• Stars
    star
    624
  • Rank 69,300 (Top 2 %)
  • Language
    Go
  • License
    MIT License
  • Created over 3 years ago
  • Updated 7 months ago

Reviews

There are no reviews yet. Be the first to send feedback to the community and the maintainers!

Repository Details

Mobile Hacker's Weapons / A collection of cool tools used by Mobile hackers. Happy hacking , Happy bug-hunting



A collection of cool tools used by Mobile hackers. Happy hacking , Happy bug-hunting

Family project

WebHackersWeapons MobileHackersWeapons

Table of Contents

Weapons

OS Type Name Description Popularity Language
All Analysis RMS-Runtime-Mobile-Security Runtime Mobile Security (RMS) 📱🔥 - is a powerful web interface that helps you to manipulate Android and iOS Apps at Runtime
All Analysis flipper A desktop debugging platform for mobile developers.
All Analysis scrounger Mobile application testing toolkit
All Pentest metasploit-framework Metasploit Framework
All Proxy BurpSuite The BurpSuite
All Proxy hetty Hetty is an HTTP toolkit for security research.
All Proxy httptoolkit HTTP Toolkit is a beautiful & open-source tool for debugging, testing and building with HTTP(S) on Windows, Linux & Mac
All Proxy proxify Swiss Army knife Proxy tool for HTTP/HTTPS traffic capture, manipulation, and replay on the go.
All Proxy zaproxy The OWASP ZAP core project
All RE diff-gui GUI for Frida -Scripts
All RE frida Clone this repo to build Frida
All RE frida-tools Frida CLI tools
All RE fridump A universal memory dumper using Frida
All RE ghidra Ghidra is a software reverse engineering (SRE) framework
All SCRIPTS frida-gadget frida-gadget is a tool that can be used to patch APKs in order to utilize the Frida gadget.
All SCRIPTS frida-scripts A collection of my Frida.re instrumentation scripts to facilitate reverse engineering of mobile apps.
All Scanner Mobile-Security-Framework-MobSF Mobile Security Framework (MobSF) is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis.
All Scanner StaCoAn StaCoAn is a crossplatform tool which aids developers, bugbounty hunters and ethical hackers performing static code analysis on mobile applications.
All Utils watchman Watches files and records, or triggers actions, when they change.
Android Analysis apkleaks Scanning APK file for URIs, endpoints & secrets.
Android Analysis drozer The Leading Security Assessment Framework for Android.
Android Device scrcpy Display and control your Android device
Android Discovery PortAuthority A handy systems and security-focused tool, Port Authority is a very fast Android port scanner. Port Authority also allows you to quickly discover hosts on your network and will display useful network information about your device and other hosts.
Android Monitor Hijacker Aircrack, Airodump, Aireplay, MDK3 and Reaver GUI Application for Android
Android Monitor PCAPdroid No-root network monitor, firewall and PCAP dumper for Android
Android NFC nfcgate An NFC research toolkit application for Android
Android Pentest Kali NetHunter Mobile Penetration Testing Platform
Android RE Apktool A tool for reverse engineering Android apk files
Android RE JEB reverse-engineering platform to perform disassembly, decompilation, debugging, and analysis of code and document files, manually or as part of an analysis pipeline.
Android RE Smali-CFGs Smali Control Flow Graph's
Android RE androguard Reverse engineering, Malware and goodware analysis of Android applications ... and more (ninja !)
Android RE apkx One-Step APK Decompilation With Multiple Backends
Android RE btrace 🔥🔥 btrace(AKA RheaTrace) is a high performance Android trace tool which is based on Systrace, it support to define custom events automatically during building apk and using bhook to provider more native events like IO.
Android RE bytecode-viewer A Java 8+ Jar & Android APK Reverse Engineering Suite (Decompiler, Editor, Debugger & More)
Android RE dex-oracle A pattern based Dalvik deobfuscator which uses limited execution to improve semantic analysis
Android RE dex2jar Tools to work with android .dex and java .class files
Android RE enjarify Enjarify is a tool for translating Dalvik bytecode to equivalent Java bytecode. This allows Java analysis tools to analyze Android applications.
Android RE jadx Dex to Java decompiler
Android RE jd-gui A standalone Java Decompiler GUI
Android RE procyon Procyon is a suite of Java metaprogramming tools, including a rich reflection API, a LINQ-inspired expression tree API for runtime code generation, and a Java decompiler.
Android Scanner qark Tool to look for several security related Android application vulnerabilities
Android Target PlaystoreDownloader A command line tool to download Android applications directly from the Google Play Store by specifying their package name (an initial one-time configuration is required)
Android Target googleplay Download APK from Google Play or send API requests
Android Target gplaycli Google Play Downloader via Command line
Android Target gplaydl Command Line Google Play APK downloader. Download APK files to your PC directly from Google Play Store.
Android Utils Magisk The Magic Mask for Android
Android Utils behe-keyboard A lightweight hacking & programming keyboard with material design
Android Utils termux-app Termux - a terminal emulator application for Android OS extendible by variety of packages.
iOS Analysis iFunBox General file management software for iPhone and other Apple products
iOS Analysis iblessing iblessing is an iOS security exploiting toolkit, it mainly includes application information collection, static analysis and dynamic analysis. It can be used for reverse engineering, binary analysis and vulnerability mining.
iOS Analysis needle The iOS Security Testing Framework
iOS Analysis objection 📱 objection - runtime mobile exploration
iOS Bluetooth toothpicker ToothPicker is an in-process, coverage-guided fuzzer for iOS. for iOS Bluetooth
iOS Bypass Jailbreak A-Bypass Super Jailbreak detection bypass!
iOS Bypass Jailbreak FlyJB-X You can HIDE Doing jailbreak your iDevice.
iOS Bypass Jailbreak HideJB a tweak has the ability to skip jailbreak detection on iOS apps.
iOS Bypass Jailbreak Liberty Bypass Jailbreak and SSL Pinning
iOS Inject bfinject Dylib injection for iOS 11.0 - 11.1.2 with LiberiOS and Electra jailbreaks
iOS RE Clutch Fast iOS executable dumper
iOS RE class-dump Generate Objective-C headers from Mach-O files.
iOS RE frida-ios-dump pull decrypted ipa from jailbreak device
iOS RE iRET iOS Reverse Engineering Toolkit.
iOS RE iSpy A reverse engineering framework for iOS
iOS RE momdec Core Data Managed Object Model Decompiler
iOS Target ipainstaller Install IPA from command line
iOS Unpinning MEDUZA A more or less universal SSL unpinning tool for iOS
iOS Unpinning ssl-kill-switch2 Blackbox tool to disable SSL certificate validation - including certificate pinning - within iOS and OS X Apps
iOS Utils idb idb is a flexible command line interface for automating iOS simulators and devices

Thanks to (Contributor)

I would like to thank everyone who helped with this project 👍😎

More Repositories

1

WebHackersWeapons

⚔️ Web Hacker's Weapons / A collection of cool tools used by Web hackers. Happy hacking , Happy bug-hunting
Ruby
3,581
star
2

dalfox

🌙🦊 Dalfox is a powerful open-source XSS scanner and utility focused on automation.
Go
3,152
star
3

DevSecOps

♾️ Collection and Roadmap for everyone who wants DevSecOps. Hope your DevOps are more safe 😎
Go
1,565
star
4

XSpear

🔱 Powerfull XSS Scanning and Parameter analysis tool&gem
Ruby
1,084
star
5

jwt-hack

🔩 jwt-hack is tool for hacking / security testing to JWT. Supported for En/decoding JWT, Generate payload for JWT attack and very fast cracking(dict/brutefoce)
Go
707
star
6

a2sv

Auto Scanning to SSL Vulnerability
Python
610
star
7

mad-metasploit

Metasploit custom modules, plugins, resource script and.. awesome metasploit collection
Ruby
373
star
8

authz0

🔑 Authz0 is an automated authorization test tool. Unauthorized access can be identified based on URLs and Roles & Credentials.
Go
341
star
9

droid-hunter

(deprecated) Android application vulnerability analysis and Android pentest tool
Ruby
287
star
10

metasploit-autopwn

db_autopwn plugin of metasploit
Ruby
192
star
11

deadfinder

🏴‍☠️ Find dead-links (broken links)
Ruby
123
star
12

RegexPassive

🔭 Collection of regexp pattern for security passive scanning
109
star
13

mzap

⚡️ Multiple target ZAP Scanning
Go
99
star
14

hack-pet

🐰 Managing command snippets for hackers/bug bounty hunters. with pet.
Go
98
star
15

XSS-Payload-without-Anything

XSS Payload without Anything.
92
star
16

gee

🏵 Gee is tool of stdin to each files and stdout. It is similar to the tee command, but there are more functions for convenience. In addition, it was written as go
Go
79
star
17

s3reverse

The format of various s3 buckets is convert in one format. for bugbounty and security testing.
Go
78
star
18

websocket-connection-smuggler

websocket-connection-smuggler
Go
66
star
19

gitls

🖇 Enumerate git repository URL from list of URL / User / Org. Friendly to pipeline
Go
58
star
20

ws-smuggler

WebSocket Connection Smuggler
Go
48
star
21

ras-fuzzer

RAS(RAndom Subdomain) Fuzzer
Go
43
star
22

MemBi

All the members of bugbounty and infosec. If you don't know who to follow, see!
Go
35
star
23

backbomb

💣 Dockerized penetration-testing/bugbounty/app-sec testing environment
Go
33
star
24

hbxss

Security test tool for Blind XSS
Ruby
27
star
25

fuzzstone

My fuzz repo!
JavaScript
23
star
26

action-dalfox

XSS scanning with Dalfox on Github-action
Dockerfile
22
star
27

recon-raven

Reconnaissance tool of Penetration test & Bug Bounty
Ruby
22
star
28

vais

SWF Vulnerability & Information Scanner
HTML
21
star
29

noir

♠️ Noir is an attack surface detector form source code.
Crystal
20
star
30

xssmaze

XSSMaze is a web service designed to test and improve the performance of security testing tools by providing various cases of XSS vulnerabilities.
Crystal
20
star
31

asset-of-hahwul.com

assets for www.hahwul.com
Shell
19
star
32

can-i-protect-xss

Everything about xss protection technology
16
star
33

volt

⚡ Golang library for quick make pentest tools
Go
15
star
34

raven

Automation Hacking & Penetration Testing Suite
Ruby
13
star
35

vunlink

Auto Web Vulnerability Scanning Framework
Ruby
11
star
36

websocket-connection-smuggling-go

websocket-connection-smuggling write in go
Go
10
star
37

hahwul

about me!
9
star
38

zest-env

🐋 Zest CLI Environment
Shell
9
star
39

awesome-zap-extensions

A curated list of amazingly awesome ZAP Extensions
8
star
40

github-aciton-injection-test

This repo is a sample repo for Github Action Injection.
8
star
41

VAHA

Web for security engineer & hacker
7
star
42

buildpack-nmap

install nmap and set alias buildpack of heroku
Shell
6
star
43

jqueen

Go
6
star
44

m2h.js

remote markdown document to html on DOM
JavaScript
6
star
45

zap-cloud-scan

5
star
46

homebrew-dalfox

Ruby
5
star
47

hahwul-testzz

tool, page code for https://www.hahwul.com
HTML
5
star
48

qs-openvpn

quick setup openvpn
Shell
5
star
49

eoyc

Encoding Only Your Choices
Crystal
5
star
50

zaproxy-ruby

A Ruby Implementation and Library for Easy Utilization of ZAP API
Ruby
5
star
51

cyan-snake

Live OS for Physical hacking
Ruby
5
star
52

podopunch

Easy testing from multiple android devices
Python
5
star
53

openvas_install_script

OpenVAS Scanner Install Script on Debian
Shell
5
star
54

rings

Ruby
4
star
55

licaner

Go
4
star
56

homebrew-jwt-hack

Ruby
4
star
57

buildpack-zap-daemon

zap(zed attack proxy) daemon mode buildpack of heroku
Shell
4
star
58

restime

Web page response time checker
Python
4
star
59

exploit-db_to_dokuwiki

exploit-db(edb) convert to dokuwiki template
Python
4
star
60

homebrew-backbomb

backbomb homebrew repository
Ruby
4
star
61

booungJS

Vulnerability analysis to javascript using javascript and web debugger
JavaScript
4
star
62

homebrew-authz0

Ruby
3
star
63

struts2-rce-cve-2017-9805-ruby

cve -2017-9805
Ruby
3
star
64

homebrew-mzap

Ruby
3
star
65

go-github-selfupdate-patched

go get error patched version
Go
3
star
66

crystal-smuggle

Toy :D
Crystal
3
star
67

CaidoTweaks

3
star
68

shooting-scheme

custom scheme testing tool with checklist
3
star
69

ftc

simple copy to file to clipboard
Ruby
3
star
70

action-authz0-test

3
star
71

mycert

Ruby
2
star
72

lab

lab.hahwul.com
2
star
73

homebrew-gee

Ruby
2
star
74

jekyll-securitytxt

Jekyll plugin for security.txt
Ruby
2
star
75

homebrew-s3reverse

Ruby
2
star
76

heroku-buildpack-geckodriver

2
star
77

vuln_test

<video><embed><object><meta><body><script><frame><frameset>
2
star
78

projectsend_r582_webshell

ProjectSend_r582_webshell exploit
Ruby
1
star
79

homebrew-eoyc

Ruby
1
star
80

hlogger

golang logger for hahwul z
Go
1
star
81

caido-crystal

Caido implementation for crystal
Crystal
1
star