README.md

March 1, 2026 ยท View on GitHub

MobileHackersWeapons Logo

A collection of awesome tools used by Mobile hackers. Happy hacking , Happy bug-hunting!

Family project

WebHackersWeapons MobileHackersWeapons

Table of Contents

Weapons

Attributes

Attributes
TypesAnalysis Pentest Proxy RE Scripts Scanner Utils Device Discovery, Monitor, NFC, Target, Bluetooth, Jailbreak, Inject, Unpinning
TagsSCRIPTS NFC Target Jailbreak Inject Hijack Unpinning Bluetooth Monitor Discovery
LangsTypeScript Python Unknown C++ JavaScript Ruby Shell Java Go Objective-C Meson Kotlin C Objective-C++

All

TypeNameDescriptionStar
AnalysisflipperA desktop debugging platform for mobile developers.
AnalysisRMS-Runtime-Mobile-SecurityRuntime Mobile Security (RMS) ๐Ÿ“ฑ๐Ÿ”ฅ - is a powerful web interface that helps you to manipulate Android and iOS Apps at Runtime
AnalysisscroungerMobile application testing toolkit
Pentestmetasploit-frameworkMetasploit Framework
ProxyzaproxyThe OWASP ZAP core project
ProxyproxifySwiss Army knife Proxy tool for HTTP/HTTPS traffic capture, manipulation, and replay on the go.
ProxyhettyHetty is an HTTP toolkit for security research.
ProxyhttptoolkitHTTP Toolkit is a beautiful & open-source tool for debugging, testing and building with HTTP(S) on Windows, Linux & Mac
ProxyBurpSuiteThe BurpSuite
REfrida-toolsFrida CLI tools
REfridumpA universal memory dumper using Frida
REfridaClone this repo to build Frida
REghidraGhidra is a software reverse engineering (SRE) framework
REdiff-guiGUI for Frida -Scripts
ScannerStaCoAnStaCoAn is a crossplatform tool which aids developers, bugbounty hunters and ethical hackers performing static code analysis on mobile applications.
ScannerMobile-Security-Framework-MobSFMobile Security Framework (MobSF) is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis.
UtilswatchmanWatches files and records, or triggers actions, when they change.
frida-scriptsA collection of my Frida.re instrumentation scripts to facilitate reverse engineering of mobile apps.
frida-gadgetfrida-gadget is a tool that can be used to patch APKs in order to utilize the Frida gadget.

iOS

TypeNameDescriptionStar
AnalysisneedleThe iOS Security Testing Framework
AnalysisiFunBoxGeneral file management software for iPhone and other Apple products
Analysisiblessingiblessing is an iOS security exploiting toolkit, it mainly includes application information collection, static analysis and dynamic analysis. It can be used for reverse engineering, binary analysis and vulnerability mining.
Analysisobjection๐Ÿ“ฑ objection - runtime mobile exploration
REmomdecCore Data Managed Object Model Decompiler
REiSpyA reverse engineering framework for iOS
REiRETiOS Reverse Engineering Toolkit.
REClutchFast iOS executable dumper
REclass-dumpGenerate Objective-C headers from Mach-O files.
REfrida-ios-dumppull decrypted ipa from Jailbreak device
REipswiOS/macOS Research Swiss Army Knife
Utilsidbidb is a flexible command line interface for automating iOS simulators and devices
ipainstallerInstall IPA from command line
HideJBa tweak has the ability to skip Jailbreak detection on iOS apps.
bfinjectDylib injection for iOS 11.0 - 11.1.2 with LiberiOS and Electra Jailbreaks
A-JailbreakSuper Jailbreak detection Jailbreak!
MEDUZAA more or less universal SSL unpinning tool for iOS
ssl-kill-switch2Blackbox tool to disable SSL certificate validation - including certificate pinning - within iOS and OS X Apps
LibertyBypass Jailbreak and SSL Pinning
toothpickerToothPicker is an in-process, coverage-guided fuzzer for iOS. for iOS Bluetooth
FlyJB-XYou can HIDE Doing Jailbreak your iDevice.

Android

TypeNameDescriptionStar
AnalysisapkleaksScanning APK file for URIs, endpoints & secrets.
AnalysisdrozerThe Leading Security Assessment Framework for Android.
PentestHacknDroidAutomation of some Mobile Application Penetration Testing activities and interaction with the mobile Android device.
PentestKali NetHunterMobile Penetration Testing Platform
REbytecode-viewerA Java 8+ Jar & Android APK Reverse Engineering Suite (Decompiler, Editor, Debugger & More)
REApktoolA tool for reverse engineering Android apk files
REandroguardReverse engineering, Malware and goodware analysis of Android applications ... and more (ninja !)
REdex2jarTools to work with android .dex and java .class files
REjadxDex to Java decompiler
REjd-guiA standalone Java Decompiler GUI
REJEBreverse-engineering platform to perform disassembly, decompilation, debugging, and analysis of code and document files, manually or as part of an analysis pipeline.
REbtrace๐Ÿ”ฅ๐Ÿ”ฅ btrace(AKA RheaTrace) is a high performance Android trace tool which is based on Systrace, it support to define custom events automatically during building apk and using bhook to provider more native events like IO.
REjadx-ai-mcpMCP server that provides access to JADX decompiler for AI assistants to analyze Android apps
REapkxOne-Step APK Decompilation With Multiple Backends
RESmali-CFGsSmali Control Flow Graph's
REdex-oracleA pattern based Dalvik deobfuscator which uses limited execution to improve semantic analysis
REprocyonProcyon is a suite of Java metaprogramming tools, including a rich reflection API, a LINQ-inspired expression tree API for runtime code generation, and a Java decompiler.
REenjarifyEnjarify is a tool for translating Dalvik bytecode to equivalent Java bytecode. This allows Java analysis tools to analyze Android applications.
ScannerqarkTool to look for several security related Android application vulnerabilities
Utilsbehe-keyboardA lightweight hacking & programming keyboard with material design
Utilstermux-appTermux - a terminal emulator application for Android OS extendible by variety of packages.
UtilsMagiskThe Magic Mask for Android
DevicescrcpyDisplay and control your Android device
nfcgateAn NFC research toolkit application for Android
googleplayDownload APK from Google Play or send API requests
gplaydlCommand Line Google Play APK downloader. Download APK files to your PC directly from Google Play Store.
HijackerAircrack, Airodump, Aireplay, MDK3 and Reaver GUI Application for Android
PCAPdroidNo-root network monitor, firewall and PCAP dumper for Android
gplaycliGoogle Play Downloader via Command line
PlaystoreDownloaderA command line tool to download Android applications directly from the Google Play Store by specifying their package name (an initial one-time configuration is required)
PortAuthorityA handy systems and security-focused tool, Port Authority is a very fast Android port scanner. Port Authority also allows you to quickly discover hosts on your network and will display useful network information about your device and other hosts.

Thanks to (Contributor)

WHW's open-source project and made it with โค๏ธ if you want contribute this project, please see CONTRIBUTING.md and Pull-Request with cool your contents.