awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectMCP serverAboutHow we rankPress
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·

Mobile App Security Testing Frameworks

Ranking updated Jun 30, 2026

For a mobile app security scanner, the strongest matches are mobsf/mobile-security-framework-mobsf (MobSF is a fully automated mobile application security testing), reverseclabs/drozer (Drozer is an Android-focused security testing framework with agent-based) and frida/frida (Frida is a dynamic instrumentation framework that excels at). sensepost/objection is also worth a look. Each is ranked by relevance to your query, popularity and recent activity.

Automated security analysis tools and testing frameworks for identifying vulnerabilities in Android and iOS applications.

Mobile App Security Testing Frameworks

Find the best repos with AI.We'll search the best matching repositories with AI.
  • mobsf/mobile-security-framework-mobsfMobSF avatar

    MobSF/Mobile-Security-Framework-MobSF

    21,224View on GitHub↗

    Mobile Security Framework is an automated security testing platform designed for the analysis of Android, iOS, and Windows mobile application binaries. It functions as a comprehensive suite for identifying security vulnerabilities, privacy risks, and malicious code within mobile software packages. The framework distinguishes itself by combining static and dynamic analysis techniques to evaluate application behavior. It performs static inspection of source code and binaries to detect insecure patterns, while simultaneously utilizing dynamic instrumentation and containerized sandboxing to monit

    MobSF is a fully automated mobile application security testing framework that supports both Android and iOS with static and dynamic analysis, API security testing, CI/CD integration, and report generation, making it a comprehensive answer to your search.

    JavaScriptCI/CD Pipeline Integrations
    View on GitHub↗21,224
  • reverseclabs/drozerReversecLabs avatar

    ReversecLabs/drozer

    4,542View on GitHub↗

    Drozer is a security testing framework for Android applications that operates through an agent-based remote execution model. It combines a client-server command routing system with a device-side agent, enabling security assessments by mapping inter-process communication (IPC) attack surfaces and running dynamic exploit modules directly on Android devices. The framework distinguishes itself through its ability to discover and enumerate exported Android components by analyzing manifest data and crafting Intents to probe for vulnerabilities. It supports content provider query injection to detect

    Drozer is an Android-focused security testing framework with agent-based dynamic analysis and component enumeration, but it does not cover iOS, meaning it only partially meets the multi-platform requirement.

    PythonAutomated Security ScannersVulnerability Scanners
    View on GitHub↗4,542
  • frida/fridafrida avatar

    frida/frida

    19,778View on GitHub↗

    Frida is a dynamic binary instrumentation toolkit that provides a framework for deep process introspection and live application state manipulation. It enables the injection of custom scripts into running processes to trace function calls, modify memory, and analyze application behavior in real-time across diverse operating systems and processor architectures. The project distinguishes itself by embedding a high-performance JavaScript engine directly within the target process, allowing for the execution of user-defined logic for real-time inspection. It utilizes instruction-level hooking to re

    Frida is a dynamic instrumentation framework that excels at real-time mobile app security testing on both Android and iOS, directly supporting dynamic analysis and runtime manipulation, making it a core tool for your needs even though it doesn’t include built-in static analysis or report generation.

    MesonDynamic Binary InstrumentationDynamic Introspection FrameworksNative Hooking Engines
    View on GitHub↗19,778
  • sensepost/objectionsensepost avatar

    sensepost/objection

    8,896View on GitHub↗

    Objection is a dynamic instrumentation framework and runtime exploration toolkit for mobile application security analysis. It provides a command-line interface to interact with the memory and state of iOS and Android applications during active execution, serving as a toolkit for runtime analysis and security testing. The project distinguishes itself by providing specialized capabilities to bypass common mobile security controls, including SSL pinning, biometric authentication, and root or jailbreak detection. It enables the extraction of sensitive credentials and data from secure storage syst

    Objection is a dynamic instrumentation toolkit for runtime security analysis of Android and iOS apps, fitting the core request for a mobile security testing framework, though it focuses on dynamic analysis and bypass techniques rather than covering all listed features like static analysis and report generation.

    PythonDynamic Binary InstrumentationMobile Runtime Exploration ToolkitsBinary Instrumentation
    View on GitHub↗8,896

Related searches

  • a learning path for mobile engineers
  • an automated security scanner for web applications
  • a security framework for penetration testing operations
  • Mobile development
  • a vulnerable web application for security training
  • a SQL injection testing tool
  • an open source penetration testing framework
  • an open source scanner for security vulnerabilities