There are 83 repositories under android-security topic.
Mobile Security Framework (MobSF) is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis.
Scanning APK file for URIs, endpoints & secrets.
Reverse Engineering Resources About All Platforms(Windows/Linux/macOS/Android/iOS/IoT) And Every Aspect! (More than 3500 open source tools and 2300 posts&videos)
Unlock an Android phone (or device) by bruteforcing the lockscreen PIN. Turn your Kali Nethunter phone into a bruteforce PIN cracker for Android devices! (no root, no adb)
An effort to build a single place for all useful android and iOS security related stuff. All references and tools belong to their respective owners. I'm just maintaining it.
Runtime Mobile Security (RMS) 📱🔥 - is a powerful web interface that helps you to manipulate Android and iOS Apps at Runtime
A curated list of Android Security materials and resources For Pentesters and Bug Hunters
A big list of Android Hackerone disclosed reports and other resources.
The repo contains a series of challenges for learning Frida for Android Exploitation.
[Official] Android reverse engineering tool focused on dynamic instrumentation automation leveraging Frida. It disassembles dex, analyzes it statically, generates hooks, discovers reflected methods, stores intercepted data and does new things from it. Its aim is to be an all-in-one Android reverse engineering platform.
Android security insights in full spectrum.
APKHunt is a comprehensive static code analysis tool for Android apps that is based on the OWASP MASVS framework. Although APKHunt is intended primarily for mobile app developers and security testers, it can be used by anyone to identify and address potential security vulnerabilities in their code.
An OSINT tool to quickly extract IP and URL endpoints from APKs by disassembling and decompiling
Oversecured Vulnerable Android App
A vulnerable Android application that shows simple examples of vulnerabilities in a ctf style.
Damn Vulnerable Bank is designed to be an intentionally vulnerable android application. This provides an interface to assess your android application security hacking skills.
Swiss army knife for identifying and fingerprinting Android devices. MIT license, no restrictions on usage in production.
Android security guides, roadmap, docs, courses, write-ups, and teryaagh.
强大的 Frida 重打包工具,用于 iOS 和 Android。轻松修改 Frida 特征,增强隐蔽性,绕过检测。简化逆向工程和安全测试。Powerful Frida repackaging tool for iOS and Android. Easily modify Frida servers to enhance stealth and bypass detection. Streamlines reverse engineering and security testing.
Static Application Security Testing (SAST) engine focused on covering the OWASP Top 10, to make source code analysis to find vulnerabilities right in the source code, focused on a agile and easy to implement software inside your DevOps pipeline. Support the following technologies: Java (Maven and Android), Kotlin (Android), Swift (iOS), .NET Full Framework, C#, and Javascript (Node.js).
Android Security Suite for in-depth reconnaissance and static bytecode analysis based on Ghera benchmarks.
A large repository of malware samples with 2500+ malware samples & source codes for a variety of platforms by Cryptware Apps.
软件安全工程师技能表
A Collection of Android (Samsung) Security Research References
LockKnife : The Ultimate Android Security Research Tool - Your Gateway to Android Security Research! 🗝️ Dive deep into Android security with this powerful command-line tool designed for researchers/hackers. Recover/Crack lock screen Passwords/Pins/Patterns, extract sensitive data like SMS, Call Logs, Credentials, forensic analysis and more. 🔒💫
PounceKey's is a Accessibility Service keylogger for Android 5 to 15! full launcher stealth. choose between receiving logs via IP, Gmail, or Discord. No txt files on device, straight buffer in logcat. Signal backdoor, best android keylogger!
Android Security Resources.
Its a Simple Social engineering Tool
WhatsApp Spy is an app designed to monitor and log all on-screen texts whenever a user opens WhatsApp / Whatsapp Business. It also supports Instagram and Messenger, sending logs to either Discord or Telegram, without port forwarding.
Frida Script Runner is a versatile web-based tool designed for Android and iOS penetration testing purposes.
Android library to reveal or obfuscate strings and assets at runtime
CWAC-NetSecurity: Simplifying Secure Internet Access
An open source Android application that is intentionally vulnerable so as to act as a learning platform for Android application security beginners.
Django application that performs SAST and Malware Analysis for Android APKs