Category: Smartphone PenTest
OWASP Security Shepherd The OWASP Security Shepherd Project is a web and mobile application security training platform. Security Shepherd has been designed to foster and improve security awareness among a varied skill-set...
scrounger – a person who borrows from or lives of others. There is no better description for this tool for two main reasons, the first is because this tool takes inspiration...
StaCoAn is a cross-platform tool which aids developers, bug-bounty hunters and ethical hackers performing static code analysis on mobile applications*. This tool will look for interesting lines in the code which can contain: Hardcoded...
backdoor-apk is a shell script that simplifies the process of adding a backdoor to any Android APK file. Users of this shell script should have the working knowledge of Linux,...
House: A runtime mobile application analysis toolkit with a Web GUI, powered by Frida, written in Python. It is designed for helping assess mobile applications by implementing dynamic function hooking and...
DROID-HUNTER 1. DROID-HUNTER Android application vulnerability analysis and Android pentest tool A. Support > App info check > Baksmaling android app > Decompile android app > Extract class file >...
Android-InsecureBankv2 This is a major update to one of my previous projects – “InsecureBank”. This vulnerable Android application is named “InsecureBankv2” and is made for security enthusiasts and developers to...
DVIA-v2 DVIA-v2 written in Swift along with additional vulnerabilities Damn Vulnerable iOS App (DVIA) is an iOS application that is damn vulnerable. Its main goal is to provide a platform...
OWASP iGoat – A Learning Tool for iOS App Pentesting and Security iGoat is a learning tool for iOS developers (iPhone, iPad, etc.) and mobile app pentesters. It was inspired...
txtool is made to help you for easily pentesting in termux, build on termux and only available for termux. It includes many tools to help you in your penetration testing...
Droid Application Fuzz Framework Droid Application Fuzz Framework (DAFF) helps you to fuzz Android Browsers and PDF Readers for memory corruption bugs in real Android devices. You can use the...
Agrigento Agrigento is based on black-box differential analysis, and it works in two steps: first, it establishes a baseline of the network behavior of an app; then, it modifies sources...
AppMon is an automated framework for monitoring and tampering system API calls of native macOS, iOS, and Android apps. It is based on Frida. This project was only possible because of Ole...
AndroTickler A java tool that helps to pentest Android apps faster, more easily and more efficiently. AndroTickler offers many features of information gathering, static and dynamic checks that cover most...
On this post, I want to introduce a small tip when you create an android payload with Metasploit. How to autohide Android payload icon after running Update Metasploit to latest...