![](/assets/headers/header-logo.png)

![](https://img.shields.io/badge/Tools%20%26%20Resources%20Available-123-757575?style=for-the-badge)

## Defensive Security

### Source Code Obfuscation

* [DexGuard](https://www.guardsquare.com/dexguard) - The full spectrum of protection for Android apps.
* [ProGuard](http://android-doc.github.io/tools/help/proguard.html) - Shrinks, optimizes, and obfuscates your code by removing unused code and renaming classes.

---

## Jailbreaking & Rooting

* [canijailbreak](http://canijailbreak.com/) - A website which tells you whether you can jailbreak your iOS device. 
* [Checkra1n](https://checkra.in/) - Jailbreak for iPhone 5s through iPhone X, iOS 12.0 and up. 
* [Chimera](https://chimera.coolstar.org/) - iOS 12 jailbreak to not only feature a CoreTrust bypass so that binaries don't need to be resigned, but to also support A12 devices, including iPhone Xs, iPhone Xr, and the newest iPads. 
* [Double H3lix](https://doubleh3lix.tihmstar.net/) - Jailbreak for 64-bit 10.x devices. 
* [Etason](https://etasonjb.tihmstar.net/) - Jailbreak for all devices running iOS 8.4.1 32 bit. 
* [Evasi0n](https://www.iphonehacks.com/download-evasi0n) - Jailbreak iPhone, iPad or iPod touch on iOS 7.0 – iOS 7.0.6. 
* [H3lix](https://h3lix.tihmstar.net/) - Jailbreak for 32-bit 10.x devices. 
* [Home Depot](http://wall.supplies/) - Jailbreak for iOS 9.x devices. 
* [IPSW](https://ipsw.me/) - Download current and previous versions of Apple's iOS, iPadOS, watchOS, tvOS and audioOS firmware and receive notifications when new firmwares are released. 
* [Magisk](https://github.com/topjohnwu/Magisk) - Magisk is a suite of open source software for customizing Android, supporting devices higher than Android 5.0.
* [Palra1n](https://github.com/palera1n/palera1n) - Jailbreak for arm64 devices on iOS 15.0+ . ![last-commit](https://img.shields.io/github/last-commit/palera1n/palera1n?style=flat)
* [Pangu Jailbreak](http://en.9.pangu.io/) - Jailbreak for iOS 9.0 - 9.1. 
* [Phoenix](https://phoenixpwn.com/) - Semi-untethered jailbreak for 9.3.5-9.3.6. All 32-bit devices supported. 
* [p0sixspwn](https://ih8sn0w.com/p0sixspwn.html) - iOS Jailbreak for 6.1.X. 
* [redsn0w](https://ipsw.me/iPhoneDev) - Jailbreak for iOS 3-5. 
* [TaiG](http://www.taig.com/) - Jailbreak for iOS 8.X. 
* [unc0ver](https://unc0ver.dev/) - A jail​break tool. 

---

## Offensive Security

### App/File Management

* [adb](https://source.android.com/setup/build/adb) - Allows you to install packages and evaluate your changes. 
* [Airdroid](https://www.airdroid.com/en/pricing/airdroid-personal/) - Transfer files across devices, remote control Android devices, mirror screen, and manage SMS & notification on computer. 
* [Android File Transfer](https://www.android.com/filetransfer/) - Browse and transfer files between your Mac computer and your Android device. 
* [iExplorer](https://macroplant.com/iexplorer) - Transfers music, messages, photos, files and everything else. 
* [iFunbox](https://www.i-funbox.com/en/index.html) - General file management software for iPhone and other Apple products. 
* [iMazing](https://imazing.com/) - Powerful user-friendly iOS device manager for Mac and PC. 

### Bug Bounty Reports

* [Android Reports & Reports](https://github.com/B3nac/Android-Reports-and-Resources) - Android reports and resources. ![last-commit](https://img.shields.io/github/last-commit/B3nac/Android-Reports-and-Resources?style=flat)

### Dynamic Analysis

* [Bytecode Viewer](https://github.com/konloch/bytecode-viewer) - A lightweight user friendly Java Bytecode Viewer. ![last-commit](https://img.shields.io/github/last-commit/konloch/bytecode-viewer?style=flat)
* [CuckooDroid](https://github.com/idanr1986/cuckoo-droid) - Automated Android Malware Analysis with Cuckoo Sandbox. ![last-commit](https://img.shields.io/github/last-commit/idanr1986/cuckoo-droid?style=flat)
* [Cutter](https://github.com/rizinorg/cutter) - Reverse engineering platform powered by rizin. ![last-commit](https://img.shields.io/github/last-commit/rizinorg/cutter?style=flat)
* [DECAF](https://github.com/decaf-project/DECAF) - DECAF \(short for Dynamic Executable Code Analysis Framework\) is a binary analysis platform based on QEMU. ![last-commit](https://img.shields.io/github/last-commit/decaf-project/DECAF?style=flat)
* [Diggy](https://github.com/s0md3v/Diggy) - Extract endpoints from apk files. ![last-commit](https://img.shields.io/github/last-commit/s0md3v/Diggy?style=flat)
* [Droid-FF](https://github.com/antojoseph/droid-ff) - The android fuzzing framework. ![last-commit](https://img.shields.io/github/last-commit/antojoseph/droid-ff?style=flat)
* [Drozer](https://github.com/FSecureLABS/drozer) - Security testing framework for Android. ![last-commit](https://img.shields.io/github/last-commit/FSecureLABS/drozer?style=flat)
* [Frida](https://github.com/frida/frida) - Dynamic instrumentation toolkit for developers, reverse-engineers, and security researchers. ![last-commit](https://img.shields.io/github/last-commit/frida/frida?style=flat)
* [Hooker](https://github.com/AndroidHooker/hooker) - Provides various tools and applications that can be use to automatically intercept and modify any API calls. ![last-commit](https://img.shields.io/github/last-commit/AndroidHooker/hooker?style=flat)
* [House](https://github.com/nccgroup/house) - A runtime mobile application analysis toolkit with a Web GUI, powered by Frida, written in Python. ![last-commit](https://img.shields.io/github/last-commit/nccgroup/house?style=flat)
* [Inspeckage](https://github.com/ac-pm/Inspeckage) - Tool developed to offer dynamic analysis of Android applications. ![last-commit](https://img.shields.io/github/last-commit/ac-pm/Inspeckage?style=flat)
* [MobSF](https://github.com/MobSF/Mobile-Security-Framework-MobSF) - An automated, all-in-one mobile application \(Android/iOS/Windows\) pen-testing, malware analysis and security assessment framework. ![last-commit](https://img.shields.io/github/last-commit/MobSF/Mobile-Security-Framework-MobSF?style=flat)
* [PATDroid](https://github.com/mingyuan-xia/PATDroid) - A collection of tools and data structures for analyzing Android applications and the system itself. ![last-commit](https://img.shields.io/github/last-commit/mingyuan-xia/PATDroid?style=flat)
* [ProbeDroid](https://github.com/ZSShen/ProbeDroid) - A dynamic Java code instrumentation for Android apps. Provides APIs for users to craft their own instrumentation tools. ![last-commit](https://img.shields.io/github/last-commit/ZSShen/ProbeDroid?style=flat)
* [radare2](https://github.com/radareorg/radare2) - Set of libraries, tools and plugins to ease reverse engineering tasks. ![last-commit](https://img.shields.io/github/last-commit/radareorg/radare2?style=flat)
* [Runtime Mobile Security \(RMS\)](https://github.com/m0bilesecurity/RMS-Runtime-Mobile-Security) - Powered by FRIDA a powerful web interface that helps you to manipulate Android and iOS Apps at Runtime. ![last-commit](https://img.shields.io/github/last-commit/m0bilesecurity/RMS-Runtime-Mobile-Security?style=flat)

### Flashing/Sideloading

* [Cydia Impactor](http://www.cydiaimpactor.com/) - Use this tool to install IPA files on iOS and APK files on Android. 
* [Odin](https://odindownload.com/) - Used to flash a custom recovery firmware image to a Samsung Android device. 

### Guides & References

* [Android Application Penetration Testing Checklist](https://www.xmind.net/m/GkgaYH/#) - Android pentesting checklist mindmap. 
* [iOS Pentesting](https://www.mindmeister.com/1713501700/ios-pentesting?fullscreen=1) - iOS pentesting mindmap. 

### Labs/Practice

* [DIVA](http://www.decompileandroid.com/) - DIVA \(Damn insecure and vulnerable App\) is an Android App intentionally designed to be insecure. 
* [DVHMA](https://github.com/logicalhacking/DVHMA) - Damn Vulnerable Hybrid Mobile App \(DVHMA\) is an hybrid mobile app \(for Android\) that intentionally contains vulnerabilities. ![last-commit](https://img.shields.io/github/last-commit/logicalhacking/DVHMA?style=flat)
* [Injured Android](https://github.com/B3nac/InjuredAndroid) - A vulnerable Android application that shows simple examples of vulnerabilities in a ctf style. ![last-commit](https://img.shields.io/github/last-commit/B3nac/InjuredAndroid?style=flat)
* [InsecureBank v2](https://github.com/dineshshetty/Android-InsecureBankv2) - Vulnerable Android application for developers and security enthusiasts to learn about Android insecurities. ![last-commit](https://img.shields.io/github/last-commit/dineshshetty/Android-InsecureBankv2?style=flat)
* [Oversecured Vulnerable Android App](https://github.com/oversecured/ovaa) - An Android app that aggregates all the platform's known and popular security vulnerabilities. ![last-commit](https://img.shields.io/github/last-commit/oversecured/ovaa?style=flat)
* [UnCrackable Apps](https://github.com/OWASP/owasp-mstg) - A collection of mobile reverse engineering challenges for iOS and Android. ![last-commit](https://img.shields.io/github/last-commit/OWASP/owasp-mstg?style=flat)
* [Vuldroid](https://github.com/jaiswalakshansh/Vuldroid) - Vuldroid is a Vulnerable Android Application made with security issues in order to demonstrate how they can occur in code. ![last-commit](https://img.shields.io/github/last-commit/jaiswalakshansh/Vuldroid?style=flat)
* [VyAPI](https://github.com/appsecco/VyAPI) - The Modern Cloud-Based Vulnerable Hybrid Android App. ![last-commit](https://img.shields.io/github/last-commit/appsecco/VyAPI?style=flat)
* [WaTF-Bank](https://github.com/WaTF-Team/WaTF-Bank) - What a Terrible Failure Mobile Banking Application for Android and iOS. ![last-commit](https://img.shields.io/github/last-commit/WaTF-Team/WaTF-Bank?style=flat)

### Online Services

* [Android APK Decompiler](http://www.decompileandroid.com/) - Online android decompiler 
* [Ostorlab](https://oversecured.com/) - Online static taint analysis, 3rd party fingerprinting, and vulnerability analysis. 
* [Oversecured](https://oversecured.com/) - Android mobile app analyzer vulnerability scanner, designed for DevOps process integration. 
* [Quixxi](https://quixxisecurity.com/) - An intelligent and integrated end-to-end mobile app security solution. 

### Post Exploitation (Android)

* [dmesg](https://github.com/DreamDevLost/classdumpios) - Prints Android kernel messages. Already installed on device. ![last-commit](https://img.shields.io/github/last-commit/DreamDevLost/classdumpios?style=flat)
* [Dumpsys](https://developer.android.com/studio/command-line/dumpsys) - a tool that runs on Android devices and provides information about system services. Already installed on device. 
* [EggShell](https://github.com/neoneggplant/EggShell) - iOS/macOS/Linux Remote Administration Tool. ![last-commit](https://img.shields.io/github/last-commit/neoneggplant/EggShell?style=flat)
* [jarsigner](https://github.com/Jamling/jarsigner) - Jar, Android apk, Eclipse RCP signer. ![last-commit](https://img.shields.io/github/last-commit/Jamling/jarsigner?style=flat)
* [keystore-explorer](https://github.com/kaikramer/keystore-explorer) - GUI replacement for the Java command-line utilities keytool and jarsigner. ![last-commit](https://img.shields.io/github/last-commit/kaikramer/keystore-explorer?style=flat)
* [MITMProxy](https://github.com/mitmproxy/mitmproxy) - An interactive TLS-capable intercepting HTTP proxy for penetration testers. ![last-commit](https://img.shields.io/github/last-commit/mitmproxy/mitmproxy?style=flat)
* [Plistsubtractor](https://github.com/joswr1ght/plistsubtractor) - Read a plist file, write out any embedded plist files. ![last-commit](https://img.shields.io/github/last-commit/joswr1ght/plistsubtractor?style=flat)
* [ProxyDroid](https://github.com/madeye/proxydroid) - Global Proxy for Android. ![last-commit](https://img.shields.io/github/last-commit/madeye/proxydroid?style=flat)
* [Simplify](https://github.com/CalebFenton/simplify) - Android virtual machine and deobfuscator. ![last-commit](https://img.shields.io/github/last-commit/CalebFenton/simplify?style=flat)
* [TCPDump](https://github.com/the-tcpdump-group/tcpdump) - The TCPdump network dissector. ![last-commit](https://img.shields.io/github/last-commit/the-tcpdump-group/tcpdump?style=flat)

### Post Exploitation (iOS)

* [BinaryCookieReader](https://github.com/as0ler/BinaryCookieReader) - A tool to read the binarycookie format of Cookies on iOS applications. ![last-commit](https://img.shields.io/github/last-commit/as0ler/BinaryCookieReader?style=flat)
* [ClassDumpiOS](https://github.com/DreamDevLost/classdumpios) - iOS port from nygard/class-dump. ![last-commit](https://img.shields.io/github/last-commit/DreamDevLost/classdumpios?style=flat)
* [Cycript](http://www.cycript.org/) - Explore and modify running applications on either iOS or Mac OS X using a hybrid of Objective-C++ and JavaScript. ![last-commit](https://img.shields.io/github/last-commit/as0ler/BinaryCookieReader?style=flat)
* [DumpDecrypted](https://github.com/stefanesser/dumpdecrypted) - Dumps decrypted mach-o files from encrypted iPhone applications from memory to disk. ![last-commit](https://img.shields.io/github/last-commit/stefanesser/dumpdecrypted?style=flat)
* [EggShell](https://github.com/neoneggplant/EggShell) - iOS/macOS/Linux Remote Administration Tool. ![last-commit](https://img.shields.io/github/last-commit/neoneggplant/EggShell?style=flat)
* [KTool](https://github.com/KritantaDev/ktool) - Cross-platform MachO/ObjC Static binary analysis tool & library. class-dump + otool + lipo + more. ![last-commit](https://img.shields.io/github/last-commit/KritantaDev/ktool?style=flat)
* [lipo](https://opensource.apple.com/source/cctools/cctools-921/misc/lipo.c.auto.html) - Used to thin out un-used code. 
* [MITMProxy](https://github.com/mitmproxy/mitmproxy) - An interactive TLS-capable intercepting HTTP proxy for penetration testers. ![last-commit](https://img.shields.io/github/last-commit/mitmproxy/mitmproxy?style=flat)
* [MobileAssistant](https://portswigger.net/burp/documentation/desktop/tools/mobile-assistant/installing) - A tool to facilitate testing of iOS apps with Burp Suite. 
* [Needle](https://github.com/FSecureLABS/needle) - The iOS Security Testing Framework. ![last-commit](https://img.shields.io/github/last-commit/FSecureLABS/needle?style=flat)
* [Objection](https://github.com/atomicobject/objection/) - A lightweight dependency injection framework for Objective-C. ![last-commit](https://img.shields.io/github/last-commit/atomicobject/objection?style=flat)
* [RVICTL](https://github.com/gh2o/rvi_capture) - Capture packets sent/received by iOS devices. ![last-commit](https://img.shields.io/github/last-commit/gh2o/rvi_capture?style=flat)
* [Sileo](https://getsileo.app/) - A fast, beautiful, powerful and efficient APT Package Manager designed for jailbroken device. 
* [SSLKillSwitch](https://github.com/iSECPartners/ios-ssl-kill-switch) - Blackbox tool to disable SSL certificate validation. ![last-commit](https://img.shields.io/github/last-commit/iSECPartners/ios-ssl-kill-switch?style=flat)
* [SSLKillSwitch2](https://github.com/nabla-c0d3/ssl-kill-switch2) - Blackbox tool to disable SSL certificate validation. ![last-commit](https://img.shields.io/github/last-commit/nabla-c0d3/ssl-kill-switch2?style=flat)
* [TCPDump](https://github.com/the-tcpdump-group/tcpdump) - The TCPdump network dissector. ![last-commit](https://img.shields.io/github/last-commit/the-tcpdump-group/tcpdump?style=flat)

### Reverse Engineering 

* [bfdecrypt](https://github.com/BishopFox/bfdecrypt) - Utility to decrypt App Store apps on jailbroken iOS 11.x ![last-commit](https://img.shields.io/github/last-commit/BishopFox/bfdecrypt?style=flat)
* [Clutch](https://github.com/KJCracks/Clutch) - Fast iOS executable dumper. ![last-commit](https://img.shields.io/github/last-commit/KJCracks/Clutch?style=flat)
* [flexdecrypt](https://github.com/JohnCoates/flexdecrypt) - Decrypt iOS Apps and Mach-O binaries. ![last-commit](https://img.shields.io/github/last-commit/NyaMisty/fouldecrypt?style=flat)
* [FoulDecrypt](https://github.com/NyaMisty/fouldecrypt) - A lightweight and simpling iOS binary decryptor. ![last-commit](https://img.shields.io/github/last-commit/NyaMisty/fouldecrypt?style=flat)
* [r2flutch](https://github.com/as0ler/r2flutch) - Tool to decrypt iOS apps using r2frida. ![last-commit](https://img.shields.io/github/last-commit/as0ler/r2flutch?style=flat)

### Static Analysis

* [Android Check](https://github.com/noveogroup/android-check) - Static code analysis plugin for Android project. ![last-commit](https://img.shields.io/github/last-commit/noveogroup/android-check?style=flat)
* [Androwarn](https://github.com/maaaaz/androwarn) - Static code analyzer for malicious Android applications. ![last-commit](https://img.shields.io/github/last-commit/maaaaz/androwarn?style=flat)
* [APKLab](https://github.com/APKLab/APKLab) - A tool for reverse engineering 3rd party, closed, binary Android apps. ![last-commit](https://img.shields.io/github/last-commit/APKLab/APKLab?style=flat)
* [APKLeaks](https://github.com/dwisiswant0/apkleaks) - Scanning APK file for URIs, endpoints & secrets. ![last-commit](https://img.shields.io/github/last-commit/dwisiswant0/apkleaks?style=flat)
* [APK Studio](https://github.com/vaibhavpandeyvpz/apkstudio) - The objective of this scanner is to find for misconfiguration, sensitive data and insecure components. ![last-commit](https://img.shields.io/github/last-commit/vaibhavpandeyvpz/apkstudio?style=flat)
* [APKTool](https://ibotpeaches.github.io/Apktool/) - Seamlessly integrates the best open-source tools right inside VS Code. 
* [Argus-SAF](https://github.com/arguslab/Argus-SAF) - Static analysis framework. ![last-commit](https://img.shields.io/github/last-commit/arguslab/Argus-SAF?style=flat)
* [Checkstyle](https://github.com/checkstyle/checkstyle) - A tool for checking Java source code for adherence to a Code Standard or set of validation rules. ![last-commit](https://img.shields.io/github/last-commit/checkstyle/checkstyle?style=flat)
* [DeGuard](http://apk-deguard.com/) - Statistical Deobfuscation for Android. 
* [Deoptfuscator](https://github.com/Gyoonus/deoptfuscator) - Reverse the control-flow obfuscation performed by DexGuard on open-source Android applications. ![last-commit](https://img.shields.io/github/last-commit/Gyoonus/deoptfuscator?style=flat)
* [Droid-Hunter](https://github.com/hahwul/droid-hunter) - Android application vulnerability analysis and Android pentest tool. ![last-commit](https://img.shields.io/github/last-commit/hahwul/droid-hunter?style=flat)
* [Error Prone](https://github.com/google/error-prone) - Error Prone is a static analysis tool for Java that catches common programming mistakes at compile-time. ![last-commit](https://img.shields.io/github/last-commit/google/error-prone?style=flat)
* [FindBugs](http://findbugs.sourceforge.net/downloads.html) - Uses static analysis to inspect Java bytecode for occurrences of bug patterns. 
* [Find Security Bugs](https://github.com/find-sec-bugs/find-sec-bugs) - Find Security Bugs is the SpotBugs plugin for security audits of Java web applications. ![last-commit](https://img.shields.io/github/last-commit/find-sec-bugs/find-sec-bugs?style=flat)
* [FlowDroid](https://github.com/secure-software-engineering/FlowDroid) - Statically computes data flows in Android apps and Java programs. ![last-commit](https://img.shields.io/github/last-commit/secure-software-engineering/FlowDroid?style=flat)
* [Gradle](https://github.com/novoda/gradle-static-analysis-plugin) - Supports many popular static analysis \(Checkstyle, PMD, FindBugs, etc\) via a set of built-in plugins. ![last-commit](https://img.shields.io/github/last-commit/novoda/gradle-static-analysis-plugin?style=flat)
* [Infer](https://github.com/facebook/infer) - Infer is a static analysis tool for Java, C++, Objective-C, and C. Infer is written in OCaml. ![last-commit](https://img.shields.io/github/last-commit/facebook/infer?style=flat)
* [JADX](https://github.com/skylot/jadx) - Dex to Java decompiler. ![last-commit](https://img.shields.io/github/last-commit/skylot/jadx?style=flat)
* [Mobile Audit](https://github.com/mpast/mobileAudit) - SAST and Malware Analysis for Android Mobile APKs. ![last-commit](https://img.shields.io/github/last-commit/mpast/mobileAudit?style=flat)
* [MobSF](https://github.com/MobSF/Mobile-Security-Framework-MobSF) - An automated, all-in-one mobile application \(Android/iOS/Windows\) pen-testing, malware analysis and security assessment framework. ![last-commit](https://img.shields.io/github/last-commit/MobSF/Mobile-Security-Framework-MobSF?style=flat)
* [PMD](https://github.com/pmd/pmd) - Finds common programming flaws like unused variables, empty catch blocks, unnecessary object creation, and so forth. ![last-commit](https://img.shields.io/github/last-commit/pmd/pmd?style=flat)
* [Qark](https://github.com/linkedin/qark) - designed to look for several security related Android application vulnerabilities, either in source code or packaged APKs. ![last-commit](https://img.shields.io/github/last-commit/linkedin/qark?style=flat)
* [Quark](https://github.com/quark-engine/quark-engine) - An Obfuscation-Neglect Android Malware Scoring System. ![last-commit](https://img.shields.io/github/last-commit/quark-engine/quark-engine?style=flat)
* [Smali](https://github.com/JesusFreke/smali) - An assembler/disassembler for the dex format used by dalvik, Android's Java VM implementation. ![last-commit](https://img.shields.io/github/last-commit/JesusFreke/smali?style=flat)
* [Soot](https://github.com/soot-oss/soot) - Smali Control Flow Graph's ![last-commit](https://img.shields.io/github/last-commit/soot-oss/soot?style=flat)
* [Sparta](https://github.com/typetools/sparta) - Static program analysis for reliable trusted apps. ![last-commit](https://img.shields.io/github/last-commit/typetools/sparta?style=flat)
* [StaCoAn](https://github.com/vincentcox/StaCoAn) - A crossplatform tool which aids developers, bugbounty hunters and ethical hackers performing static code analysis on mobile applications ![last-commit](https://img.shields.io/github/last-commit/vincentcox/StaCoAn?style=flat)
* [Trueseeing](https://github.com/monolithworks/trueseeing) - A fast, accurate and resillient vulnerabilities scanner for Android apps. ![last-commit](https://img.shields.io/github/last-commit/monolithworks/trueseeing?style=flat)
* [Yaazhini](https://www.vegabird.com/yaazhini/) - A fast, accurate and resillient vulnerabilities scanner for Android apps.

### Video Content

* [B3nac Sec](https://www.youtube.com/c/B3nacSec/featured) - Dedicated mobile ethical hacking 

### Virtualization

* [Android Tamer](https://androidtamer.com/) - Live Platform for Android Security professionals. 
* [AppUse](https://appsec-labs.com/appuse/) - Mobile app security testing, Android and iOS applications. Custom-made tools and scripts created by AppSec Labs. 

### Whitepapers

* [Android Rooting:Methods, Detection, and Evastion](http://lersse-dl.ece.ubc.ca/record/310/files/p3.pdf) - Written by San-Tsai Sun, Andrea Cuadros, and Konstantin Beznosov. 
