Androguard is a full python tool to play with Android files, including DEX, ODEX, APK, Android's binary xml, Android resources. It can disassemble DEX/ODEX bytecodes, provide basic decompiler for DEX/ODEX files, offer Frida support for easy dynamic analysis, and use SQLite database to save the session.
FEATURES
ALTERNATIVES
A tool for identifying potential security vulnerabilities in web applications
A software supply chain security platform that analyzes binaries and software components to detect malware, vulnerabilities, exposed secrets, and tampering throughout the development lifecycle.
Tenable One Exposure Management Platform is a comprehensive platform for vulnerability management and exposure management.
A Burp extension for scanning JavaScript files for endpoint links
Dynamic instrumentation toolkit for developers, reverse-engineers, and security researchers.
A static analysis tool for Android apps that detects malware and other malicious code
AWS Web Application Firewalls (WAFs) protect web applications and APIs from attacks, providing prebuilt security rules and the ability to create custom rules.
PINNED

Mandos Brief Newsletter
A weekly newsletter providing cybersecurity leadership insights, industry updates, and strategic guidance for security professionals advancing to management positions.

PTJunior
An AI-powered penetration testing platform that autonomously discovers, exploits, and documents vulnerabilities while generating NIST-compliant reports.

OSINTLeak
OSINTLeak is a tool for discovering and analyzing leaked sensitive information across various online sources to identify potential security risks.

ImmuniWeb® Discovery
ImmuniWeb Discovery is an attack surface management platform that continuously monitors an organization's external digital assets for security vulnerabilities, misconfigurations, and threats across domains, applications, cloud resources, and the dark web.

Checkmarx SCA
A software composition analysis tool that identifies vulnerabilities, malicious code, and license risks in open source dependencies throughout the software development lifecycle.

Orca Security
A cloud-native application protection platform that provides agentless security monitoring, vulnerability management, and compliance capabilities across multi-cloud environments.

DryRun
A GitHub application that performs automated security code reviews by analyzing contextual security aspects of code changes during pull requests.