You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Mobile Security Framework (MobSF) is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis.
APKHunt is a comprehensive static code analysis tool for Android apps that is based on the OWASP MASVS framework. Although APKHunt is intended primarily for mobile app developers and security testers, it can be used by anyone to identify and address potential security vulnerabilities in their code.
Modern offline-first Application Security Intelligence Platform for Android, iOS, Flutter and React Native with attack-chain analysis, explainable findings, source exploration, AI-assisted investigation and professional reporting.
Nutcracker is a powerful, modular and extensible framework designed for mobile security analysis and offensive threat intelligence. Detects and bypasses anti-root/RASP protections, analyzes insecure manifest conf, extracts hardcoded secrets and launches OSINT recon — all in one tool. aligned with MASVS for comprehensive security compliance.
Assessors Studio operationalizes CycloneDX Attestations (CDXA): perform assessments, collect evidence, make claims, and issue machine-readable CycloneDX attestations, optionally legally binding for B2B and B2G use cases.
NutBank is an intentionally vulnerable Android app designed for security research and mobile pentesting demos. Built to showcase nutcracker's RASP bypass capabilities. Features hardcoded secrets, insecure components, and real RASP protections (RootBeer, Frida detection, emulator detection) that nutcracker can detect and bypass.
📱 Damn Vulnerable Mobile App - a single Flutter codebase that builds real native iOS & Android binaries with 200+ intentionally-vulnerable modules mapped to OWASP MASVS/MASTG, Mobile Top 10, CWE, plus LLM & Agentic AI Top 10. For mobile security training, pentest practice, and scanner validation.
Mobile Security Intelligence Platform - Transform mobile app security scans into actionable intelligence with static/dynamic analysis, framework detection, and OWASP MASVS mapping
Check an Android manifest and an iOS Info.plist for risky settings before a store release: debug flags, cleartext traffic, exported components, broad permissions, missing usage descriptions. OWASP MASVS, SARIF, no dependencies.