android-security-awesome Awesome

Link Liveness Checker

Lint Shell scripts Lint Markdown Lint YAML Lint GitHub Actions GitHub contributors

A collection of Android security-related resources.

  1. Tools
  2. Academic/Research/Publications/Books
  3. Exploits/Vulnerabilities/Bugs

Tools

Online Analyzers

  1. AndroTotal
  2. Appknox - not free
  3. Virustotal - max 128MB
  4. Fraunhofer App-ray - not free
  5. NowSecure Lab Automated - Enterprise tool for mobile app security testing both Android and iOS mobile apps. Lab Automated features dynamic and static analysis on real devices in the cloud to return results in minutes. Not free
  6. App Detonator - Detonate APK binary to provide source code level details, including app author, signature, build, and manifest information. 3 Analysis/day free quota.
  7. Pithus - Open-Source APK analyzer. Still in Beta and limited to static analysis for the moment. It is possible to hunt malware with Yara rules. More here.
  8. Oversecured - Enterprise vulnerability scanner for Android and iOS apps; it offers app owners and developers the ability to secure each new version of a mobile app by integrating Oversecured into the development process. Not free.
  9. AppSweep by Guardsquare - Free, fast Android application security testing for developers
  10. Koodous - Performs static/dynamic malware analysis over a vast repository of Android samples and checks them against public and private Yara rules.
  11. Immuniweb. Does an "OWASP Mobile Top 10 Test", "Mobile App Privacy Check", and an application permissions test. The free tier is 4 tests per day, including report after registration
  12. ANY.RUN - An interactive cloud-based malware analysis platform with support for Android application analysis. Limited free plan available.
  13. ~~BitBaan~~
  14. ~~AVC UnDroid~~
  15. ~~AMAaaS - Free Android Malware Analysis Service. A bare-metal service features static and dynamic analysis for Android applications. A product of MalwarePot~~.
  16. ~~AppCritique - Upload your Android APKs and receive comprehensive free security assessments~~
  17. ~~NVISO ApkScan - sunsetting on Oct 31, 2019~~
  18. ~~Mobile Malware Sandbox~~
  19. ~~IBM Security AppScan Mobile Analyzer - not free~~
  20. ~~Visual Threat - no longer an Android app analyzer~~
  21. ~~Tracedroid~~
  22. ~~habo - 10/day~~
  23. ~~CopperDroid~~
  24. ~~SandDroid~~
  25. ~~Stowaway~~
  26. ~~Anubis~~
  27. ~~Mobile app insight~~
  28. ~~Mobile-Sandbox~~
  29. ~~Ijiami~~
  30. ~~Comdroid~~
  31. ~~Android Sandbox~~
  32. ~~Foresafe~~
  33. ~~Dexter~~
  34. ~~MobiSec Eacus~~
  35. ~~Fireeye- max 60MB 15/day~~
  36. ~~approver - Approver is a fully automated security analysis and risk assessment platform for Android and iOS apps. Not free.~~