APKLeaks
dwisiswant0
Command line scanner that decompiles an Android APK and pattern matches the output for hardcoded URIs, API keys and other secrets.
Mobile Security
Analyze, instrument and harden Android and iOS applications.
23 tools profiled
How it differs Analyses Android and iOS app binaries, statically and at runtime. The backend APIs an app calls belong to API security or DAST.
dwisiswant0
Command line scanner that decompiles an Android APK and pattern matches the output for hardcoded URIs, API keys and other secrets.
Apktool project
Reverse engineering tool that decodes Android APK resources and DEX bytecode to editable form and rebuilds a working package from them.
Appdome
Build service that injects runtime self protection, anti tampering and obfuscation into compiled iOS and Android binaries without source code changes.
Appknox
Mobile application security platform that scans uploaded iOS and Android binaries statically and dynamically and maps findings to compliance frameworks.
Corellium
Arm virtualization platform that runs real iOS and Android firmware as instrumented virtual devices for security research and dynamic analysis.
Data Theorem
Continuous mobile application security platform that scans pre release and published builds dynamically and maps the backend APIs those apps call.
Reversec
Android security assessment framework that uses an on device agent to enumerate and interact with exported app components and IPC endpoints.
eShard
Mobile application security testing service that runs automated attacks against builds on real devices to measure how well their runtime protections hold.
Frida project
Dynamic instrumentation toolkit that injects a scriptable JavaScript engine into running processes to hook, trace and rewrite behavior at runtime.
National Security Agency
Software reverse engineering suite with a multi architecture disassembler and decompiler, released as open source by the NSA.
Guardsquare
Mobile application protection suite providing code obfuscation, encryption and runtime self protection for Android and iOS, alongside the open source ProGuard.
Cryptic Apps
Desktop disassembler and decompiler for macOS and Linux, widely used for analyzing Mach-O binaries from iOS and macOS applications.
dwisiswant0
Command line scanner that decompiles an Android APK and pattern matches the output for hardcoded URIs, API keys and other secrets.
Apktool project
Reverse engineering tool that decodes Android APK resources and DEX bytecode to editable form and rebuilds a working package from them.
Appdome
Build service that injects runtime self protection, anti tampering and obfuscation into compiled iOS and Android binaries without source code changes.
Appknox
Mobile application security platform that scans uploaded iOS and Android binaries statically and dynamically and maps findings to compliance frameworks.
Corellium
Arm virtualization platform that runs real iOS and Android firmware as instrumented virtual devices for security research and dynamic analysis.
Data Theorem
Continuous mobile application security platform that scans pre release and published builds dynamically and maps the backend APIs those apps call.
Reversec
Android security assessment framework that uses an on device agent to enumerate and interact with exported app components and IPC endpoints.
eShard
Mobile application security testing service that runs automated attacks against builds on real devices to measure how well their runtime protections hold.
Frida project
Dynamic instrumentation toolkit that injects a scriptable JavaScript engine into running processes to hook, trace and rewrite behavior at runtime.
National Security Agency
Software reverse engineering suite with a multi architecture disassembler and decompiler, released as open source by the NSA.
Guardsquare
Mobile application protection suite providing code obfuscation, encryption and runtime self protection for Android and iOS, alongside the open source ProGuard.
Cryptic Apps
Desktop disassembler and decompiler for macOS and Linux, widely used for analyzing Mach-O binaries from iOS and macOS applications.
skylot
Decompiler that converts Android DEX bytecode into readable Java source, with a command line tool and a graphical browser for APKs.
mitmproxy project
Interactive HTTPS proxy that intercepts, inspects, modifies and replays traffic, with a Python addon API for scripted manipulation.
MobSF project
Self hosted framework that performs automated static and dynamic security analysis of Android and iOS application binaries and produces a consolidated report.
Nandee
SaaS platform that scans Android and iOS codebases for mobile-specific vulnerability classes and proposes code-level fixes.
NowSecure
Mobile application security platform that runs automated static and dynamic testing on real devices and reports against recognized mobile testing standards.
SensePost
Runtime mobile exploration toolkit built on dynamic instrumentation, offering common iOS and Android assessment tasks as ready made commands.
Ostorlab
Mobile application scanner that pairs static binary analysis with instrumented dynamic testing on an extensible agent based engine.
Oversecured
Static analysis service that traces untrusted data through compiled Android and iOS binaries to find exploitable inter-component vulnerabilities.
radare2 project
Open source reverse engineering framework for disassembling, patching and debugging binaries across a wide range of architectures and file formats.
Talsec
Mobile runtime application self-protection SDK that detects tampering, hooking, rooted or jailbroken devices and emulated environments.
Zimperium
Automated scanner that analyzes compiled Android and iOS builds for security, privacy and compliance issues inside the release pipeline.
skylot
Decompiler that converts Android DEX bytecode into readable Java source, with a command line tool and a graphical browser for APKs.
mitmproxy project
Interactive HTTPS proxy that intercepts, inspects, modifies and replays traffic, with a Python addon API for scripted manipulation.
MobSF project
Self hosted framework that performs automated static and dynamic security analysis of Android and iOS application binaries and produces a consolidated report.
Nandee
SaaS platform that scans Android and iOS codebases for mobile-specific vulnerability classes and proposes code-level fixes.
NowSecure
Mobile application security platform that runs automated static and dynamic testing on real devices and reports against recognized mobile testing standards.
SensePost
Runtime mobile exploration toolkit built on dynamic instrumentation, offering common iOS and Android assessment tasks as ready made commands.
Ostorlab
Mobile application scanner that pairs static binary analysis with instrumented dynamic testing on an extensible agent based engine.
Oversecured
Static analysis service that traces untrusted data through compiled Android and iOS binaries to find exploitable inter-component vulnerabilities.
radare2 project
Open source reverse engineering framework for disassembling, patching and debugging binaries across a wide range of architectures and file formats.
Talsec
Mobile runtime application self-protection SDK that detects tampering, hooking, rooted or jailbroken devices and emulated environments.
Zimperium
Automated scanner that analyzes compiled Android and iOS builds for security, privacy and compliance issues inside the release pipeline.