Showing 36 of 60 projects
An automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis, and security assessment framework.
A comprehensive, curated collection of tools, research, and resources for Android application security analysis and reverse engineering.
A comprehensive, curated collection of tools, research, and resources for Android application security analysis and penetration testing.
A Python toolkit for reverse engineering, analyzing, and pentesting Android applications (APK, DEX, resources).
A tool to scan APK files for URIs, endpoints, secrets, and sensitive data patterns.
A Python-based hacking tool for remotely exploiting Android devices via ADB and Metasploit to gain Meterpreter sessions.
A comprehensive cheat sheet and tool collection for mobile application penetration testing, mapped to OWASP Mobile Top 10 risks.
A CLI tool that automatically patches Android APK files to bypass HTTPS security for traffic inspection.
A security testing framework for Android that identifies vulnerabilities by interacting with apps, IPC endpoints, and the OS.
A security-oriented, feedback-driven, evolutionary software fuzzer that uses hardware and software code coverage to find bugs.
A web interface powered by FRIDA for runtime manipulation, analysis, and security testing of Android and iOS applications.
An Xposed module for dynamic analysis of Android apps via API hooks, unexported activity launching, and runtime inspection.
A SpotBugs plugin for detecting security vulnerabilities in Java web and Android applications.
A curated collection of disclosed Android security reports from HackerOne and educational resources for vulnerability research.
An obfuscation-neglect Android malware scoring system that analyzes APKs for malicious behavior patterns.
An efficient Android vulnerability scanner that finds security issues and missing best practices in APK files.
The largest open collection of Android malware samples for security research and analysis.
A collection of tools and scripts for unpacking and analyzing protected Android applications, originally presented at Defcon 22.
A virtual machine for Android application security assessment, reverse engineering, and malware analysis.
An intentionally insecure Android app designed to teach secure coding and penetration testing through hands-on vulnerability challenges.
A curated collection of Android exploits, hacking tools, and resources for security research and penetration testing.
A work-in-progress reference guide for Android security topics, tools, and version-specific details.
A Python-based tool for exploiting and managing Android devices via ADB with capabilities like screen recording, data extraction, and remote control.
A comprehensive checklist for designing, testing, and releasing secure Android applications based on OWASP standards.
Dynamic analysis tool for Android applications that monitors runtime behavior, detects information leaks, and visualizes app activity.
A vulnerable Android CTF application demonstrating real-world security vulnerabilities and exploitation techniques.
A vulnerable Android app aggregating known security vulnerabilities for testing and educational purposes.
A lightweight Kotlin library for stateless device identification and fingerprinting on Android.
A CLI tool that decompiles Android APKs into readable Java source with reconstructed R.* references.
A comprehensive mobile application reverse engineering and analysis framework for security testing against OWASP mobile threats.
An extension of Cuckoo Sandbox that adds automated Android malware analysis capabilities for executing and analyzing Android applications.
A static application security testing (SAST) CLI tool that scans source code for OWASP Top 10 vulnerabilities across multiple programming languages.
A static code analyzer that detects and reports potential malicious behaviors in Android applications.
A blackbox security profiling tool for Android that hooks and analyzes security-sensitive APIs at runtime.
A secure, extensible command-line Android APK vulnerability analyzer written in Rust for automated security testing.
An open-source toolkit for automated dynamic analysis of Android applications by intercepting and modifying API calls.
Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.