The main idea behind this project is to create corrupt but structurally valid media files, direct them to the appropriate software components in Android to be decoded and/or played and monitor the system for potential issues (i.e system crashes) that may lead to exploitable vulnerabilities. Custom developed Python scripts are used to send the malformed data across a distributed infrastructure of Android devices, log the findings and monitor for possible issues, in an automated manner. The actual decoding of the media files on the Android devices is done using the Stagefright command line interface. The results are sorted out, in an attempt to find only the unique issues, using a custom built triage mechanism.
FEATURES
ALTERNATIVES
Pupy is a cross-platform C2 and post-exploitation framework for remote access and control of compromised systems across various operating systems.
GNU/Linux Wireless distribution for security testing with XFCE desktop environment.
A collection of Microsoft PowerShell modules for penetration testing purposes.
Python-based toolkit for network hacking with various implemented techniques and supported by Securetia SRL.
Boofuzz is a network protocol fuzzing tool that aims to fuzz everything
Covenant is a .NET C2 framework for red teamers, facilitating collaborative and efficient management of red team operations.
Back-end component for red team operations with crucial design considerations.
Weaponizing Kerberos protocol flaws for stealthy attacks on domain users.
PINNED
Fabric Platform by BlackStork
Fabric Platform is a cybersecurity reporting solution that automates and standardizes report generation, offering a private-cloud platform, open-source tools, and community-supported templates.
Mandos Brief Newsletter
Stay ahead in cybersecurity. Get the week's top cybersecurity news and insights in 8 minutes or less.
Wiz
Wiz Cloud Security Platform is a cloud-native security platform that enables security, dev, and devops to work together in a self-service model, detecting and preventing cloud security threats in real-time.
Adversa AI
Adversa AI is a cybersecurity company that provides solutions for securing and hardening machine learning, artificial intelligence, and large language models against adversarial attacks, privacy issues, and safety incidents across various industries.