APKLeaks
dwisiswant0
Command line scanner that decompiles an Android APK and pattern matches the output for hardcoded URIs, API keys and other secrets.
Mobile Security
Analyze, instrument and harden Android and iOS applications.
23 tools profiled
How it differs Analyses Android and iOS app binaries, statically and at runtime. The backend APIs an app calls belong to API security or DAST.
dwisiswant0
Command line scanner that decompiles an Android APK and pattern matches the output for hardcoded URIs, API keys and other secrets.
Apktool project
Reverse engineering tool that decodes Android APK resources and DEX bytecode to editable form and rebuilds a working package from them.
Appknox
Mobile application security platform that scans uploaded iOS and Android binaries statically and dynamically and maps findings to compliance frameworks.
Data Theorem
Continuous mobile application security platform that scans pre release and published builds dynamically and maps the backend APIs those apps call.
Reversec
Android security assessment framework that uses an on device agent to enumerate and interact with exported app components and IPC endpoints.
Frida project
Dynamic instrumentation toolkit that injects a scriptable JavaScript engine into running processes to hook, trace and rewrite behavior at runtime.
Guardsquare
Mobile application protection suite providing code obfuscation, encryption and runtime self protection for Android and iOS, alongside the open source ProGuard.
skylot
Decompiler that converts Android DEX bytecode into readable Java source, with a command line tool and a graphical browser for APKs.
dwisiswant0
Command line scanner that decompiles an Android APK and pattern matches the output for hardcoded URIs, API keys and other secrets.
Apktool project
Reverse engineering tool that decodes Android APK resources and DEX bytecode to editable form and rebuilds a working package from them.
Appknox
Mobile application security platform that scans uploaded iOS and Android binaries statically and dynamically and maps findings to compliance frameworks.
Data Theorem
Continuous mobile application security platform that scans pre release and published builds dynamically and maps the backend APIs those apps call.
Reversec
Android security assessment framework that uses an on device agent to enumerate and interact with exported app components and IPC endpoints.
Frida project
Dynamic instrumentation toolkit that injects a scriptable JavaScript engine into running processes to hook, trace and rewrite behavior at runtime.
Guardsquare
Mobile application protection suite providing code obfuscation, encryption and runtime self protection for Android and iOS, alongside the open source ProGuard.
skylot
Decompiler that converts Android DEX bytecode into readable Java source, with a command line tool and a graphical browser for APKs.
MobSF project
Self hosted framework that performs automated static and dynamic security analysis of Android and iOS application binaries and produces a consolidated report.
Nandee
SaaS platform that scans Android and iOS codebases for mobile-specific vulnerability classes and proposes code-level fixes.
NowSecure
Mobile application security platform that runs automated static and dynamic testing on real devices and reports against recognized mobile testing standards.
SensePost
Runtime mobile exploration toolkit built on dynamic instrumentation, offering common iOS and Android assessment tasks as ready made commands.
Ostorlab
Mobile application scanner that pairs static binary analysis with instrumented dynamic testing on an extensible agent based engine.
Oversecured
Static analysis service that traces untrusted data through compiled Android and iOS binaries to find exploitable inter-component vulnerabilities.
Talsec
Mobile runtime application self-protection SDK that detects tampering, hooking, rooted or jailbroken devices and emulated environments.
Zimperium
Automated scanner that analyzes compiled Android and iOS builds for security, privacy and compliance issues inside the release pipeline.
MobSF project
Self hosted framework that performs automated static and dynamic security analysis of Android and iOS application binaries and produces a consolidated report.
Nandee
SaaS platform that scans Android and iOS codebases for mobile-specific vulnerability classes and proposes code-level fixes.
NowSecure
Mobile application security platform that runs automated static and dynamic testing on real devices and reports against recognized mobile testing standards.
SensePost
Runtime mobile exploration toolkit built on dynamic instrumentation, offering common iOS and Android assessment tasks as ready made commands.
Ostorlab
Mobile application scanner that pairs static binary analysis with instrumented dynamic testing on an extensible agent based engine.
Oversecured
Static analysis service that traces untrusted data through compiled Android and iOS binaries to find exploitable inter-component vulnerabilities.
Talsec
Mobile runtime application self-protection SDK that detects tampering, hooking, rooted or jailbroken devices and emulated environments.
Zimperium
Automated scanner that analyzes compiled Android and iOS builds for security, privacy and compliance issues inside the release pipeline.