
  • Android Dev Summit 2019
  • Android security architecture
  • Get the Ultimate Privilege of Android Phone

기타

  • Android-Reports-and-Resources
  • android-security-awesome
  • Android Penetration Testing Courses
  • Lesser-known Tools for Android Application Pentesting
  • android-device-check - a set of scripts to check Android device security configuration
  • apk-mitm - a CLI application that prepares Android APK files for HTTPS inspection
  • Andriller - is software utility with a collection of forensic tools for smartphones
  • Dexofuzzy: Android malware similarity clustering method using opcode sequence-Paper
  • Chasing the Joker
  • Side Channel Attacks in 4G and 5G Cellular Networks-Slides
  • Shodan.io-mobile-app for Android
  • Popular Android Malware 2018
  • Popular Android Malware 2019
  • Popular Android Malware 2020

iOS

일반 - 블로그, 논문, 방법론* iOS Security

  • Basic iOS Apps Security Testing lab
  • IOS Application security – Setting up a mobile pentesting platform
  • iOS 애플리케이션에서 발견되는 가장 일반적인 취약점 모음
  • IOS_Application_Security_Testing_Cheat_Sheet
  • OWASP iOS Basic Security Testing
  • 탈옥 없이 iOS 앱 동적 분석
  • iOS 애플리케이션 인젝션
  • Low-Hanging Apples: iOS 앱에서 자격 증명 및 비밀 찾기
  • Checkra1n Era - 시리즈
  • BFU 추출: 잠기고 비활성화된 iPhone의 포렌식 분석
  • HowTo-decrypt-Signal.sqlite-for-IOS
  • Can I Jailbreak?
  • iCloud에서 스크린 타임 비밀번호 및 음성 메모 추출 방법
  • Swift 앱 리버스 엔지니어링
  • FRIDA로 iOS를 Mettle하세요
  • iOS 애플리케이션 침투 테스트를 위한 런타임 접근 방식
  • iOS Internals vol 2
  • usbmux 및 iOS 잠금 서비스 이해하기

도서

  • Hacking and Securing iOS Applications: Stealing Data, Hijacking Software, and How to Prevent It
  • iOS Penetration Testing
  • iOS App Security, Penetration Testing, and Development
  • IOS Hacker's Handbook
  • Hacking iOS Applications a detailed testing guide
  • iOS 앱 개발 (Swift)
  • iOS Programming Cookbook

강좌

  • iOS 애플리케이션 침투 테스트
  • iOS 애플리케이션 리버스 엔지니어링
  • iOS용 앱 디자인 및 개발

도구

  • Cydia Impactor
  • checkra1n 탈옥
  • idb - iOS 앱 보안 평가 도구
  • Frida
  • Objection - Frida 기반 모바일 탐색 툴킷
  • Bfinject
  • iFunbox
  • Libimobiledevice - Apple iOS 기기 서비스와 통신하기 위한 라이브러리
  • iRET (iOS Reverse Engineering Toolkit) - oTool, dumpDecrypted, SQLite, Theos, Keychain_dumper, Plutil 포함
  • Myriam iOS
  • iWep Pro - iOS 기기를 무선 네트워크 진단 도구로 전환하는 유용한 애플리케이션 무선 제품군
  • Burp Suite
  • Cycript
  • needle - iOS 보안 테스트 프레임워크
  • iLEAPP - iOS 로그, 이벤트 및 환경설정 파서
  • Cutter - radare2 기반 무료 오픈 소스 RE 플랫폼
  • decrypt0r - SecureRom 자료를 자동으로 다운로드 및 복호화
  • iOS Security Suite - 고급 사용자 친화적인 플랫폼 보안 및 안티탬퍼링 라이브러리

실습 환경

  • OWASP iGoat
  • Damn Vulnerable iOS App (DVIA) v2
  • Damn Vulnerable iOS App (DVIA) v1
  • iPhoneLabs
  • iOS-Attack-Defense

발표

  • iOS 보안의 이면
  • 현대 iOS 애플리케이션 보안
  • Secure Enclave Processor 신비 풀기
  • HackPac iOS 사용자 공간에서 포인터 인증 해킹
  • Apple 커널 드라이버 분석 및 공격
  • Wi-Fi를 통한 iOS 원격 침해 및 샌드박스 탈출
  • iOS 모바일 앱 리버스 엔지니어링
  • iOS 10 커널 힙 재검토
  • KTRW: 디버깅 가능한 iPhone 구축을 위한 여정
  • SecureROM이 싫어하는 한 가지 기묘한 트릭
  • 옛날 이야기: iOS 11 안정화 해제 - 스포일러: Apple은 패치를 못 함
  • 메신저 해킹: iMessage를 통한 iPhone 원격 침해
  • Apple 보안 업데이트에서 iOS 0-Day 탈옥 재현
  • iOS 시뮬레이터의 SpringBoard 리버스 엔지니어링
  • iPhone XS Max 공격

기타

  • iOS 침투 테스트에 가장 유용한 도구
  • iOS-Security-Guides
  • osx-security-awesome - OSX 및 iOS 관련 보안 도구
  • Apple의 비밀 정원에 대한 신뢰: Apple 연속성 프로토콜 탐색 및 리버싱 - 슬라이드
  • Apple 플랫폼 보안
  • Santoku Linux를 활용한 모바일 보안, 포렌식 및 악성코드 분석
도구 다운로드
  • Infer – A Static Analysis tool for Java, C, C++ and Objective-C
  • Android Check – Static Code analysis plugin for Android Project
  • FindBugs-IDEA Static byte code analysis to look for bugs in Java code
  • APK Leaks – Scanning APK file for URIs, endpoints & secrets
  • Runtime Mobile Security (RMS) - is a powerful web interface that helps you to manipulate Android and iOS Apps at Runtime
  • MOBEXLER - A Mobile Application Penetration Testing Platform
  • Vuldroid
  • iOS 코드 서명 심층 분석
  • AirDoS: 근처의 모든 iPhone 또는 iPad를 원격으로 사용 불가능하게 만들기
  • SSH를 사용하여 #checkra1n 탈옥된 iPhone 파일 시스템에 접근하고 탐색하는 방법
  • 야생에서 발견된 iOS 익스플로잇 체인 심층 분석 - Project Zero
  • iPhone의 완전 원격 공격 표면 - Project Zero