AppSecNews

Mobile Security

Mobile Application Security

Analyze, instrument and harden Android and iOS applications.

23 tools profiled

How it differs Analyses Android and iOS app binaries, statically and at runtime. The backend APIs an app calls belong to API security or DAST.

License
Subcategory
Deployment
Languages
Integrations
Maturity
Signals
Clear

11 tools match

  • APKLeaks

    dwisiswant0

    Mobile Security

    Command line scanner that decompiles an Android APK and pattern matches the output for hardcoded URIs, API keys and other secrets.

    Open source
    Growing
  • Apktool

    Apktool project

    Mobile Security

    Reverse engineering tool that decodes Android APK resources and DEX bytecode to editable form and rebuilds a working package from them.

    Open source
    Established Verified
  • Drozer

    Reversec

    Mobile Security

    Android security assessment framework that uses an on device agent to enumerate and interact with exported app components and IPC endpoints.

    Open source
    Established
  • Frida

    Frida project

    Mobile Security

    Dynamic instrumentation toolkit that injects a scriptable JavaScript engine into running processes to hook, trace and rewrite behavior at runtime.

    Open source
    Established Verified
  • Ghidra

    National Security Agency

    Mobile Security

    Software reverse engineering suite with a multi architecture disassembler and decompiler, released as open source by the NSA.

    Open source
    Established
  • Jadx

    skylot

    Mobile Security

    Decompiler that converts Android DEX bytecode into readable Java source, with a command line tool and a graphical browser for APKs.

    Open source
    Established Verified
  • APKLeaks

    dwisiswant0

    Command line scanner that decompiles an Android APK and pattern matches the output for hardcoded URIs, API keys and other secrets.

    Open source Growing
    Mobile Security
  • Apktool

    Apktool project

    Reverse engineering tool that decodes Android APK resources and DEX bytecode to editable form and rebuilds a working package from them.

    Open source Established
    Mobile Security
  • Drozer

    Reversec

    Android security assessment framework that uses an on device agent to enumerate and interact with exported app components and IPC endpoints.

    Open source Established
    Mobile Security
  • Frida

    Frida project

    Dynamic instrumentation toolkit that injects a scriptable JavaScript engine into running processes to hook, trace and rewrite behavior at runtime.

    Open source Established
    Mobile Security
  • Ghidra

    National Security Agency

    Software reverse engineering suite with a multi architecture disassembler and decompiler, released as open source by the NSA.

    Open source Established
    Mobile Security
  • Jadx

    skylot

    Decompiler that converts Android DEX bytecode into readable Java source, with a command line tool and a graphical browser for APKs.

    Open source Established
    Mobile Security
  • mitmproxy

    mitmproxy project

    Mobile Security

    Interactive HTTPS proxy that intercepts, inspects, modifies and replays traffic, with a Python addon API for scripted manipulation.

    Open source
    Established Verified
  • MobSF

    MobSF project

    Mobile Security

    Self hosted framework that performs automated static and dynamic security analysis of Android and iOS application binaries and produces a consolidated report.

    Open source
    Established
  • Objection

    SensePost

    Mobile Security

    Runtime mobile exploration toolkit built on dynamic instrumentation, offering common iOS and Android assessment tasks as ready made commands.

    Open source
    Established
  • Ostorlab

    Ostorlab

    Mobile Security

    Mobile application scanner that pairs static binary analysis with instrumented dynamic testing on an extensible agent based engine.

    Freemium
    Growing
  • radare2

    radare2 project

    Mobile Security

    Open source reverse engineering framework for disassembling, patching and debugging binaries across a wide range of architectures and file formats.

    Open source
    Established Verified
  • mitmproxy

    mitmproxy project

    Interactive HTTPS proxy that intercepts, inspects, modifies and replays traffic, with a Python addon API for scripted manipulation.

    Open source Established
    Mobile Security
  • MobSF

    MobSF project

    Self hosted framework that performs automated static and dynamic security analysis of Android and iOS application binaries and produces a consolidated report.

    Open source Established
    Mobile Security
  • Objection

    SensePost

    Runtime mobile exploration toolkit built on dynamic instrumentation, offering common iOS and Android assessment tasks as ready made commands.

    Open source Established
    Mobile Security
  • Ostorlab

    Ostorlab

    Mobile application scanner that pairs static binary analysis with instrumented dynamic testing on an extensible agent based engine.

    Freemium Growing
    Mobile Security
  • radare2

    radare2 project

    Open source reverse engineering framework for disassembling, patching and debugging binaries across a wide range of architectures and file formats.

    Open source Established
    Mobile Security
Tick up to 4 tools above.