Skip to content
49

awesome-mobile-security

An effort to build a single place for all useful android and iOS security related stuff. All references and tools belong to their respective owners. I'm just maintaining it.

3.5k stars378 forks244 entriesLast push Mar 1, 2024 (2 years ago)License none

This page lists names, links and short descriptions. The original list on GitHub is the source and belongs to its authors.

Android >General - Blogs, Papers, How To's

Android: Gaining access to arbitrary* Content Providers

Evernote: Universal-XSS, theft of all cookies from all sites, and more

Interception of Android implicit intents

TikTok: three persistent arbitrary code executions and one theft of arbitrary files

Persistent arbitrary code execution in Android's Google Play Core Library: details, explanation and the PoC -…

Android: Access to app protected components

Android: arbitrary code execution via third-party package contexts

Android Pentesting Labs - Step by Step guide for beginners

An Android Hacking Primer

Secure an Android Device

Security tips

OWASP Mobile Security Testing Guide

Security Testing for Android Cross Platform Application

Dive deep into Android Application Security

Pentesting Android Apps Using Frida

Mobile Security Testing Guide

Mobile Application Penetration Testing Cheat Sheet

Android Applications Reversing 101

Android Security Guidelines

Android WebView Vulnerabilities

OWASP Mobile Top 10

Practical Android Phone Forensics

Mobile Reverse Engineering Unleashed

Android Root Detection Bypass Using Objection and Frida Scripts

quark-engine - An Obfuscation-Neglect Android Malware Scoring System

An Obfuscation-Neglect Android Malware Scoring System.

In 4 listsDetails

Root Detection Bypass By Manual Code Manipulation.

Application and Network Usage in Android

GEOST BOTNET - the discovery story of a new Android banking trojan

Mobile Pentesting With Frida

Magisk Systemless Root - Detection and Remediation

AndrODet: An adaptive Android obfuscation detector

Hands On Mobile API Security

Zero to Hero - Mobile Application Testing - Android Platform

How to use FRIDA to bruteforce Secure Startup with FDE-encryption on a Samsung G935F running Android 8

Android Malware Adventures

AAPG - Android application penetration testing guide

Bypassing Android Anti-Emulation

Bypassing Xamarin Certificate Pinning

Configuring Burp Suite With Android Nougat

Android >Books

SEI CERT Android Secure Coding Standard

Android Security Internals

Android Cookbook

Android Hacker's Handbook

Android Security Cookbook

The Mobile Application Hacker's Handbook

Android Malware and Analysis

Android Security: Attacks and Defenses

Android >Courses

Learning-Android-Security

Mobile Application Security and Penetration Testing

Advanced Android Development

Learn the art of mobile app development

Learning Android Malware Analysis

Android App Reverse Engineering 101

In 2 lists

Android Pentesting for Beginners

Android >Tools

Amandroid – A Static Analysis Framework

Androwarn – Yet Another Static Code Analyzer

detects and warns the user about potential malicious behaviors developed by an Android application.

In 3 lists

APK Analyzer – Static and Virtual Analysis Tool

In 2 lists

APK Inspector – A Powerful GUI Tool

In 2 lists

Droid Hunter – Android application vulnerability analysis and Android pentest tool

Error Prone – Static Analysis Tool

Catches common programming mistakes as compile-time errors. License: Apache 2 , .

In 4 listsDetails

Findbugs – Find Bugs in Java Programs

Find Security Bugs – A SpotBugs plugin for security audits of Java web applications.

OWASP - SpotBugs plugin for security audits of Java web applications. Supports Eclipse, IntelliJ, Android Studio and SonarQube.

In 2 lists

Flow Droid – Static Data Flow Tracker

Static taint analysis tool for Android applications.

In 2 lists

Smali/Baksmali – Assembler/Disassembler for the dex format

apk decompilation

In 2 lists

Smali-CFGs – Smali Control Flow Graph’s

In 2 lists

SPARTA – Static Program Analysis for Reliable Trusted Apps

verifies (proves) that an app satisfies an information-flow security policy; built on the Checker Framework

In 2 lists

Thresher – To check heap reachability properties

Vector Attack Scanner – To search vulnerable points to attack

Gradle Static Analysis Plugin

Checkstyle – A tool for checking Java source code

Tool for checking Java source code for adherence to a Code Standard or set of validation rules.

In 4 listsDetails

PMD – An extensible multilanguage static code analyzer

Source code analysis for finding bad coding practices. License: BSD 4.

In 3 lists

Soot – A Java Optimization Framework

Android Quality Starter

QARK – Quick Android Review Kit

Tool to look for several security related Android application vulnerabilities.

In 3 lists

Infer – A Static Analysis tool for Java, C, C++ and Objective-C

MIT 🟢Modern static analysis tool for verifying the correctness of code.

In 5 listsDetails

Android Check – Static Code analysis plugin for Android Project

FindBugs-IDEA Static byte code analysis to look for bugs in Java code

APK Leaks – Scanning APK file for URIs, endpoints & secrets

Scanning APK file for URIs, endpoints & secrets.

In 2 lists

Adhrit - Android Security Suite for in-depth reconnaissance and static bytecode analysis based on Ghera benchmarks

Android Hooker - Opensource project for dynamic analyses of Android applications

Dynamic Java code instrumentation (requires the Substrate Framework)

In 2 lists

AppAudit - Online tool ( including an API) uses dynamic and static analysis

AppAudit - A bare-metal analysis tool on Android devices

CuckooDroid - Extension of Cuckoo Sandbox the Open Source software

Android extension for Cuckoo sandbox

In 2 lists

DroidBox - Dynamic analysis of Android applications

Droid-FF - Android File Fuzzing Framework

Drozer

Marvin - Analyzes Android applications and allows tracking of an app

Inspeckage

Android Package Inspector - dynamic analysis with API hooks, start unexported activities, and more. (Xposed Module)

In 2 lists

PATDroid - Collection of tools and data structures for analyzing Android applications

AndroL4b - Android security virtual machine based on ubuntu-mate

A Virtual Machine for Assessing Android applications, Reverse Engineering and Malware Analysis

In 3 lists

Radare2 - Unix-like reverse engineering framework and commandline tools

UNIX-like reverse engineering framework and command-line toolset

In 3 lists

Cutter - Free and Open Source RE Platform powered by radare2

Free and open source reverse engineering platform powered by Rizin.

In 3 lists

ByteCodeViewer - Android APK Reverse Engineering Suite (Decompiler, Editor, Debugger)

Mobile-Security-Framework MobSF

Mobile Security Framework (MobSF) is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis.

In 5 listsDetails

CobraDroid - Custom build of the Android operating system geared specifically for application security

custom image for malware analysis

In 2 lists

Magisk v20.2 - Root & Universal Systemless Interface

Runtime Mobile Security (RMS) - is a powerful web interface that helps you to manipulate Android and iOS Apps at Runtime

is a powerful web interface that helps you to manipulate Android and iOS Apps at Runtime

In 3 lists

MOBEXLER - A Mobile Application Penetration Testing Platform

Oversecured

A static vulnerability scanner for Android apps (APK files) containing 90+ vulnerability categories

In 3 lists

Android Observatory APK Scan

Android APK Decompiler

AndroTotal

dead

In 2 lists

NVISO ApkScan

sunsetting on Oct 31, 2019

In 2 lists

VirusTotal

VirusTotal, a subsidiary of Google, is a free online service that analyzes files and URLs enabling the identification of viruses, worms, trojans and other kinds of malicious content detected by antivirus engines and website scanners. At the same time, it may be used as a means to detect false…

In 13 listsDetails

Scan Your APK

AVC Undroid

OPSWAT

Scan a file, hash, IP, URL or domain address for malware for free.

In 4 listsDetails

ImmuniWeb Mobile App Scanner

Ostor Lab

Quixxi

TraceDroid

Visual Threat

App Critique

Upload your Android APKs and receive comprehensive free security assessments

In 3 lists

Android >Labs

OVAA (Oversecured Vulnerable Android App)

Oversecured Vulnerable Android App.

In 3 lists

DIVA (Damn insecure and vulnerable App)

Damn Insecure and vulnerable App for Android.

In 3 lists

SecurityShepherd

Damn Vulnerable Hybrid Mobile App (DVHMA)

OWASP-mstg

Is a comprehensive manual for mobile app security development, testing and reverse engineering.

In 4 listsDetails

VulnerableAndroidAppOracle

Android InsecureBankv2

Vulnerable Android application for developers and security enthusiasts to learn about Android insecurities.

In 3 lists

Purposefully Insecure and Vulnerable Android Application (PIIVA)

Sieve app

In 2 lists

DodoVulnerableBank

Digitalbank

Android Digital Bank Vulnerable Mobile App

In 2 lists

OWASP GoatDroid

In 2 lists

AppKnox Vulnerable Application

Vulnerable Android Application

MoshZuk

Hackme Bank

Android Security Labs

Android-security

VulnDroid

FridaLab

Santoku Linux - Mobile Security VM

Santoku is dedicated to mobile forensics, analysis, and security, and packaged in an easy to use, Open Source platform.

In 3 lists

Vuldroid

Android Application covering various static and dynamic vulnerabilities.

In 3 lists

Android >Talks

Blowing the Cover of Android Binary Fuzzing (Slides)

One Step Ahead of Cheaters -- Instrumenting Android Emulators

Vulnerable Out of the Box: An Evaluation of Android Carrier Devices

Rock appround the clock: Tracking malware developers by Android

Chaosdata - Ghost in the Droid: Possessing Android Applications with ParaSpectre

Remotely Compromising Android and iOS via a Bug in Broadcom's Wi-Fi Chipsets

Honey, I Shrunk the Attack Surface – Adventures in Android Security Hardening

Hide Android Applications in Images

Scary Code in the Heart of Android

Fuzzing Android: A Recipe For Uncovering Vulnerabilities Inside System Components In Android

Unpacking the Packed Unpacker: Reverse Engineering an Android Anti-Analysis Native Library

Android FakeID Vulnerability Walkthrough

Unleashing D* on Android Kernel Drivers

The Smarts Behind Hacking Dumb Devices

Overview of common Android app vulnerabilities

Android Dev Summit 2019

Android Dev Summit.

In 2 lists

Android security architecture

Get the Ultimate Privilege of Android Phone

Android >Misc.

Android-Reports-and-Resources

List of Android Hackerone disclosed reports and other resources

In 2 lists

android-security-awesome

A collection of android security related resources. A lot of work is happening in academia and industry on tools to perform dynamic analysis, static analysis and reverse engineering of android apps.

In 5 listsDetails

Android Penetration Testing Courses

Lesser-known Tools for Android Application PenTesting

android-device-check - a set of scripts to check Android device security configuration

apk-mitm - a CLI application that prepares Android APK files for HTTPS inspection

A CLI application that prepares Android APK files for HTTPS inspection

In 2 lists

Andriller - is software utility with a collection of forensic tools for smartphones

a software utility with a collection of forensic tools for smartphones. It performs read-only, forensically sound, non-destructive acquisition from Android devices.

In 4 listsDetails

Dexofuzzy: Android malware similarity clustering method using opcode sequence-Paper

Chasing the Joker

Side Channel Attacks in 4G and 5G Cellular Networks-Slides

Shodan.io-mobile-app for Android

Popular Android Malware 2018

Popular Android Malware 2019

Popular Android Malware 2020

iOS >General - Blogs, Papers, How to's

iOS Security

Basic iOS Apps Security Testing lab

IOS Application security – Setting up a mobile pentesting platform

Collection of the most common vulnerabilities found in iOS applications

IOS_Application_Security_Testing_Cheat_Sheet

OWASP iOS Basic Security Testing

Dynamic analysis of iOS apps w/o Jailbreak

iOS Application Injection

Low-Hanging Apples: Hunting Credentials and Secrets in iOS Apps

Checkra1n Era - series

In 2 lists

BFU Extraction: Forensic Analysis of Locked and Disabled iPhones

HowTo-decrypt-Signal.sqlite-for-IOS

Can I Jailbreak?

How to Extract Screen Time Passcodes and Voice Memos from iCloud

Reverse Engineering Swift Apps

Mettle your iOS with FRIDA

A run-time approach for pentesting iOS applications

iOS Internals vol 2

Understanding usbmux and the iOS lockdown service

A Deep Dive into iOS Code Signing

AirDoS: remotely render any nearby iPhone or iPad unusable

How to access and traverse a #checkra1n jailbroken iPhone File system using SSH

Deep dive into iOS Exploit chains found in the wild - Project Zero

The Fully Remote Attack Surface of the iPhone - Project Zero

iOS >Books

Hacking and Securing iOS Applications: Stealing Data, Hijacking Software, and How to Prevent It

iOS Penetration Testing

iOS App Security, Penetration Testing, and Development

IOS Hacker's Handbook

Charles Miller, Dino DaiZovi, Dion Blazakis, Ralf-Philip Weinmann, and Stefan Esser.

In 2 lists

Hacking iOS Applications a detailed testing guide

In 2 lists

Develop iOS Apps (Swift)

iOS Programming Cookbook

iOS >Courses

Pentesting iOS Applications

Reverse Engineering iOS Applications

App Design and Development for iOS

iOS >Tools

Cydia Impactor

checkra1n jailbreak

idb - iOS App Security Assessment Tool

Frida

Dynamic instrumentation toolkit for developers, reverse-engineers, and security researchers.

In 4 lists

Objection - mobile exploration toolkit by Frida

A runtime mobile exploration toolkit, powered by Frida, built to help you assess the security posture of your mobile applications, without needing a jailbreak

In 5 listsDetails

Bfinject

iFunbox

Libimobiledevice - library to communicate with the services of the Apple ios devices

iRET (iOS Reverse Engineering Toolkit)

includes oTool, dumpDecrypted, SQLite, Theos, Keychain_dumper, Plutil

Myriam iOS

iWep Pro - wireless suite of useful applications used to turn your iOS device into a wireless network diagnostic tool

Burp Suite

Intercept API and Reply with changes in realtime with according api manipulations.

In 3 lists

Cycript

needle - The iOS Security Testing Framework

iLEAPP - iOS Logs, Events, And Preferences Parser

Cutter - Free and Open Source RE Platform powered by radare2

Free and open source reverse engineering platform powered by Rizin.

In 3 lists

decrypt0r - automatically download and decrypt SecureRom stuff

iOS Security Suite - an advanced and easy-to-use platform security & anti-tampering library

iOS >Labs

OWASP iGoat

Damn Vulnerable iOS App (DVIA) v2

Damn Vulnerable iOS App v2 for learning

In 2 lists

Damn Vulnerable iOS App (DVIA) v1

iPhoneLabs

iOS-Attack-Defense

iOS >Talks

Behind the Scenes of iOS Security

Modern iOS Application Security

Demystifying the Secure Enclave Processor

HackPac Hacking Pointer Authentication in iOS User Space

Analyzing and Attacking Apple Kernel Drivers

Remotely Compromising iOS via Wi-Fi and Escaping the Sandbox

Reverse Engineering iOS Mobile Apps

iOS 10 Kernel Heap Revisited

KTRW: The journey to build a debuggable iPhone

The One Weird Trick SecureROM Hates

Tales of old: untethering iOS 11-Spoiler: Apple is bad at patching

Messenger Hacking: Remotely Compromising an iPhone through iMessage

Recreating An iOS 0-Day Jailbreak Out Of Apple's Security Updates

Reverse Engineering the iOS Simulator’s SpringBoard

Attacking iPhone XS Max

iOS >Misc.

Most usable tools for iOS penetration testing

iOS-Security-Guides

osx-security-awesome - OSX and iOS related security tools

OSX and iOS related security tools

In 2 lists

Trust in Apple's Secret Garden: Exploring & Reversing Apple's Continuity Protocol-Slides

Apple Platform Security

Mobile security, forensics & malware analysis with Santoku Linux

See category
94

Awesome Mac

jaywcjlove/awesome-mac

 This project is dedicated to collecting high-quality macOS software and organizing them systematically by different categories for easy search and use.

Fresh★ 115k1316 entriesPushed today
91

Open Source Mac Os Apps

serhii-londar/open-source-mac-os-apps

🚀 Awesome list of open source applications for macOS. https://t.me/s/opensourcemacosapps

Fresh★ 51k700 entriesPushed 20 days ago
91

Awesome-Kubernetes

ramitsurana/awesome-kubernetes

A curated list for awesome kubernetes sources :ship::tada:

Fresh★ 16k47 entriesPushed 8 days ago
90

Awesome Nodejs

sindresorhus/awesome-nodejs

:zap: Delightful Node.js packages and resources [BECAUSE OF TOO MUCH SPAM AND LOW-QUALITY SUBMISSIONS, SUBMISSIONS ARE PAUSED TEMPORARILY]

Fresh★ 67k588 entriesPushed 28 days ago
90

Awesome Home Assistant

frenck/awesome-home-assistant

A curated list of amazingly awesome Home Assistant resources.

Fresh★ 8.5k312 entriesPushed 2 days ago
90

Awesome Ios

vsouza/awesome-ios

A curated list of awesome iOS ecosystem, including Objective-C and Swift Projects

Fresh★ 53k1812 entriesPushed 1 month ago