Nandee
Nandee
SaaS platform that scans Android and iOS codebases for mobile-specific vulnerability classes and proposes code-level fixes.
Mobile Security
Analyze, instrument and harden Android and iOS applications.
23 tools profiled
How it differs Analyses Android and iOS app binaries, statically and at runtime. The backend APIs an app calls belong to API security or DAST.
Nandee
SaaS platform that scans Android and iOS codebases for mobile-specific vulnerability classes and proposes code-level fixes.
Ostorlab
Mobile application scanner that pairs static binary analysis with instrumented dynamic testing on an extensible agent based engine.
MobSF project
Self hosted framework that performs automated static and dynamic security analysis of Android and iOS application binaries and produces a consolidated report.
Reversec
Android security assessment framework that uses an on device agent to enumerate and interact with exported app components and IPC endpoints.
Appknox
Mobile application security platform that scans uploaded iOS and Android binaries statically and dynamically and maps findings to compliance frameworks.
radare2 project
Open source reverse engineering framework for disassembling, patching and debugging binaries across a wide range of architectures and file formats.
Cryptic Apps
Desktop disassembler and decompiler for macOS and Linux, widely used for analyzing Mach-O binaries from iOS and macOS applications.
Guardsquare
Mobile application protection suite providing code obfuscation, encryption and runtime self protection for Android and iOS, alongside the open source ProGuard.
Zimperium
Automated scanner that analyzes compiled Android and iOS builds for security, privacy and compliance issues inside the release pipeline.
dwisiswant0
Command line scanner that decompiles an Android APK and pattern matches the output for hardcoded URIs, API keys and other secrets.
Data Theorem
Continuous mobile application security platform that scans pre release and published builds dynamically and maps the backend APIs those apps call.
Talsec
Mobile runtime application self-protection SDK that detects tampering, hooking, rooted or jailbroken devices and emulated environments.
Nandee
SaaS platform that scans Android and iOS codebases for mobile-specific vulnerability classes and proposes code-level fixes.
Ostorlab
Mobile application scanner that pairs static binary analysis with instrumented dynamic testing on an extensible agent based engine.
MobSF project
Self hosted framework that performs automated static and dynamic security analysis of Android and iOS application binaries and produces a consolidated report.
Reversec
Android security assessment framework that uses an on device agent to enumerate and interact with exported app components and IPC endpoints.
Appknox
Mobile application security platform that scans uploaded iOS and Android binaries statically and dynamically and maps findings to compliance frameworks.
radare2 project
Open source reverse engineering framework for disassembling, patching and debugging binaries across a wide range of architectures and file formats.
Cryptic Apps
Desktop disassembler and decompiler for macOS and Linux, widely used for analyzing Mach-O binaries from iOS and macOS applications.
Guardsquare
Mobile application protection suite providing code obfuscation, encryption and runtime self protection for Android and iOS, alongside the open source ProGuard.
Zimperium
Automated scanner that analyzes compiled Android and iOS builds for security, privacy and compliance issues inside the release pipeline.
dwisiswant0
Command line scanner that decompiles an Android APK and pattern matches the output for hardcoded URIs, API keys and other secrets.
Data Theorem
Continuous mobile application security platform that scans pre release and published builds dynamically and maps the backend APIs those apps call.
Talsec
Mobile runtime application self-protection SDK that detects tampering, hooking, rooted or jailbroken devices and emulated environments.
SensePost
Runtime mobile exploration toolkit built on dynamic instrumentation, offering common iOS and Android assessment tasks as ready made commands.
mitmproxy project
Interactive HTTPS proxy that intercepts, inspects, modifies and replays traffic, with a Python addon API for scripted manipulation.
Frida project
Dynamic instrumentation toolkit that injects a scriptable JavaScript engine into running processes to hook, trace and rewrite behavior at runtime.
Appdome
Build service that injects runtime self protection, anti tampering and obfuscation into compiled iOS and Android binaries without source code changes.
NowSecure
Mobile application security platform that runs automated static and dynamic testing on real devices and reports against recognized mobile testing standards.
skylot
Decompiler that converts Android DEX bytecode into readable Java source, with a command line tool and a graphical browser for APKs.
National Security Agency
Software reverse engineering suite with a multi architecture disassembler and decompiler, released as open source by the NSA.
eShard
Mobile application security testing service that runs automated attacks against builds on real devices to measure how well their runtime protections hold.
Corellium
Arm virtualization platform that runs real iOS and Android firmware as instrumented virtual devices for security research and dynamic analysis.
Apktool project
Reverse engineering tool that decodes Android APK resources and DEX bytecode to editable form and rebuilds a working package from them.
Oversecured
Static analysis service that traces untrusted data through compiled Android and iOS binaries to find exploitable inter-component vulnerabilities.
SensePost
Runtime mobile exploration toolkit built on dynamic instrumentation, offering common iOS and Android assessment tasks as ready made commands.
mitmproxy project
Interactive HTTPS proxy that intercepts, inspects, modifies and replays traffic, with a Python addon API for scripted manipulation.
Frida project
Dynamic instrumentation toolkit that injects a scriptable JavaScript engine into running processes to hook, trace and rewrite behavior at runtime.
Appdome
Build service that injects runtime self protection, anti tampering and obfuscation into compiled iOS and Android binaries without source code changes.
NowSecure
Mobile application security platform that runs automated static and dynamic testing on real devices and reports against recognized mobile testing standards.
skylot
Decompiler that converts Android DEX bytecode into readable Java source, with a command line tool and a graphical browser for APKs.
National Security Agency
Software reverse engineering suite with a multi architecture disassembler and decompiler, released as open source by the NSA.
eShard
Mobile application security testing service that runs automated attacks against builds on real devices to measure how well their runtime protections hold.
Corellium
Arm virtualization platform that runs real iOS and Android firmware as instrumented virtual devices for security research and dynamic analysis.
Apktool project
Reverse engineering tool that decodes Android APK resources and DEX bytecode to editable form and rebuilds a working package from them.
Oversecured
Static analysis service that traces untrusted data through compiled Android and iOS binaries to find exploitable inter-component vulnerabilities.