MARA is a Mobile Application Reverse engineering and Analysis Framework that combines commonly used tools for testing mobile applications against OWASP mobile security threats. It supports features like APK reverse engineering, disassembling Dalvik bytecode, decompiling APK to Java source code, APK deobfuscation, APK analysis, and more. Developed and maintained by @xtian_kisutsa and @iamckn, MARA is in its early stages of development with ongoing updates based on the roadmap.
FEATURES
SIMILAR TOOLS
Runtime Mobile Security (RMS) is a powerful web interface powered by FRIDA for manipulating Android and iOS Apps at Runtime.
A search engine for the Internet of Things (IoT) that discovers and monitors devices connected to the internet.
A Graphical Realism Framework for Industrial Control Simulation organized as 5 VirtualBox VMs for realistic ICS network simulation.
MiniCPS is a framework for real-time Cyber-Physical Systems simulation that supports physical process and control device simulation along with network emulation capabilities.
Comprehensive manual for mobile app security testing and reverse engineering with technical processes for verifying controls.
An Outlook add-in for reporting suspicious emails to security teams and tracking user behavior during awareness campaigns.
A cross-platform software library for interacting with iOS devices without jailbreaking.
Steghide is a steganography program for hiding data in image and audio files.
A distributed systems simulator that creates vulnerable Kubernetes clusters in AWS for security training and vulnerability mitigation practice.
PINNED

Mandos
Fractional CISO service that helps B2B companies implement security leadership to win enterprise deals, achieve compliance, and develop strategic security programs.

Checkmarx SCA
A software composition analysis tool that identifies vulnerabilities, malicious code, and license risks in open source dependencies throughout the software development lifecycle.

Orca Security
A cloud-native application protection platform that provides agentless security monitoring, vulnerability management, and compliance capabilities across multi-cloud environments.

DryRun
A GitHub application that performs automated security code reviews by analyzing contextual security aspects of code changes during pull requests.