Showing 36 of 76 projects
A tool for reverse engineering Android APK files, enabling resource decoding, modification, and smali debugging.
An automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis, and security assessment framework.
A comprehensive manual for mobile app security testing and reverse engineering, aligned with OWASP MASVS and MASWE.
A forensic toolkit for gathering and analyzing traces on Android and iOS devices to identify potential spyware compromise.
A comprehensive, curated collection of tools, research, and resources for Android application security analysis and penetration testing.
A comprehensive, curated collection of tools, research, and resources for Android application security analysis and reverse engineering.
A runtime mobile exploration toolkit powered by Frida for security assessment of iOS and Android apps without jailbreak.
A Python toolkit for reverse engineering, analyzing, and pentesting Android applications (APK, DEX, resources).
A tool to scan APK files for URIs, endpoints, secrets, and sensitive data patterns.
Open-source implementations of one-time passcode generators for Blackberry and iOS, supporting HOTP and TOTP standards.
A comprehensive cheat sheet and tool collection for mobile application penetration testing, mapped to OWASP Mobile Top 10 risks.
A security testing framework for Android that identifies vulnerabilities by interacting with apps, IPC endpoints, and the OS.
A VS Code extension that integrates Android reverse-engineering tools for APK analysis, modification, and debugging.
Securely store passwords, tokens, and sensitive data in React Native apps using iOS Keychain and Android Keystore.
A web interface powered by FRIDA for runtime manipulation, analysis, and security testing of Android and iOS applications.
An Xposed module for dynamic analysis of Android apps via API hooks, unexported activity launching, and runtime inspection.
The OWASP Mobile Application Security Verification Standard (MASVS) is the industry standard for mobile app security.
A React Native bridge for AppAuth SDKs to implement OAuth2 and OpenID Connect authentication with native best practices.
A Burp Suite extension that bridges to Frida, enabling dynamic analysis and manipulation of mobile app traffic using the app's own code.
An automated framework for monitoring and tampering with system API calls of native macOS, iOS, and Android apps using Frida.
A deprecated CLI tool for SSH authentication and Git commit/tag signing using keys stored on a mobile device.
React Native library for biometric authentication (Touch ID and Face ID) on iOS and Android.
A reverse engineering framework for Flutter apps, enabling traffic interception and dynamic analysis via patched Flutter engines.
A runtime mobile application analysis toolkit with a Web GUI, powered by Frida, for dynamic function hooking and intercepting.
A modular, black-box obfuscation tool for Android apps (APK/AAB) that works without source code.
An efficient Android vulnerability scanner that finds security issues and missing best practices in APK files.
A collection of tools and scripts for unpacking and analyzing protected Android applications, originally presented at Defcon 22.
A virtual machine for Android application security assessment, reverse engineering, and malware analysis.
An intentionally insecure Android app designed to teach secure coding and penetration testing through hands-on vulnerability challenges.
A work-in-progress reference guide for Android security topics, tools, and version-specific details.
A comprehensive checklist for designing, testing, and releasing secure Android applications based on OWASP standards.
A cross-platform static code analysis tool for mobile applications (APK/IPA) to find security vulnerabilities like hardcoded credentials and API keys.
A vulnerable Android app aggregating known security vulnerabilities for testing and educational purposes.
A lightweight Kotlin library for stateless device identification and fingerprinting on Android.
A customizable Android library for implementing swipe-based captcha verification with puzzle piece dragging.
A C library providing elliptic curve cryptography optimized for constrained environments like embedded systems and mobile apps.
Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.