> cat /dev/github | grep security-tools

Kotlin

Clippy

2026-08-31 Kotlin ★ 440
Clippy is an Android tool designed to enhance link management by allowing users to easily copy links from their device's sharing menu. Its primary use case is to provide a cleaner and more secure link experience by enabling users to copy either the original URL or a version stripped of URL shorteners and tracking parameters. Notable features include seamless integration with the sharing options of various apps and straightforward functionality for copying both raw and cleaned links.

CertoraProver

2026-08-25 Kotlin ★ 329
Certora Prover is a formal verification tool designed for analyzing and ensuring the correctness of smart contracts. Primarily used in blockchain development, it leverages advanced SMT solvers and integrates various programming languages to validate contract logic against specified properties. Notable features include support for multiple solvers, a cloud platform for ease of use, and detailed reporting capabilities for diagnostics.

fitface-studio

2026-08-21 Kotlin ★ 17
FitFace Studio is an Android application designed for customizing Fit3 (SM-R390) watch faces by allowing users to browse, edit, and install them directly to their watches via Bluetooth. The tool features a catalogue for searching and sorting watch faces, a layout editor for altering backgrounds and widgets, and does not redistribute watch face packages; instead, it edits the original binary directly. With functionalities such as widget movement, color adjustments, and real-time validation before installation, it facilitates a user-friendly interface for personalizing watch faces without the need for app re-signing or installation on the device.

JavaShroud

2026-08-21 Kotlin ★ 87
JavaShroud is a comprehensive obfuscation and hardening toolchain for Java applications, utilizing bytecode transformation through a Kotlin engine and enabling the execution of lowered methods within a Native bytecode VM (NBVM). It offers various features, including class and method renaming, string encryption, control flow obfuscation, method virtualization, and integrated runtime protections, designed to enhance security by increasing the costs associated with reverse engineering and code analysis. The tool emphasizes the generation of unique keys and layouts for each output, adhering to the Kerckhoffs principle, ensuring that the strength of the protection does not rely on implementation secrecy.

ZeroDroid

2026-08-17 Kotlin ★ 33
ZeroDroid is a comprehensive Android hardware security toolkit designed to transform smartphones into portable RF labs, network analyzers, and security auditing tools, featuring 29 specialized utilities. Its primary use case includes analyzing various radio frequencies and sensors, as well as conducting detailed network assessments. Notable features include the ability to access WiFi, Bluetooth, NFC, GPS, and other device sensors, all presented through a terminal-hacker user interface.

Root-My-Pixel

2026-08-11 Kotlin ★ 237
Root My Pixel is an Android application that automates the acquisition of temporary root access on Google Pixel devices using the NebuSec IonStack exploit (CVE-2026-43499) and integrates with ReSukiSU / KernelSU. It employs a sophisticated installation workflow for device detection and exploit execution while providing real-time log monitoring and management features like soft reboot and log exporting. This tool specifically targets a range of supported Pixel models and requires prerequisites such as the Shizuku service and ReSukiSU Manager for optimal functionality.

morphe-patches

2026-08-08 Kotlin ★ 49
hxreborn Patches provides a collection of modifications for Android applications built upon the Morphe framework. Its primary use case is to enhance user experience by implementing features such as hiding upgrade prompts, enabling custom themes, and unlocking premium functionalities across various apps like Proton Mail and Showly. Notable features include the ability to disable tracking and customize UI elements, catering to users who seek greater control over their app interactions.

ameen-morphe

2026-08-06 Kotlin ★ 18
Ameen's Morphe Patches is a collection of bytecode-level modifications designed for enhancing the functionality of various Android applications using the Morphe framework. The tool primarily serves to unlock premium features in apps like Foodvisor and PhotoGrid, allowing users to bypass limitations and watermarks. Key features include ease of use through the Morphe Manager or CLI, as well as the ability to apply custom logic to APKs without requiring the original source code.

librepods

2026-08-03 Kotlin ★ 29606
LibrePods is a tool designed to replicate AirPods functionalities on non-Apple platforms, leveraging the proprietary protocol for communication between AirPods and Apple devices. It enables features such as noise control mode adjustments, ear detection, and battery status reporting on Linux and Android systems. Notable features include customization options for conversational awareness, automatic connections, and various control settings, ensuring users can fully utilize their AirPods outside of the Apple ecosystem.

CVE-2024-33352

2026-08-03 Kotlin ★ 21
CVE-2024-33352 identifies a critical vulnerability in BlueStacks for Windows, affecting versions prior to 10.40.1000.502. This flaw allows unprivileged users to access and modify configuration files stored in a world-writeable directory, enabling them to backdoor the virtual machine and gain code execution as a privileged user by manipulating shared folder settings. The README provides a detailed exploitation method and emphasizes the necessity of updating to a patched version to mitigate this security risk.

Password-Monitor

2026-08-03 Kotlin ★ 120
Password Monitor is a cybersecurity tool that checks the integrity of user passwords against known data breaches by utilizing the Have I Been Pwned? service. It emphasizes privacy by ensuring that passwords are never shared and offers a user-friendly interface with support for material design, dark themes, and ad-free usage. Notable features include being fully open source, the avoidance of personal data collection, and reproducible builds for easy installation.

IYPS

2026-08-03 Kotlin ★ 278
IYPS is a password strength evaluation application that analyzes and rates the robustness of user-provided passwords, estimates potential cracking times, and delivers actionable advice for enhancing password security. It features a random password and passphrase generator, operates entirely offline, and is designed with a modern Material You interface, supporting both light and dark themes without ads or personal data collection.

ApkClaw

2026-08-03 Kotlin ★ 13
ApkClaw is a tool that enables users to control Android devices by sending plain language messages through popular chat applications like WeChat, Telegram, and Discord. Its primary use case involves delegating tasks such as opening apps, tapping buttons, and checking status directly from a computer, leveraging an AI agent for task execution on the Android device. Notable features include multi-platform messaging support, easy setup instructions, and the ability to manage Android tasks remotely, simplifying user interactions with their devices.

tsa

2026-08-03 Kotlin ★ 32
TSA (TON Symbolic Analyzer) is a static analysis tool designed for evaluating smart contracts on the TON blockchain through symbolic execution. Its primary use cases include detecting potential runtime errors, generating regression tests, and identifying malicious contracts, with the capability to analyze any language compiled to TVM bitcode format. Notable features include its test generation capabilities and detailed analysis of integer processing issues and data handling in smart contracts.

kUML

2026-08-03 Kotlin ★ 22
Architecture that compiles. Kotlin DSL for UML 2.x, SysML 2 and C4 diagrams-as-code — CLI, Compose Desktop, IntelliJ & Obsidian plugins, Asciidoctor extension on Maven Central, ELK layout, reverse engineering (Java/Kotlin), XMI import/export, plugin SPI. Apache-2.0.

adobo

2026-08-03 Kotlin ★ 241
Adobo is a patching tool designed for enhancing the functionality of Android applications like YouTube and Reddit through the Morphe framework. Its primary use case involves modifying apps to block ads, remove unnecessary permissions, and introduce privacy-focused features. Notable capabilities include disabling tracking, enabling incognito modes for input methods, and extensive customization options for popular apps.

discover-ads-filter

2026-08-03 Kotlin ★ 44
Discover Ads Filter is an Xposed module designed to remove sponsored cards and advertisements from the Google Discover feed on the Pixel Launcher and within the Google app for devices running Android 11 and above. It uses DexKit to scan the Google app and identify ad items by resolving hook targets, enabling efficient filtering and caching of ad content. Notably, it requires a compatible LSPosed manager with libxposed API support to function effectively.

playstore-adblock

2026-08-03 Kotlin ★ 76
Playstore Adblock is an Xposed module designed to eliminate sponsored listings and advertisements from the Google Play Store, enhancing the user experience by allowing seamless app browsing. It is compatible with Android 11 and above and requires libxposed API 101+, offering a straightforward installation process that involves activation through an Xposed manager. Notable features include adaptation to various Play Store versions and the ability to clear cached ad responses, ensuring optimal functionality.

zemer-cipher

2026-08-03 Kotlin ★ 26
Zemer-Cipher is an Android library designed for YouTube cipher deobfuscation and PoToken generation, facilitating the extraction of streaming URLs from obfuscated JavaScript. Key features include signature cipher deobfuscation, n-parameter transformations to mitigate throttling, and remote-updateable player configurations that allow real-time updates without requiring app releases. This library is crucial for applications leveraging the YouTube API to maintain functionality amid frequent player script rotations.

BurpMCP-Ultra

2026-08-03 Kotlin ★ 205
BurpMCP-Ultra is a powerful Kotlin extension for Burp Suite Professional that integrates an MCP server, enabling programmatic control of Burp functionalities via AI agents. It supports 149 structured tools for tasks such as proxy history analysis, scan management, fuzzing, and guided exploitation, all secured through token-based local transport. Notable features include custom scan checks, an extensive real-time dashboard, and hardened localhost security controls.

stickyburp

2026-08-03 Kotlin ★ 15
StickyBurp is a Burp Suite extension designed to facilitate the management of global per-project environment variables, referred to as "stickies," which can be created from selected text across different Burp tabs. This tool allows users to easily store, replace, and utilize dynamic payload content such as authentication tokens, UUIDs, and server URLs, enhancing the efficiency of penetration testing workflows. Notable features include sticky management with color coding, persistence across projects, and the ability to copy values easily for use in various Burp functions like Repeater and Intruder.

intentions

2026-08-03 Kotlin ★ 12
Intentions is an Android tool designed for testing and manipulating Inter-Process Communication (IPC) via Intents, primarily intended for users with rooted devices running Android 10 and above. Key features include the ability to scan installed apps for their exported components, build and dispatch custom Intents, capture incoming Intents through a sink and logcat observer, and perform replay and fuzzing of Intents, all while offering various export formats for generated commands. The tool acts as an IPC workbench, combining intent discovery, custom intent creation, and comprehensive testing capabilities tailored for security researchers and developers.

opentaint

2026-08-03 Kotlin ★ 149
OpenTaint is an open-source taint analysis engine designed for application security, effectively identifying vulnerabilities that abstract syntax tree (AST) pattern matchers may overlook. Its primary use case involves enhancing security measures for applications, particularly those built with technologies like Java, Kotlin, and Spring, by allowing large language model (LLM) agents to execute vulnerability rules while offering scalable performance. Notable features include formal taint analysis capabilities and extensive integration support for various programming languages and platforms.

Mirage

2026-08-03 Kotlin ★ 11
Mirage is an Android application designed to facilitate the auto-injection of shared objects into target processes using the hxo framework. Its primary use case is to enhance the functionality of applications, specifically within the context of Android environments, while supporting versions from Android 9 onwards. Key features include easy installation via an APK, developer support for customization, and a community-driven approach for real-time assistance and feedback.

postexploitation-toolbox-android

2026-08-03 Kotlin ★ 20
The postexploitation-toolbox-android is a specialized toolkit for executing post-exploitation techniques on Android devices, particularly designed for Android 14 on the Samsung S21 Ultra. It leverages CVE-2024-34740 to allow code injection into system processes, enabling features such as temporary app debuggability, system-wide permission bypassing, and dynamic resource editing, while providing a user-friendly interface for manipulating system service internals through Java reflection.

takopii

2026-08-03 Kotlin ★ 11
Takopii is a production-grade banker malware architecture designed for Android, featuring four APK specimens that encapsulate techniques from 17 real-world malware families. Its primary use case is to facilitate the study of malware detection and defense strategies, offering Kotlin source code alongside comprehensive YARA and Sigma detection rules. Notably, all specimens demonstrate zero detection across 66 VirusTotal engines, showcasing advanced evasion capabilities within a structured kill chain framework.

Spectre

2026-08-03 Kotlin ★ 151
Spectre is an Android application designed for monitoring and interacting with various wireless signals, including Bluetooth, Wi-Fi, cellular, and GNSS. Its primary use case revolves around RF exposure measurement and pen-testing, featuring tools for detailed analysis of signal strength, local network discovery, and BLE device interaction. Notable features include comprehensive support for multiple network technologies, advanced filtering capabilities, and a GATT inspector for Bluetooth devices, all while adhering to Android's security restrictions.

AppVerifier

2026-03-22 Kotlin ★ 960
Verify apps easily.

burp-ai-agent

2026-03-22 Kotlin ★ 1438
Burp Suite extension that adds built-in MCP tooling, AI-assisted analysis, privacy controls, passive and active scanning and more

inql

2026-03-22 Kotlin ★ 1745
InQL is a robust, open-source Burp Suite extension for advanced GraphQL testing, offering intuitive vulnerability detection, customizable scans, and seamless Burp integration.

MetaRadar

2026-03-22 Kotlin ★ 1319
A tool for BLE environment monitoring. Find and track Bluetooth devices around, and get notified when the target device is detected.

revanced-patcher

2026-03-22 Kotlin ★ 3264
💉 ReVanced Patcher used to patch Android applications

revanced-patches-template

2026-03-22 Kotlin ★ 4644
👋🧩Template repository for ReVanced Patches

ToolsFx

2026-03-22 Kotlin ★ 2004
跨平台密码学工具箱。包含编解码,编码转换,加解密, 哈希,MAC,签名,大数运算,压缩,二维码功能,CTF等功能。

WechatMagician

2026-03-22 Kotlin ★ 1893
WechatMagician is a Xposed module written in Kotlin, that allows you to completely control your Wechat.

WechatSpellbook

2026-03-22 Kotlin ★ 1736
Wechat Spellbook 是一个使用Kotlin编写的开源微信插件框架,底层需要 Xposed 或 VirtualXposed 等Hooking框架的支持,而顶层可以轻松对接Java、Kotlin、Scala等JVM系语言。让程序员能够在几分钟内编写出简单的微信插件,随意揉捏微信的内部逻辑。