Mobileapp Pentest CheatsheetThe Mobile App Pentest cheat sheet was created to provide concise collection of high value information on specific mobile application penetration testing topics.
Werdlists⌨️ Wordlists, Dictionaries and Other Data Sets for Writing Software Security Test Cases
InspeckageAndroid Package Inspector - dynamic analysis with api hooks, start unexported activities and more. (Xposed Module)
R2frida WikiThis repo aims at providing practical examples on how to use r2frida
AstorAutomatic program repair for Java with generate-and-validate techniques ✌️✌️: jGenProg (2014) - jMutRepair (2016) - jKali (2016) - DeepRepair (2017) - Cardumen (2018) - 3sfix (2018)
PandaPlatform for Architecture-Neutral Dynamic Analysis
Awesome FridaAwesome Frida - A curated list of Frida resources http://www.frida.re/ (https://github.com/frida/frida)
MutantAutomated code reviews via mutation testing - semantic code coverage.
RedexerThe Redexer binary instrumentation framework for Dalvik bytecode
AirspyAirSpy - Frida-based tool for exploring and tracking the evolution of Apple's AirDrop protocol implementation on i/macOS, from the server's perspective. Released during BH USA 2019 Training https://www.nowsecure.com/event/advanced-frida-and-radare-a-hackers-delight/
BapBinary Analysis Platform
Mobile Security Framework MobsfMobile Security Framework (MobSF) is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis.
IntellidroidA targeted input generator for Android that improves the effectiveness of dynamic malware analysis.
KiekerKieker's main repository
MjolnerCycript backend powered by Frida.
Fsmonmonitor filesystem on iOS / OS X / Android / FirefoxOS / Linux
JackhammerJackhammer - One Security vulnerability assessment/management tool to solve all the security team problems.
Awesome Symbolic ExecutionA curated list of awesome symbolic execution resources including essential research papers, lectures, videos, and tools.
HabomalhunterHaboMalHunter is a sub-project of Habo Malware Analysis System (https://habo.qq.com), which can be used for automated malware analysis and security assessment on the Linux system.
R2fridaRadare2 and Frida better together.
CrosshairAn analysis tool for Python that blurs the line between testing and type systems.
FromjsSee where each character on the screen came from in code.
SaferwallA hackable malware sandbox for the 21st Century
Symbolic ExecutionHistory of symbolic execution (as well as SAT/SMT solving, fuzzing, and taint data tracking)
EngineDroidefense: Advance Android Malware Analysis Framework
EnlightnYour performance & security consultant, an artisan command away.
Dynamic AnalysisA curated list of dynamic analysis tools for all programming languages, binaries, and more.
MedusaBinary instrumentation framework based on FRIDA
WasabiA dynamic analysis framework for WebAssembly programs.
Compiler RtProject moved to: https://github.com/llvm/llvm-project
DLintRuntime checker for JS coding practices
ethereum-dasmAn ethereum evm bytecode disassembler and static/dynamic analysis tool
mbsimA multi-body simulation software
opemOPEM (Open Source PEM Fuel Cell Simulation Tool)
malossTowards Measuring Supply Chain Attacks on Package Managers for Interpreted Languages
DrCCTProfDrCCTProf is a fine-grained call path profiling framework for binaries running on ARM and X86 architectures.
on-edgeA library for detecting certain improper uses of the "Defer, Panic, and Recover" pattern in Go programs
phuzzFind exploitable PHP files by parameter fuzzing and function call tracing
talvosTalvos is a dynamic-analysis framework and debugger for Vulkan/SPIR-V programs.
r2frida-bookThe radare2 + frida book for Mobile Application assessment
tiroTIRO - A hybrid iterative deobfuscation framework for Android applications
libdft64libdft for Intel Pin 3.x and 64 bit platform. (Dynamic taint tracking, taint analysis)
jitanaA graph-based static-dynamic hybrid DEX code analysis tool
allsafeIntentionally vulnerable Android application.
sortcheckTool for detecting violations of ordering axioms in qsort/bsearch callbacks.
aparoidStatic and dynamic Android application security analysis