Top 12 mobile-security Open-Source Projects
-
-
Mobile-Security-Framework-MobSF
Mobile Security Framework (MobSF) is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis.
Project mention: Can anyone recommend a good tool to pentest mobile apps?, I have the packages locally. Thanks | reddit.com/r/Pentesting | 2022-07-18I can say only for android: - General Scanner -> https://github.com/MobSF/Mobile-Security-Framework-MobSF - Decompiler -> https://github.com/skylot/jadx
-
Scout APM
Less time debugging, more time building. Scout APM allows you to find and fix performance issues with no hassle. Now with error monitoring and external services monitoring, Scout is a developer's best friend when it comes to application development.
-
owasp-mstg
The Mobile Security Testing Guide (MSTG) is a comprehensive manual for mobile app security testing and reverse engineering. It describes the technical processes for verifying the controls listed in the OWASP Mobile Application Security Verification Standard (MASVS).
Project mention: Securing API keys, clientId, clientSecret etc while distributing to App Store? Ways to prevent reverse engineering? | reddit.com/r/swift | 2022-07-28Check out OWASP, they have plenty documentation about threat modeling and attack vectors for mobile apps. Regarding jailbreak detection, see the following: https://github.com/OWASP/owasp-mstg/blob/master/Document/0x06j-Testing-Resiliency-Against-Reverse-Engineering.md
-
Project mention: Scan the apk file to check its different layers | reddit.com/r/NETSECSOFT | 2022-01-09
git clone https://github.com/dwisiswant0/apkleaks
-
RMS-Runtime-Mobile-Security
Runtime Mobile Security (RMS) 📱🔥 - is a powerful web interface that helps you to manipulate Android and iOS Apps at Runtime
Then use runtime tools like Runtime Mobile Security, Grapefruit, and Objection to see stuff in action and practice Frida along with as these tools usually support loading custom Frida scripts.
-
Androl4b
A Virtual Machine For Assessing Android applications, Reverse Engineering and Malware Analysis
-
-
SonarQube
Static code analysis for 29 languages.. Your projects are multi-language. So is SonarQube analysis. Find Bugs, Vulnerabilities, Security Hotspots, and Code Smells so you can release quality code every time. Get started analyzing your projects today for free.
-
Then use runtime tools like Runtime Mobile Security, Grapefruit, and Objection to see stuff in action and practice Frida along with as these tools usually support loading custom Frida scripts.
-
-
If you look at things like - https://github.com/mbcrump/awesome-security - you'll see they've broken it down into fields like "Infrastructure Security", "Hardware Security and Binary Exploitation", etc. Whilst having a knowledge of all of those areas would be awesome, it is most likely that certain areas will interest you more.
-
Project mention: apkingo is a tool written in Go to get detailed information about apk files | reddit.com/r/andSec | 2022-03-21
-
mobile-security related posts
Index
What are some of the best open-source mobile-security projects? This list will help you:
Project | Stars | |
---|---|---|
1 | hacker101 | 12,567 |
2 | Mobile-Security-Framework-MobSF | 11,790 |
3 | owasp-mstg | 9,251 |
4 | apkleaks | 3,162 |
5 | RMS-Runtime-Mobile-Security | 1,858 |
6 | Androl4b | 981 |
7 | reFlutter | 704 |
8 | grapefruit | 586 |
9 | UnSAFE_Bank | 85 |
10 | awesome-security | 51 |
11 | apkingo | 39 |
12 | DataMaster-Android-AdBlock-Hosts | 17 |
Are you hiring? Post a new remote job listing for free.