A curated list of Android Security materials and resources For Pentesters and Bug Hunters
-
Updated
Sep 2, 2026
A curated list of Android Security materials and resources For Pentesters and Bug Hunters
This repo is a helpful starting point for those interested in exploring the world of Android hacking and bug bounties. The resources mentioned have personally assisted me.
An open source Android application that is intentionally vulnerable so as to act as a learning platform for Android application security beginners.
The MPT (Mobile Pentest Toolkit) is a must-have solution for your android penetration testing workflow.
A curated set of offensive security notes on vulnerabilities, techniques, and tools
It provides configurable shortcuts to help make the pre-qual/testing process more efficient.
An helper for mobile applications analysis
Awesome android Pentest tools collection
An advanced Android kernel exploitation tool designed to bypass File-Based Encryption (FBE) and screen locks using Zero-Day vulnerabilities. (Educational & Research Purpose).
Detect and fix code vulnerabilities by running AI-driven adversarial checks that simulate attacks and verify secure, correct fixes automatically.
A Tailscale exit node built with tsnet that forwards all mobile device traffic through Burp Suite for penetration testing.
Mobile Application Penetration Testing checklist including iOS and Android
[Beta testing] Android bruteforcing tool for apps pentesting, simulating manual user typing with adb
Scripts to inject CA cert to android system
ActiFuzz is an Android intent fuzzing python script for exported activities that take extras as inputs.
Professional-grade modular Android 12+ penetration testing framework — 10 modules: Recon, Payload, Installer, C2, PrivEsc, Persistence, Exfiltration, MITM, Automation, Reporting
BurnerOS is an Android-based secure workspace built for privacy-sensitive workflows. It provides an isolated environment for encrypted notes, private browsing, burner contacts, and fast local data purge controls.
A comprehensive collection of Android Application Security Test Cases based on OWASP MASVS, OWASP Mobile Top 10, Android Security Best Practices, and real-world penetration testing scenarios.
🚀 The easiest way to manage Frida on Android. Auto-setup, version matching, bypass scripts, wireless ADB.
My Personal Blog
To associate your repository with the android-pentest topic, visit your repo's landing page and select "manage topics."