Access Brute Force – Android v7+ application to perform a dictionary...
Access Brute Force : Android v7+ application to perform a dictionary brute force attack against a host exposing: + SMB Windows shares. + FTP server. + SSH access. The application is developed using...
View Articledroidstatx – Android Applications Security Analyser, Xmind Generator.
+ droidstatx is a Python tool that generates an Xmind map with all the information gathered and any evidence of possible vulnerabilities identified via static analysis. + The map itself is an Android...
View Articledroidcarve – Commandline Android reverse engineering tool.
DroidCarve is capable of analyzing an Android APK file and automate certain reverse engineering tasks. Features: + Code disassembling into Smali bytecode. + APK signature extraction. + AndroidManifest...
View Articleandroguard v3.1.0-rc1 – Reverse engineering, Malware and goodware analysis of...
What has changed androguard v3.1.0-rc1? – Ported Androguard to python3! You can now use py2.7 or py>=3.3! – Tainted Analysis is gone and will be replaced by XREFs using the...
View ArticleMADLIRA – Malware detection using learning and information retrieval for...
MADLIRA is a tool for Android malware detection. It consists in two components: TFIDF component and SVM learning component. In gerneral, it takes an input a set of malwares and benwares and then...
View Articlesci – Reverse engineering framework working at the assembly (SMALI) level.
Legal Disclamer: Usage of SCI for attacking targets without prior mutual consent is illegal. It is the end user’s responsibility to obey all applicable local, state and federal laws. Developers assume...
View ArticleAndroTickler – Penetration testing and auditing toolkit for Android apps.
A java tool that helps to pentest Android apps faster, more easily and more efficiently. AndroTickler offers many features of information gathering, static and dynamic checks that cover most of the...
View ArticleDex-Oracle ~ Dalvik deobfuscator which uses limited execution to improve...
How it Works Dex-Oracle? Oracle takes Android apps (APK), Dalvik executables (DEX), and Smali files as inputs. First, if the input is an APK or DEX, it is disassembled into Smali files. Then, the Smali...
View ArticleTROMMEL: Sift Through Directories of Files to Identify Indicators That May...
TROMMEL – sifts through directories of files to identify indicators that may contain vulnerabilities. TROMMEL identifies the following indicators related to: – Secure Shell (SSH) key files – Secure...
View ArticleAPKStat – Automated Information Retrieval From APKs For Initial Analysis.
APKStat – Automated Information Retrieval From APKs For Initial Analysis. APKStat will use APK Tool to decompress and decode your APK file. APK Stat Will: + Breaks Permissions, Activities, Activity...
View Articletrueseeing is a fast, accurate and resillient vulnerabilities scanner for...
trueseeing is a fast, accurate and resillient vulnerabilities scanner for Android apps. It operates on Android Packaging File (APK) and outputs a comprehensive report in HTML. It doesn’t matter if the...
View Articleavpass – Tool for leaking and bypassing Android malware detection system.
AVPASS is a tool for leaking the detection model of Android malware detection systems (i.e., antivirus software), and bypassing their detection logics by using the leaked information coupled with APK...
View Articlekwetza – Python script to inject existing Android applications with a...
What does it do? Kwetza infects an existing Android application with either custom or default payload templates to avoid detection by antivirus. Kwetza allows you to infect Android applications using...
View Articleglassdoor is a modern, autonomous security framework for Android APKs.
glassdoor is a modern, autonomous security framework for Android APKs written in Scala. Its purpose is to automatically find backdoors, security flaws and other data leakages in applications running on...
View ArticleTheFatRat v1.9 – Backdoor Creator For Remote Access.
CHANGELOG TheFatRat v1.9 from 1.8: + v1.9.4 – Fatrat will be full terminal mode , Powerstage tool added , Setup script rebuilded + v1.9.3 – Added update scriptCHANGELOG + v1.9.4 – Fatrat will be full...
View ArticleHIDAAF – Human Interface Device Android Attack Framework.
HIDAAF is a python framework that makes it easy to generate HID attack scripts for the Android platform with corresponding phone models. The HIDAAF output format is intended for the Bash Bunny...
View Articlesimplify – Generic Android Deobfuscator.
Simplify virtually executes an app to understand its behavior and then tries to optimize the code so that it behaves identically but is easier for a human to understand. Each optimization type is...
View ArticleHijacker v1-stable version – Android GUI Application for wifi auditing tools.
Changelog From Hijackerv-1-RC to Hijacker v1-stable version 22/1/2017: * Add the option to mark Access Points or Stations to distinguish them easily, move options restore commands in onResume() of...
View Articledrozer v2.4.2 is a comprehensive security audit & attack framework for Android.
Changelog drozer v2.4.2: + [Bugfix] Updated PyOpenSSL to fix Issue #239 + [Bugfix] Fixed setup.py to install Drozer without setting PYTHONPATH environment variable + [Documentation] Fixed documentation...
View ArticleApktool v2.2.2 – A tool for reverse engineering Android apk files.
Changelog Apktool v2.2.2-git: * Added Android 7.1 Resources (Issue 1349) * Update aapt to android-7.1.1_r4. * Upgrade to gradle 3.3 * Fixed NPE with styles that had a parent that didn’t exist. (Issue...
View Article