{"id":55929,"url":"https://github.com/hahwul/MobileHackersWeapons","name":"MobileHackersWeapons","description":"Mobile Hacker's Weapons / A collection of cool tools used by Mobile hackers. Happy hacking , Happy bug-hunting","projects_count":73,"last_synced_at":"2026-09-23T05:00:34.679Z","repository":{"id":38403154,"uuid":"329039148","full_name":"hahwul/MobileHackersWeapons","owner":"hahwul","description":"Mobile Hacker's Weapons / A collection of cool tools used by Mobile hackers. Happy hacking , Happy bug-hunting","archived":false,"fork":false,"pushed_at":"2026-03-01T01:58:42.000Z","size":2599,"stargazers_count":1259,"open_issues_count":3,"forks_count":210,"subscribers_count":51,"default_branch":"main","last_synced_at":"2026-07-26T05:04:43.244Z","etag":null,"topics":["android","awesome-list","bugbounty","bugbountytips","hacking","ios","mobilehacks","scanner","security","tools"],"latest_commit_sha":null,"homepage":"","language":"Ruby","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"mit","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/hahwul.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":"CONTRIBUTING.md","funding":".github/FUNDING.yml","license":"LICENSE","code_of_conduct":"CODE_OF_CONDUCT.md","threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":null,"maintainers":null,"copyright":null,"agents":null,"dco":null,"cla":null},"funding":{"custom":["https://paypal.me/hahwul","https://www.buymeacoffee.com/hahwul"]}},"created_at":"2021-01-12T16:03:41.000Z","updated_at":"2026-07-24T21:24:45.000Z","dependencies_parsed_at":"2026-03-30T23:00:31.412Z","dependency_job_id":null,"html_url":"https://github.com/hahwul/MobileHackersWeapons","commit_stats":{"total_commits":75,"total_committers":5,"mean_commits":15.0,"dds":0.24,"last_synced_commit":"ac1d7bf735262ee2ce9af1607f56ecddf14c046f"},"previous_names":[],"tags_count":0,"template":false,"template_full_name":null,"purl":"pkg:github/hahwul/MobileHackersWeapons","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/hahwul%2FMobileHackersWeapons","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/hahwul%2FMobileHackersWeapons/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/hahwul%2FMobileHackersWeapons/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/hahwul%2FMobileHackersWeapons/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/hahwul","download_url":"https://codeload.github.com/hahwul/MobileHackersWeapons/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/hahwul%2FMobileHackersWeapons/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":36652428,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-08-06T04:43:03.162Z","status":"online","status_checked_at":"2026-08-14T02:00:06.934Z","response_time":54,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"created_at":"2024-02-06T00:50:22.632Z","updated_at":"2026-09-23T05:00:34.679Z","primary_language":null,"list_of_lists":false,"displayable":true,"categories":["Weapons","Family project"],"sub_categories":["iOS","All","Android"],"readme":"\n\u003cdiv align=\"center\"\u003e\n\u003cpicture\u003e\n  \u003csource media=\"(prefers-color-scheme: dark)\" srcset=\"images/mhw-dark.png\" width=\"500px;\"\u003e\n  \u003csource media=\"(prefers-color-scheme: light)\" srcset=\"images/mhw-light.png\" width=\"500px;\"\u003e\n  \u003cimg alt=\"MobileHackersWeapons Logo\" src=\"images/mhw-dark.png\" width=\"500px;\"\u003e\n\u003c/picture\u003e\n\u003cp\u003eA collection of awesome tools used by Mobile hackers. Happy hacking , Happy bug-hunting!\u003c/p\u003e\n\u003c/div\u003e\n\n\u003cp align=\"center\"\u003e\n\u003ca href=\"https://github.com/hahwul/MobileHackersWeapons/blob/main/CONTRIBUTING.md\"\u003e\n\u003cimg src=\"https://img.shields.io/badge/CONTRIBUTIONS-WELCOME-000000?style=for-the-badge\u0026labelColor=black\"\u003e\u003c/a\u003e\n\u003c/p\u003e\n\n## Family project\n[![WebHackersWeapons](https://img.shields.io/github/stars/hahwul/WebHackersWeapons?label=WebHackersWeapons)](https://github.com/hahwul/WebHackersWeapons)\n[![MobileHackersWeapons](https://img.shields.io/github/stars/hahwul/MobileHackersWeapons?label=MobileHackersWeapons)](https://github.com/hahwul/MobileHackersWeapons)\n\n## Table of Contents\n- [Weapons](#weapons)\n- [Contribute](/CONTRIBUTING.md)\n- [Thanks to contributor](#thanks-to-contributor)\n\n## Weapons\n*Attributes*\n|       | Attributes                                        |\n|-------|---------------------------------------------------|\n| Types | `Analysis` `Pentest` `Proxy` `RE` `Scripts` `Scanner` `Utils` `Device` `Discovery`, `Monitor`, `NFC`, `Target`, `Bluetooth`, `Jailbreak`, `Inject`, `Unpinning`|\n| Tags  | [`SCRIPTS`](/categorize/tags/SCRIPTS.md) [`NFC`](/categorize/tags/NFC.md) [`Target`](/categorize/tags/Target.md) [`Jailbreak`](/categorize/tags/Jailbreak.md) [`Inject`](/categorize/tags/Inject.md) [`Hijack`](/categorize/tags/Hijack.md) [`Unpinning`](/categorize/tags/Unpinning.md) [`Bluetooth`](/categorize/tags/Bluetooth.md) [`Monitor`](/categorize/tags/Monitor.md) [`Discovery`](/categorize/tags/Discovery.md)                         |\n| Langs | [`TypeScript`](/categorize/langs/TypeScript.md) [`Python`](/categorize/langs/Python.md) [`Unknown`](/categorize/langs/Unknown.md) [`C++`](/categorize/langs/C++.md) [`JavaScript`](/categorize/langs/JavaScript.md) [`Ruby`](/categorize/langs/Ruby.md) [`Shell`](/categorize/langs/Shell.md) [`Java`](/categorize/langs/Java.md) [`Go`](/categorize/langs/Go.md) [`Objective-C`](/categorize/langs/Objective-C.md) [`Meson`](/categorize/langs/Meson.md) [`Kotlin`](/categorize/langs/Kotlin.md) [`C`](/categorize/langs/C.md) [`Objective-C++`](/categorize/langs/Objective-C++.md)                        |\n\n### All\n| Type | Name | Description | Star |\n| --- | --- | --- | --- |\n|Analysis|[flipper](https://github.com/facebook/flipper)|A desktop debugging platform for mobile developers.|![](https://img.shields.io/github/stars/facebook/flipper?label=%20)|\n|Analysis|[RMS-Runtime-Mobile-Security](https://github.com/m0bilesecurity/RMS-Runtime-Mobile-Security)|Runtime Mobile Security (RMS) 📱🔥  - is a powerful web interface that helps you to manipulate Android and iOS Apps at Runtime|![](https://img.shields.io/github/stars/m0bilesecurity/RMS-Runtime-Mobile-Security?label=%20)|\n|Analysis|[scrounger](https://github.com/nettitude/scrounger)|Mobile application testing toolkit|![](https://img.shields.io/github/stars/nettitude/scrounger?label=%20)|\n|Pentest|[metasploit-framework](https://github.com/rapid7/metasploit-framework)|Metasploit Framework|![](https://img.shields.io/github/stars/rapid7/metasploit-framework?label=%20)|\n|Proxy|[zaproxy](https://github.com/zaproxy/zaproxy)|The OWASP ZAP core project|![](https://img.shields.io/github/stars/zaproxy/zaproxy?label=%20)|\n|Proxy|[proxify](https://github.com/projectdiscovery/proxify)|Swiss Army knife Proxy tool for HTTP/HTTPS traffic capture, manipulation, and replay on the go.|![](https://img.shields.io/github/stars/projectdiscovery/proxify?label=%20)|\n|Proxy|[hetty](https://github.com/dstotijn/hetty)|Hetty is an HTTP toolkit for security research.|![](https://img.shields.io/github/stars/dstotijn/hetty?label=%20)|\n|Proxy|[httptoolkit](https://github.com/httptoolkit/httptoolkit)|HTTP Toolkit is a beautiful \u0026 open-source tool for debugging, testing and building with HTTP(S) on Windows, Linux \u0026 Mac|![](https://img.shields.io/github/stars/httptoolkit/httptoolkit?label=%20)|\n|Proxy|[BurpSuite](https://portswigger.net/burp)|The BurpSuite||\n|RE|[frida-tools](https://github.com/frida/frida-tools)|Frida CLI tools|![](https://img.shields.io/github/stars/frida/frida-tools?label=%20)|\n|RE|[fridump](https://github.com/Nightbringer21/fridump)|A universal memory dumper using Frida|![](https://img.shields.io/github/stars/Nightbringer21/fridump?label=%20)|\n|RE|[frida](https://github.com/frida/frida)|Clone this repo to build Frida|![](https://img.shields.io/github/stars/frida/frida?label=%20)|\n|RE|[ghidra](https://github.com/NationalSecurityAgency/ghidra)|Ghidra is a software reverse engineering (SRE) framework|![](https://img.shields.io/github/stars/NationalSecurityAgency/ghidra?label=%20)|\n|RE|[diff-gui](https://github.com/antojoseph/diff-gui)|GUI for Frida -Scripts|![](https://img.shields.io/github/stars/antojoseph/diff-gui?label=%20)|\n|Scanner|[StaCoAn](https://github.com/vincentcox/StaCoAn)|StaCoAn is a crossplatform tool which aids developers, bugbounty hunters and ethical hackers performing static code analysis on mobile applications.|![](https://img.shields.io/github/stars/vincentcox/StaCoAn?label=%20)|\n|Scanner|[Mobile-Security-Framework-MobSF](https://github.com/MobSF/Mobile-Security-Framework-MobSF)|Mobile Security Framework (MobSF) is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis.|![](https://img.shields.io/github/stars/MobSF/Mobile-Security-Framework-MobSF?label=%20)|\n|Utils|[watchman](https://github.com/facebook/watchman)|Watches files and records, or triggers actions, when they change.|![](https://img.shields.io/github/stars/facebook/watchman?label=%20)|\n||[frida-scripts](https://github.com/0xdea/frida-scripts)|A collection of my Frida.re instrumentation scripts to facilitate reverse engineering of mobile apps.|![](https://img.shields.io/github/stars/0xdea/frida-scripts?label=%20)|\n||[frida-gadget](https://github.com/ksg97031/frida-gadget)|frida-gadget is a tool that can be used to patch APKs in order to utilize the Frida gadget.|![](https://img.shields.io/github/stars/ksg97031/frida-gadget?label=%20)|\n\n### iOS\n| Type | Name | Description | Star |\n| --- | --- | --- | --- |\n|Analysis|[needle](https://github.com/FSecureLABS/needle)|The iOS Security Testing Framework|![](https://img.shields.io/github/stars/FSecureLABS/needle?label=%20)|\n|Analysis|[iFunBox](http://www.i-funbox.com/)|General file management software for iPhone and other Apple products||\n|Analysis|[iblessing](https://github.com/Soulghost/iblessing)|iblessing is an iOS security exploiting toolkit, it mainly includes application information collection, static analysis and dynamic analysis. It can be used for reverse engineering, binary analysis and vulnerability mining.|![](https://img.shields.io/github/stars/Soulghost/iblessing?label=%20)|\n|Analysis|[objection](https://github.com/sensepost/objection)|📱 objection - runtime mobile exploration|![](https://img.shields.io/github/stars/sensepost/objection?label=%20)|\n|RE|[momdec](https://github.com/atomicbird/momdec)|Core Data Managed Object Model Decompiler|![](https://img.shields.io/github/stars/atomicbird/momdec?label=%20)|\n|RE|[iSpy](https://github.com/BishopFox/iSpy)|A reverse engineering framework for iOS|![](https://img.shields.io/github/stars/BishopFox/iSpy?label=%20)|\n|RE|[iRET](https://github.com/S3Jensen/iRET)|iOS Reverse Engineering Toolkit.|![](https://img.shields.io/github/stars/S3Jensen/iRET?label=%20)|\n|RE|[Clutch](https://github.com/KJCracks/Clutch)|Fast iOS executable dumper|![](https://img.shields.io/github/stars/KJCracks/Clutch?label=%20)|\n|RE|[class-dump](https://github.com/nygard/class-dump)|Generate Objective-C headers from Mach-O files.|![](https://img.shields.io/github/stars/nygard/class-dump?label=%20)|\n|RE|[frida-ios-dump](https://github.com/AloneMonkey/frida-ios-dump)|pull decrypted ipa from Jailbreak device|![](https://img.shields.io/github/stars/AloneMonkey/frida-ios-dump?label=%20)|\n|RE|[ipsw](https://github.com/blacktop/ipsw)|iOS/macOS Research Swiss Army Knife|![](https://img.shields.io/github/stars/blacktop/ipsw?label=%20)|\n|Utils|[idb](https://github.com/facebook/idb)|idb is a flexible command line interface for automating iOS simulators and devices|![](https://img.shields.io/github/stars/facebook/idb?label=%20)|\n||[ipainstaller](https://github.com/autopear/ipainstaller)|Install IPA from command line|![](https://img.shields.io/github/stars/autopear/ipainstaller?label=%20)|\n||[HideJB](http://cydia.saurik.com/package/com.thuthuatjb.hidejb/)|a tweak has the ability to skip Jailbreak detection on iOS apps.||\n||[bfinject](https://github.com/BishopFox/bfinject)|Dylib injection for iOS 11.0 - 11.1.2 with LiberiOS and Electra Jailbreaks|![](https://img.shields.io/github/stars/BishopFox/bfinject?label=%20)|\n||[A-Jailbreak](https://www.ios-repo-updates.com/repository/baw-repo/package/com.rpgfarm.a-Jailbreak/)|Super Jailbreak detection Jailbreak!||\n||[MEDUZA](https://github.com/kov4l3nko/MEDUZA)|A more or less universal SSL unpinning tool for iOS|![](https://img.shields.io/github/stars/kov4l3nko/MEDUZA?label=%20)|\n||[ssl-kill-switch2](https://github.com/nabla-c0d3/ssl-kill-switch2)|Blackbox tool to disable SSL certificate validation - including certificate pinning - within iOS and OS X Apps|![](https://img.shields.io/github/stars/nabla-c0d3/ssl-kill-switch2?label=%20)|\n||[Liberty](https://yaluJailbreak.net/liberty/)|Bypass Jailbreak and SSL Pinning||\n||[toothpicker](https://github.com/seemoo-lab/toothpicker)|ToothPicker is an in-process, coverage-guided fuzzer for iOS. for iOS Bluetooth|![](https://img.shields.io/github/stars/seemoo-lab/toothpicker?label=%20)|\n||[FlyJB-X](https://github.com/XsF1re/FlyJB-X)|You can HIDE Doing Jailbreak your iDevice.|![](https://img.shields.io/github/stars/XsF1re/FlyJB-X?label=%20)|\n\n### Android\n| Type | Name | Description | Star |\n| --- | --- | --- | --- |\n|Analysis|[apkleaks](https://github.com/dwisiswant0/apkleaks)|Scanning APK file for URIs, endpoints \u0026 secrets.|![](https://img.shields.io/github/stars/dwisiswant0/apkleaks?label=%20)|\n|Analysis|[drozer](https://github.com/FSecureLABS/drozer)|The Leading Security Assessment Framework for Android.|![](https://img.shields.io/github/stars/FSecureLABS/drozer?label=%20)|\n|Pentest|[HacknDroid](https://github.com/RaffaDNDM/HacknDroid)|Automation of some Mobile Application Penetration Testing activities and interaction with the mobile Android device.|![](https://img.shields.io/github/stars/RaffaDNDM/HacknDroid?label=%20)|\n|Pentest|[Kali NetHunter](https://gitlab.com/kalilinux/nethunter/build-scripts/kali-nethunter-project)|Mobile Penetration Testing Platform||\n|RE|[bytecode-viewer](https://github.com/Konloch/bytecode-viewer/)|A Java 8+ Jar \u0026 Android APK Reverse Engineering Suite (Decompiler, Editor, Debugger \u0026 More)|![](https://img.shields.io/github/stars/Konloch/bytecode-viewer/?label=%20)|\n|RE|[Apktool](https://github.com/iBotPeaches/Apktool)|A tool for reverse engineering Android apk files|![](https://img.shields.io/github/stars/iBotPeaches/Apktool?label=%20)|\n|RE|[androguard](https://github.com/androguard/androguard)|Reverse engineering, Malware and goodware analysis of Android applications ... and more (ninja !)|![](https://img.shields.io/github/stars/androguard/androguard?label=%20)|\n|RE|[dex2jar](https://github.com/pxb1988/dex2jar)|Tools to work with android .dex and java .class files|![](https://img.shields.io/github/stars/pxb1988/dex2jar?label=%20)|\n|RE|[jadx](https://github.com/skylot/jadx)|Dex to Java decompiler|![](https://img.shields.io/github/stars/skylot/jadx?label=%20)|\n|RE|[jd-gui](https://github.com/java-decompiler/jd-gui)|A standalone Java Decompiler GUI|![](https://img.shields.io/github/stars/java-decompiler/jd-gui?label=%20)|\n|RE|[JEB](https://www.pnfsoftware.com/jeb/)|reverse-engineering platform to perform disassembly, decompilation, debugging, and analysis of code and document files, manually or as part of an analysis pipeline.||\n|RE|[btrace](https://github.com/bytedance/btrace)|🔥🔥 btrace(AKA RheaTrace) is a high performance Android trace tool which is based on Systrace, it support to define custom events automatically during building apk and using bhook to provider more native events like IO.|![](https://img.shields.io/github/stars/bytedance/btrace?label=%20)|\n|RE|[jadx-ai-mcp](https://github.com/zinja-coder/jadx-ai-mcp)|MCP server that provides access to JADX decompiler for AI assistants to analyze Android apps|![](https://img.shields.io/github/stars/zinja-coder/jadx-ai-mcp?label=%20)|\n|RE|[apkx](https://github.com/b-mueller/apkx)|One-Step APK Decompilation With Multiple Backends|![](https://img.shields.io/github/stars/b-mueller/apkx?label=%20)|\n|RE|[Smali-CFGs](https://github.com/EugenioDelfa/Smali-CFGs)|Smali Control Flow Graph's|![](https://img.shields.io/github/stars/EugenioDelfa/Smali-CFGs?label=%20)|\n|RE|[dex-oracle](https://github.com/CalebFenton/dex-oracle)|A pattern based Dalvik deobfuscator which uses limited execution to improve semantic analysis|![](https://img.shields.io/github/stars/CalebFenton/dex-oracle?label=%20)|\n|RE|[procyon](https://github.com/mstrobel/procyon)|Procyon is a suite of Java metaprogramming tools, including a rich reflection API, a LINQ-inspired expression tree API for runtime code generation, and a Java decompiler.|![](https://img.shields.io/github/stars/mstrobel/procyon?label=%20)|\n|RE|[enjarify](https://github.com/Storyyeller/enjarify)|Enjarify is a tool for translating Dalvik bytecode to equivalent Java bytecode. This allows Java analysis tools to analyze Android applications.|![](https://img.shields.io/github/stars/Storyyeller/enjarify?label=%20)|\n|Scanner|[qark](https://github.com/linkedin/qark)|Tool to look for several security related Android application vulnerabilities|![](https://img.shields.io/github/stars/linkedin/qark?label=%20)|\n|Utils|[behe-keyboard](https://github.com/VladThodo/behe-keyboard)|A lightweight hacking \u0026 programming keyboard with material design|![](https://img.shields.io/github/stars/VladThodo/behe-keyboard?label=%20)|\n|Utils|[termux-app](https://github.com/termux/termux-app)|Termux - a terminal emulator application for Android OS extendible by variety of packages.|![](https://img.shields.io/github/stars/termux/termux-app?label=%20)|\n|Utils|[Magisk](https://github.com/topjohnwu/Magisk)|The Magic Mask for Android|![](https://img.shields.io/github/stars/topjohnwu/Magisk?label=%20)|\n|Device|[scrcpy](https://github.com/Genymobile/scrcpy)|Display and control your Android device|![](https://img.shields.io/github/stars/Genymobile/scrcpy?label=%20)|\n||[nfcgate](https://github.com/nfcgate/nfcgate)|An NFC research toolkit application for Android|![](https://img.shields.io/github/stars/nfcgate/nfcgate?label=%20)|\n||[googleplay](https://github.com/89z/googleplay)|Download APK from Google Play or send API requests|![](https://img.shields.io/github/stars/89z/googleplay?label=%20)|\n||[gplaydl](https://github.com/rehmatworks/gplaydl)|Command Line Google Play APK downloader. Download APK files to your PC directly from Google Play Store.|![](https://img.shields.io/github/stars/rehmatworks/gplaydl?label=%20)|\n||[Hijacker](https://github.com/chrisk44/Hijacker)|Aircrack, Airodump, Aireplay, MDK3 and Reaver GUI Application for Android|![](https://img.shields.io/github/stars/chrisk44/Hijacker?label=%20)|\n||[PCAPdroid](https://github.com/emanuele-f/PCAPdroid)|No-root network monitor, firewall and PCAP dumper for Android|![](https://img.shields.io/github/stars/emanuele-f/PCAPdroid?label=%20)|\n||[gplaycli](https://github.com/matlink/gplaycli)|Google Play Downloader via Command line|![](https://img.shields.io/github/stars/matlink/gplaycli?label=%20)|\n||[PlaystoreDownloader](https://github.com/ClaudiuGeorgiu/PlaystoreDownloader)|A command line tool to download Android applications directly from the Google Play Store by specifying their package name (an initial one-time configuration is required)|![](https://img.shields.io/github/stars/ClaudiuGeorgiu/PlaystoreDownloader?label=%20)|\n||[PortAuthority](https://github.com/aaronjwood/PortAuthority)|A handy systems and security-focused tool, Port Authority is a very fast Android port scanner. Port Authority also allows you to quickly discover hosts on your network and will display useful network information about your device and other hosts.|![](https://img.shields.io/github/stars/aaronjwood/PortAuthority?label=%20)|\n\n## Thanks to (Contributor)\nWHW's open-source project and made it with ❤️ if you want contribute this project, please see [CONTRIBUTING.md](https://github.com/hahwul/MobileHackersWeapons/blob/main/CONTRIBUTING.md) and Pull-Request with cool your contents.\n\n[![](/images/CONTRIBUTORS.svg)](https://github.com/hahwul/MobileHackersWeapons/graphs/contributors)\n\n","projects_url":"https://awesome.ecosyste.ms/api/v1/lists/hahwul%2Fmobilehackersweapons/projects"}