--- title: Mobile Security kind: overview topics: [mobile-security] sources: - wiki/sources/skills/mobile-security.md - wiki/sources/README-categories.md - wiki/sources/descriptions/unrandoms__frida-mobile-kit.md - wiki/sources/descriptions/3v1lC0d3__Root_Detection_Low_level.md - wiki/sources/descriptions/zelect0r__zamr.md - wiki/sources/descriptions/iBotPeaches__Apktool.md - wiki/sources/descriptions/zinja-coder__apktool-mcp-server.md - wiki/sources/descriptions/Akipe__awesome-android-aosp.md - wiki/sources/descriptions/AndnixSH__APKToolGUI.md - wiki/sources/descriptions/APKLab__APKLab.md - wiki/sources/descriptions/xjoker__delamain.md - wiki/sources/descriptions/axhlzy__PyAsmPatch.md - wiki/sources/descriptions/axhlzy__Il2CppHookScripts.md - wiki/sources/descriptions/azw413__Glass.md - wiki/sources/descriptions/ax__apk.sh.md - wiki/sources/descriptions/skylot__jadx.md - wiki/sources/descriptions/pxb1988__dex2jar.md - wiki/sources/descriptions/zhuowei__cheese.md - wiki/sources/descriptions/zhizhuodemao__android_proxy_mcp.md - wiki/sources/descriptions/zeroxjf__lightsaber.md - wiki/sources/descriptions/Zenlua__Tool-Tree.md - wiki/sources/descriptions/rooootdev__lara.md - wiki/sources/descriptions/wh1te4ever__darksword-kexploit-fun.md - wiki/sources/descriptions/wh1te4ever__xnu_1day_practice.md - wiki/sources/descriptions/wh1te4ever__HumptyLock.md - wiki/sources/descriptions/jsherman212__xnuspy.md - wiki/sources/descriptions/hackcatml__kfd-explorer.md - wiki/sources/descriptions/felix-pb__kfd.md - wiki/sources/descriptions/hackcatml__frida-findJNINativeMethods.md - wiki/sources/descriptions/zboralski__unflutter.md - wiki/sources/descriptions/yukiarrr__Il2cppSpy.md - wiki/sources/descriptions/jd-opensource__arkdecompiler.md - wiki/sources/descriptions/hx1997__dayu.md - wiki/sources/descriptions/huawei-mediatek-devs__android_kernel_huawei_mt6761.md - wiki/sources/descriptions/xxzzddxzd__unitySpeedTools.md - wiki/sources/descriptions/oobbb__android-il2cpp-modspeed.md - wiki/sources/descriptions/ys1231__MoveCertificate.md - wiki/sources/descriptions/yoavst__ida-ios-helper.md - wiki/sources/descriptions/Laert-Android__Advanced-Root-Checker.md - wiki/sources/descriptions/Lazenca__Lazenca-S.md - wiki/sources/descriptions/34306__vphone-aio.md - wiki/sources/descriptions/34306__usbliter8-fun.md - wiki/sources/descriptions/34306__mdc0.md - wiki/sources/descriptions/vaenshine__VansonMod.md - wiki/sources/descriptions/Lakr233__vphone-cli.md - wiki/sources/descriptions/zqxwce__vphone-ws.md - wiki/sources/descriptions/LaurieWired__Malimite.md - wiki/sources/descriptions/LeoChen-CoreMind__elf-got-patcher.md - wiki/sources/descriptions/LGLTeam__Android-Mod-Menu.md - wiki/sources/descriptions/LuckyPray__DexKit-Android.md - wiki/sources/descriptions/LowTension__android_kernel_xiaomi_sm8475.md - wiki/sources/descriptions/Danda420__kernel_xiaomi_sm8250.md - wiki/sources/descriptions/RooTurkk__ROOTURK-Kernel.md - wiki/sources/descriptions/lj94093__IDAAndroidBreakpoint.md - wiki/sources/descriptions/ymdzq__OFRP-device_xiaomi_mondrian.md - wiki/sources/descriptions/Ctapchuk__android_bootable_recovery-OFRP.md - wiki/sources/descriptions/Chinaapps__ZN-Toolbox.md - wiki/sources/descriptions/flakeforever__device_xiaomi_mondrian.md - wiki/sources/descriptions/firerpa__lamda.md - wiki/sources/descriptions/yhnu__op7t.md - wiki/sources/descriptions/utziacre__android_kernel_xiaomi_pipa.md - wiki/sources/descriptions/fiqri19102002__android_kernel_xiaomi_sweet.md - wiki/sources/descriptions/SM7325-AE__android_kernel_motorola_dubai.md - wiki/sources/descriptions/utziacre__android_kernel_oneplus_sm8250.md - wiki/sources/descriptions/psavarmattas__android_kernel_oneplus_sm7250-WKSU.md - wiki/sources/descriptions/mylove90__pc_ginkgo.md - wiki/sources/descriptions/msnx__KernelSU-Pixel4XL.md - wiki/sources/descriptions/universal5433__android_kernel_samsung_universal5433.md - wiki/sources/descriptions/pascua28__android_kernel_samsung_sm7150.md - wiki/sources/descriptions/yabinc__simpleperf_demo.md - wiki/sources/descriptions/xmmword__dpatch.md - wiki/sources/descriptions/xiaoxindada__magiskboot_ndk_on_linux.md - wiki/sources/descriptions/svoboda18__magiskboot.md - wiki/sources/descriptions/ookiineko__magiskboot_build.md - wiki/sources/descriptions/gmh5225__magiskboot-linux.md - wiki/sources/descriptions/gmh5225__frida-il2cpp-datacollector.md - wiki/sources/descriptions/gmh5225__Il2Cpp-HookScripts.md - wiki/sources/descriptions/gmh5225__PokemonGoDumper.md - wiki/sources/descriptions/omochikaeri15__battle-cats-complete.md - wiki/sources/descriptions/gmh5225__frida-ceserver.md - wiki/sources/descriptions/gmh5225__bytecode-viewer.md - wiki/sources/descriptions/CUB3D__ghidra-hexagon-sleigh.md - wiki/sources/descriptions/CalebFenton__simplify.md - wiki/sources/descriptions/CodingGay__BlackObfuscator.md - wiki/sources/descriptions/ClaudiuGeorgiu__Obfuscapk.md - wiki/sources/descriptions/Col-E__Recaf.md - wiki/sources/descriptions/gmh5225__Anticheat-android-cheap-engine.md - wiki/sources/descriptions/gmh5225__cheap-engine.md - wiki/sources/descriptions/JingMatrix__Demo.md - wiki/sources/descriptions/Jiang-Night__Kernel_driver_hack.md - wiki/sources/descriptions/Jordan231111__lsposed-universal-template.md - wiki/sources/descriptions/JoshKappler__laneguard.md - wiki/sources/descriptions/KuhakuPixel__AceTheGame.md - wiki/sources/descriptions/gmh5225__ceserver-ios.md - wiki/sources/descriptions/0xiuks__ceserver-ios.md - wiki/sources/descriptions/0xbinder__android-kernel-exploitation-lab.md - wiki/sources/descriptions/0xCD4__SSL-bypass.md - wiki/sources/descriptions/gmh5225__CODM-ESP-Aimbot-Mod-Menu.md - wiki/sources/descriptions/gmh5225__KittyMemory-IOS.md - wiki/sources/descriptions/gmh5225__freedom.md - wiki/sources/descriptions/gmh5225__External-ImGui-Android.md - wiki/sources/descriptions/gmh5225__Alaa-8ball-pool-source-exposed.md - wiki/sources/descriptions/gmh5225__Android-Emulator-Detection.md - wiki/sources/descriptions/gmh5225__Android-Mod-Menu-ImGui.md - wiki/sources/descriptions/gmh5225__FakerAndroid.md - wiki/sources/descriptions/ekknod__usbsn.md - wiki/sources/descriptions/repinek__fallguys-frida-modmenu.md - wiki/sources/descriptions/astra1dev__MalumMenu-Android.md - wiki/sources/descriptions/dabao1955__kernel_build_action.md - wiki/sources/descriptions/TheWildJames__kernel_build_scripts.md - wiki/sources/descriptions/Andrea-lyz__oppo_oplus_realme_sm8750.md - wiki/sources/descriptions/xProHackerx__imgui-ios-mod-menu.md - wiki/sources/descriptions/jprx__darwin-vm.md - wiki/sources/descriptions/jixiaoyong__ApkSigner.md - wiki/sources/descriptions/joeyjurjens__iOS-Mod-Menu-Template-for-Theos.md - wiki/sources/descriptions/x-spy__CVE-2026-43499-popsicle.md - wiki/sources/descriptions/xgl34222220-ops__BaiZe.md - wiki/sources/descriptions/xscope0__xkvm-ios-injector.md - wiki/sources/descriptions/villager1314__CVE-2026-64560-Analysis.md - wiki/sources/descriptions/crazymind90__CVE-2026-XNU-AIO-KEVENT-UAF.md - wiki/sources/descriptions/alephsecurity__xnu-qemu-arm64.md - wiki/sources/descriptions/ChefKissInc__qemu-apple-silicon.md - wiki/sources/descriptions/farazsth98__poc-CVE-2025-38352.md - wiki/sources/descriptions/wwweeeqqu__honor-of-kings-RE-research.md - wiki/sources/descriptions/walzer__game-engine-detector.md - wiki/sources/descriptions/kp7742__UE4Dumper.md - wiki/sources/descriptions/gmh5225__UE4Dumper_Emulator.md - wiki/sources/descriptions/gmh5225__UE4-Apk-Dumper.md - wiki/sources/descriptions/MJx0__iOS_UE4Dumper.md - wiki/sources/descriptions/MJx0__KittyMemory.md - wiki/sources/descriptions/kp7742__MemDumper.md - wiki/sources/descriptions/Kakaxh1__RootRaven.md - wiki/sources/descriptions/MrOplus__frida-ide.md - wiki/sources/descriptions/ChiChou__vscode-frida.md - wiki/sources/descriptions/ChiChou__grapefruit.md - wiki/sources/descriptions/ChiChou__bagbak.md - wiki/sources/descriptions/GliTcHZzZ67__mast-orchestrator.md - wiki/sources/descriptions/jafarm189__MOABile.md - wiki/sources/descriptions/Kc57__iHide.md - wiki/sources/descriptions/KpwnZ__Def1nit3lyN0tAJa1lbr3akTool.md - wiki/sources/descriptions/vvb2060__MagiskDetector.md - wiki/sources/descriptions/rushiranpise__detection.md - wiki/sources/descriptions/vvb2060__KeyAttestation.md - wiki/sources/descriptions/VisionR1__KeyAttestation.md - wiki/sources/descriptions/Vector35__workflow_objc.md - wiki/sources/descriptions/MxIris-Reverse-Engineering__RuntimeViewer.md - wiki/sources/descriptions/shakevsky__keybuster.md - wiki/sources/descriptions/vrolife__mypower.md - wiki/sources/descriptions/vrolife__android_native_app_imgui.md - wiki/sources/descriptions/horoni__android_imgui_menu.md - wiki/sources/descriptions/vm03__payload_dumper.md - wiki/sources/descriptions/venkata-ram__DroidShield.md - wiki/sources/descriptions/talsec__Free-RASP-Community.md - wiki/sources/descriptions/talsec__Free-RASP-Unity-POC.md - wiki/sources/descriptions/talsec__Free-RASP-ReactNative.md - wiki/sources/descriptions/talsec__Free-RASP-Android.md - wiki/sources/descriptions/talsec__Free-RASP-Capacitor.md - wiki/sources/descriptions/talsec__Free-RASP-Cordova.md - wiki/sources/descriptions/Binuka97__cordova-plugin-rootguard.md - wiki/sources/descriptions/talsec__Free-RASP-iOS.md - wiki/sources/descriptions/talsec__Free-RASP-Flutter.md - wiki/sources/descriptions/talsec__Free-RASP-KMP.md - wiki/sources/descriptions/rajssinde__rs-native-kit-security.md - wiki/sources/descriptions/NoobDigital__react-native-shieldscan.md - wiki/sources/descriptions/AfanasievN__react-native-device-risk-signals.md - wiki/sources/descriptions/phajmvawnsix__com.sipvlib.anticheat.md - wiki/sources/descriptions/utmapp__UTM.md - wiki/sources/descriptions/user1342__Obfu-DE-Scate.md - wiki/sources/descriptions/trustdecision__trustdevice-ios.md - wiki/sources/descriptions/trustdecision__trustdevice-android.md - wiki/sources/descriptions/Xheghun__DeviceTrust.md - wiki/sources/descriptions/topjohnwu__Magisk.md - wiki/sources/descriptions/tiann__KernelSU.md - wiki/sources/descriptions/tiann__DirtyPipeRoot.md - wiki/sources/descriptions/polygraphene__DirtyPipe-Android.md - wiki/sources/descriptions/tomasz-lisowski__swsim.md - wiki/sources/descriptions/the-dise__EasyPixel.md - wiki/sources/descriptions/longpoxin__hideroot.md - wiki/sources/descriptions/canyie__Riru-MomoHider.md - wiki/sources/descriptions/canyie__MagiskKiller.md - wiki/sources/descriptions/canyie__MagiskEoP.md - wiki/sources/descriptions/gmh5225__MagiskHide.md - wiki/sources/descriptions/thelok1s__florida-zygisk.md - wiki/sources/descriptions/lico-n__ZygiskFrida.md - wiki/sources/descriptions/gmh5225__memory_server.md - wiki/sources/descriptions/H5GG__H5GG.md - wiki/sources/descriptions/gmh5225__neotty.md - wiki/sources/descriptions/NeoTerrm__NeoTerm.md - wiki/sources/descriptions/termux__termux-app.md - wiki/sources/descriptions/jackpal__Android-Terminal-Emulator.md - wiki/sources/descriptions/DP-Hridayan__aShellYou.md - wiki/sources/descriptions/j4nn__CVE-2020-0041.md - wiki/sources/descriptions/bluefrostsecurity__CVE-2020-0041.md - wiki/sources/descriptions/gmh5225__AdbFileManager.md - wiki/sources/descriptions/pgp__XFiles.md - wiki/sources/descriptions/SysAdminDoc__FileExplorer.md - wiki/sources/descriptions/Raival-e__File-Explorer.md - wiki/sources/descriptions/nzcv__note.md - wiki/sources/descriptions/tangsilian__android-vuln.md - wiki/sources/descriptions/tamirzb__CVE-2021-1961.md - wiki/sources/descriptions/jsirichai__CVE-2019-2215.md - wiki/sources/descriptions/nahid0x1__CVE-2024-0044.md - wiki/sources/descriptions/gmh5225__Android-privilege-CVE-2022-20452-LeakValue.md - wiki/sources/descriptions/systemnb__compile_android_driver.md - wiki/sources/descriptions/iofomo__abyss.md - wiki/sources/descriptions/systemnb__android-kernel-hacking-toolkit.md - wiki/sources/descriptions/systemnb__RootSocketKit.md - wiki/sources/descriptions/rogxo__kernel_hack.md - wiki/sources/descriptions/Poko-Apps__MemKernel.md - wiki/sources/descriptions/Poko-Apps__Il2cppDumpDroidGUI.md - wiki/sources/descriptions/Poko-Apps__CodMDumper.md - wiki/sources/descriptions/PAGalaxyLab__YAHFA.md - wiki/sources/descriptions/PShocker__Zygisk-MagiskHide.md - wiki/sources/descriptions/MhmRdd__NoHello.md - wiki/sources/descriptions/PerformanC__ReZygisk.md - wiki/sources/descriptions/Dr-TSNG__ApplistDetector.md - wiki/sources/descriptions/Dr-TSNG__ZygiskOnKernelSU.md - wiki/sources/descriptions/Abbbbbi__Frida-Seccomp.md - wiki/sources/descriptions/Admirepowered__Zygisk_mod.md - wiki/sources/descriptions/Dispa1r__Integrated_kernel_module.md - wiki/sources/descriptions/Darlenepurpleblack444__Zygisk-Il2CppFucker.md - wiki/sources/descriptions/Perfare__Zygisk-Il2CppDumper.md - wiki/sources/descriptions/PixelOS-AOSP__official_devices.md - wiki/sources/descriptions/PixelOS-AOSP__manifest.md - wiki/sources/descriptions/abcz316__rwProcMem33.md - wiki/sources/descriptions/abcz316__SKRoot-linuxKernelRoot.md - wiki/sources/descriptions/ri-char__rwMem.md - wiki/sources/descriptions/mrcang09__Android-Mem-Edit.md - wiki/sources/descriptions/ri-char__pwatch.md - wiki/sources/descriptions/enenH__pwatch-c.md - wiki/sources/descriptions/Ylarod__hardware-breakpoint.md - wiki/sources/descriptions/suifei__fridare.md - wiki/sources/descriptions/Ylarod__Florida.md - wiki/sources/descriptions/TheQmaks__phantom-frida.md - wiki/sources/descriptions/CrackerCat__strongR-frida-android.md - wiki/sources/descriptions/AsenOsen__frida-stealth.md - wiki/sources/descriptions/1013503897__Morphida.md - wiki/sources/descriptions/noobpk__frida-android-hook.md - wiki/sources/descriptions/su-vikas__conbeerlib.md - wiki/sources/descriptions/crmulliner__adbi.md - wiki/sources/descriptions/WaterlooBridge__adbi.md - wiki/sources/descriptions/Rprop__And64InlineHook.md - wiki/sources/descriptions/codetronik__AndroidAntiCheat.md - wiki/sources/descriptions/ARandomPerson7__G-Presto-Anti-Cheat-Reverse-Engineered.md - wiki/sources/descriptions/ARandomPerson7__Appsealing-Reversal.md - wiki/sources/descriptions/Colorful-glassblock__duchamp-root.md - wiki/sources/descriptions/ChwnWang0__Android-kernel-inline-hook-framework.md - wiki/sources/descriptions/3intermute__arm64_silent_syscall_hook.md - wiki/sources/descriptions/CoolestEnoch__kernel-su-huawei-nova2.md - wiki/sources/descriptions/cocos2d__cocos2d-x.md - wiki/sources/descriptions/cocos__cocos4.md - wiki/sources/descriptions/cocos__cocos-engine.md - wiki/sources/descriptions/cloudfuzz__android-kernel-exploitation.md - wiki/sources/descriptions/Markakd__bad_io_uring.md - wiki/sources/descriptions/ScottyBauer__Android_Kernel_CVE_POCs.md - wiki/sources/descriptions/cs1ime__AndroidSuperInject.md - wiki/sources/descriptions/strazzere__anti-emulator.md - wiki/sources/descriptions/reveny__Android-Emulator-Detection.md - wiki/sources/descriptions/strazzere__android-unpacker.md - wiki/sources/descriptions/rednaga__APKiD.md - wiki/sources/descriptions/staturnzz__oob_entry.md - wiki/sources/descriptions/staturnzz__momentarius.md - wiki/sources/descriptions/0x36__weightBufs.md - wiki/sources/descriptions/0x36__Pixel_GPU_Exploit.md - wiki/sources/descriptions/roothide__Dopamine2-roothide.md - wiki/sources/descriptions/stars-one__ASCTool.md - wiki/sources/descriptions/obfusk__apksigcopier.md - wiki/sources/descriptions/ssut__payload-dumper-go.md - wiki/sources/descriptions/springmusk026__Imgui-Unity.md - wiki/sources/descriptions/springmusk026__ImGui-Unity-With-Layout.md - wiki/sources/descriptions/gmh5225__ImGui-Unity-Android.md - wiki/sources/descriptions/gmh5225__IOS-jailbreak--Fugu15.md - wiki/sources/descriptions/springmusk026__Android-ModMenu-SemiJni.md - wiki/sources/descriptions/springmusk026__Android-Mod-Menu-Kotlin.md - wiki/sources/descriptions/sanqiuu__AndroidCheatTemplate.md - wiki/sources/descriptions/gmh5225__AndroidCheatTemplate.md - wiki/sources/descriptions/gmh5225__Android-MemoryTool.md - wiki/sources/descriptions/AndroidReverser-Test__Kernel-Trace.md - wiki/sources/descriptions/Anatdx__Kasumi.md - wiki/sources/descriptions/Anonym0usWork1221__C-Android-Memory-Tool.md - wiki/sources/descriptions/Exo1i__MagiskHluda.md - wiki/sources/descriptions/ExploitTheLoop__writemem.md - wiki/sources/descriptions/ExWhyZed9__android_kernel_gki_common_5.10.md - wiki/sources/descriptions/Elcapitanoe__pif-config-generator.md - wiki/sources/descriptions/s3rg0x__AIMachDec.md - wiki/sources/descriptions/gilboz__ida_kernelcache_ng.md - wiki/sources/descriptions/cellebrite-labs__ida_kcpp.md - wiki/sources/descriptions/cellebrite-labs__PPLorer.md - wiki/sources/descriptions/s4m33r89__Imgui-Native-ModMenu.md - wiki/sources/descriptions/skylicht-lab__skylicht-engine.md - wiki/sources/descriptions/sergiovillaverde__win11_apk_installer.md - wiki/sources/descriptions/rockbruno__swiftshield.md - wiki/sources/descriptions/pykaso__Swift-String-Obfuscator.md - wiki/sources/descriptions/ri-char__zygisk-dump-dex.md - wiki/sources/descriptions/reveny__Zygisk-ImGui-Mod-Menu.md - wiki/sources/descriptions/lbertitoyt__ImGUI-Zygisk-Unity.md - wiki/sources/descriptions/reveny__Android-Virtual-Inject.md - wiki/sources/descriptions/reveny__Android-Ptrace-Injector.md - wiki/sources/descriptions/reveny__Android-LD-Preload-Injector.md - wiki/sources/descriptions/jiqiu2022__Zygisk-MyInjector.md - wiki/sources/descriptions/hackcatml__zygisk-memdump.md - wiki/sources/descriptions/ohchase__yaui.md - wiki/sources/descriptions/emanuele-f__PCAPdroid.md - wiki/sources/descriptions/damanoreshkan-beep__rtl8852au-userspace.md - wiki/sources/descriptions/eltavine__Duck-Detector-Refactoring.md - wiki/sources/descriptions/erfur__linjector-rs.md - wiki/sources/descriptions/reveny__Android-Native-Root-Detector.md - wiki/sources/descriptions/apkunpacker__RootAppDetector.md - wiki/sources/descriptions/apkunpacker__MagiskDetection.md - wiki/sources/descriptions/apkunpacker__DetectZygisk.md - wiki/sources/descriptions/apkunpacker__AntiFrida_Bypass.md - wiki/sources/descriptions/apkunpacker__Anti-Frida.md - wiki/sources/descriptions/aimardcr__FridaDetectionBypass.md - wiki/sources/descriptions/Ishanoshada__Ultimate-Frida-Bypass.md - wiki/sources/descriptions/anbox__anbox.md - wiki/sources/descriptions/anasfanani__Magisk-Tailscaled.md - wiki/sources/descriptions/reveny__Android-Native-Import-Hide.md - wiki/sources/descriptions/reveny__Android-Library-Remap-Hide.md - wiki/sources/descriptions/radareorg__r2garlic.md - wiki/sources/descriptions/neocanable__garlic.md - wiki/sources/descriptions/quic__gunyah-hypervisor.md - wiki/sources/descriptions/Droid-VM__DroidVM.md - wiki/sources/descriptions/DoranekoSystems__DynaDbg.md - wiki/sources/descriptions/qemu-gvm__qemu-gvm.md - wiki/sources/descriptions/quarkslab__peetch.md - wiki/sources/descriptions/null-luo__btrace.md - wiki/sources/descriptions/aquasecurity__tracee.md - wiki/sources/descriptions/gmh5225__android_ebpf.md - wiki/sources/descriptions/ShinoLeah__eHook.md - wiki/sources/descriptions/Sh11no__eDBG.md - wiki/sources/descriptions/LLeavesG__eBPFDexDumper.md - wiki/sources/descriptions/Satar07__edbgserver.md - wiki/sources/descriptions/SeeFlowerX__stackplz.md - wiki/sources/descriptions/SeeFlowerX__frida-smali-trace.md - wiki/sources/descriptions/gmh5225__android-kernel-driver-template.md - wiki/sources/descriptions/aosp-mirror__kernel_common.md - wiki/sources/descriptions/gmh5225__Android-ModGamesByInjectZygote.md - wiki/sources/descriptions/AndroidModLoader__AndroidModLoader.md - wiki/sources/descriptions/gmh5225__Android-DLL-Injector.md - wiki/sources/descriptions/gmh5225__AndroidDriveSignity.md - wiki/sources/descriptions/quarkslab__AERoot.md - wiki/sources/descriptions/newbit1__rootAVD.md - wiki/sources/descriptions/gmh5225__MagiskOnWSALocal.md - wiki/sources/descriptions/LSPosed__MagiskOnWSALocal.md - wiki/sources/descriptions/cinit__WSAPatch.md - wiki/sources/descriptions/alesimula__wsa_pacman.md - wiki/sources/descriptions/WSA-Community__WSA-Linux-Kernel.md - wiki/sources/descriptions/Mrack__MemDetection.md - wiki/sources/descriptions/Mrack__DeObfBR.md - wiki/sources/descriptions/MiCode__kernel_devicetree.md - wiki/sources/descriptions/MiCode__Xiaomi_Kernel_OpenSource.md - wiki/sources/descriptions/MlgmXyysd__KernelSU_Debug.md - wiki/sources/descriptions/MlgmXyysd__Xiaomi-HyperOS-BootLoader-Bypass.md - wiki/sources/descriptions/Mood-Coding__pubgm_shitty_source.md - wiki/sources/descriptions/MustardChef__WSABuilds.md - wiki/sources/descriptions/LSPosed__WSA-Kernel-SU.md - wiki/sources/descriptions/KiruyaMomochi__wsa-kernel-build.md - wiki/sources/descriptions/K3V1991__How-to-download-and-install-WSA.md - wiki/sources/descriptions/LSPosed__DexBuilder.md - wiki/sources/descriptions/LSPosed__DirtySepolicy.md - wiki/sources/descriptions/LSPosed__AndroidHiddenApiBypass.md - wiki/sources/descriptions/MuntashirAkon__AppManager.md - wiki/sources/descriptions/d4rken-org__butler.md - wiki/sources/descriptions/qq703048949__event_replay.md - wiki/sources/descriptions/muchenspace__android_virtualTouch.md - wiki/sources/descriptions/paradiseduo__IPAPatch.md - wiki/sources/descriptions/addrianyy__ios_packager.md - wiki/sources/descriptions/adanainv3-creator__OxClient.md - wiki/sources/descriptions/palera1n__palera1n.md - wiki/sources/descriptions/open-obfuscator__dProtect.md - wiki/sources/descriptions/Octowolve__Unity-ImGUI-Android.md - wiki/sources/descriptions/opa334__opainject.md - wiki/sources/descriptions/opa334__TrollStore.md - wiki/sources/descriptions/opa334__Dopamine.md - wiki/sources/descriptions/miticollo__xpc-tracer.md - wiki/sources/descriptions/mut1234__BYPASS-PUBG-MOBILE-IMGUI.md - wiki/sources/descriptions/Polarmods__PolarImGui.md - wiki/sources/descriptions/SsageParuders__CheatUnityGames.md - wiki/sources/descriptions/ServenScorpion__VirtualApp.md - wiki/sources/descriptions/Solaree__pairipcore.md - wiki/sources/descriptions/Super-Cssdiv__ChinaPubg.md - wiki/sources/descriptions/halloweeks__pubg-mobile-pak-extract.md - wiki/sources/descriptions/gmh5225__pubgm_sdk_and_offsets.md - wiki/sources/descriptions/gmh5225__pubg_mobile_memory_hacking_examples.md - wiki/sources/descriptions/atulkunal999__pubg_mobile_memory_hacking.md - wiki/sources/descriptions/atlas4381__qualcomm_avb_exploit_poc.md - wiki/sources/descriptions/gmh5225__PUBGM1.6-DeadGame.md - wiki/sources/descriptions/gmh5225__PUBGM-PUBGPatcher.md - wiki/sources/descriptions/gmh5225__PTFakeTouch.md - wiki/sources/descriptions/gmh5225__LastIslandOfSurvival-iOSCheat-Source.md - wiki/sources/descriptions/gmh5225__pubg.md - wiki/sources/descriptions/mrexodia__lldbext-dump.md - wiki/sources/descriptions/musabcel__android_rom_list.md - wiki/sources/descriptions/mrx7014__SpoofingCollection.md - wiki/sources/descriptions/wchunlin1006__LocusMimic.md - wiki/sources/descriptions/cxOrz__AnyWhere.md - wiki/sources/descriptions/Xposed-Modules-Repo__com.wowsoftware.hidemyandroid.md - wiki/sources/descriptions/GJR787878__DeviceResetSpoofer.md - wiki/sources/descriptions/AtawurRahmanTanvir__NEXUS.md - wiki/sources/descriptions/AlirezaParsi__COPG.md - wiki/sources/descriptions/Android1500__AndroidFaker.md - wiki/sources/descriptions/mekos2772__ios-location-spoofer.md - wiki/sources/descriptions/Yu9191__wloc.md - wiki/sources/descriptions/maoabc__nmmp.md - wiki/sources/descriptions/lzghzr__APatch_kpm.md - wiki/sources/descriptions/loerting__dalvikus.md - wiki/sources/descriptions/lockedbyte__so_loader.md - wiki/sources/descriptions/icculus__mojoelf.md - wiki/sources/descriptions/smithluke874__Android-VirtualCam-Manager.md - wiki/sources/descriptions/libtersafe__dfm_android_unicorn.md - wiki/sources/descriptions/andoridcharlyroot-debug__charlyengine.md - wiki/sources/descriptions/dbcyyds__MemDbg.md - wiki/sources/descriptions/darvincisec__DetectFrida.md - wiki/sources/descriptions/deadeert__EWS.md - wiki/sources/descriptions/libtersafe__KPM-MemReader.md - wiki/sources/descriptions/kkkbbb__rustFrida.md - wiki/sources/descriptions/kkkbbb__mkpms.md - wiki/sources/descriptions/khanhduytran0__coruna.md - wiki/sources/descriptions/keowu__sjcam.md - wiki/sources/descriptions/TaszkSecLabs__xiaomi-c400-pwn.md - wiki/sources/descriptions/mytechnotalent__Embedded-Hacking.md - wiki/sources/descriptions/jwmcglynn__android-emulator.md - wiki/sources/descriptions/google__android-emulator-hypervisor-driver.md - wiki/sources/descriptions/google__android-classyshark.md - wiki/sources/descriptions/gmh5225__zygisk-imgui-modmenu.md - wiki/sources/descriptions/fatalSec__DaliVM.md - wiki/sources/descriptions/eybisi__kavanoz.md - wiki/sources/descriptions/fedes1to__Zygisk-ImGui-Menu.md - wiki/sources/descriptions/FBlackBox__BlackBox.md - wiki/sources/descriptions/Fox2Code__FoxMagiskModuleManager.md - wiki/sources/descriptions/gmh5225__yuzu-android.md - wiki/sources/descriptions/RemiPelloux__OpenSw.md - wiki/sources/descriptions/RytterMohn__UsbDetectionBypass.md - wiki/sources/descriptions/moaaz01__nightowl.md - wiki/sources/descriptions/jjolano__shadow.md - wiki/sources/descriptions/jiayy__android_vuln_poc-exp.md - wiki/sources/descriptions/jiayuxuan123__RescueX.md - wiki/sources/descriptions/jailbreakdotparty__dirtyZero.md - wiki/sources/descriptions/jbro129__android-modding.md - wiki/sources/descriptions/j-hc__FlagSecurePatcher.md - wiki/sources/descriptions/infosecrajesh__Auto-generate-Frida-bypass-scripts-for-SSL-pinning-root-detection-on-Android-iOS.md - wiki/sources/descriptions/index-login__MobileRE-Skill.md - wiki/sources/descriptions/imxiaoc996__DeviceWarLock.md - wiki/sources/descriptions/okhsunrog__vpnhide.md - wiki/sources/descriptions/rathorekrishna401-NeuroVoid__ApexSU.md - wiki/sources/descriptions/salvogiangri__KnoxPatch.md - wiki/sources/descriptions/gmh5225__MapleServerAndroid.md - wiki/sources/descriptions/quarkslab__android-hardware-attestation-demo.md - wiki/sources/descriptions/gmh5225__KernelSU-4.4.md - wiki/sources/descriptions/gmh5225__A146B-KSU.md - wiki/sources/descriptions/gmh5225__Android_Native_Surface.md - wiki/sources/descriptions/SsageParuders__Android_Native_Surface.md - wiki/sources/descriptions/geeksonsecurity__android-overlay-protection.md - wiki/sources/descriptions/geeksonsecurity__android-overlay-malware-example.md - wiki/sources/descriptions/g2wfw__qbdi-tracer-android.md - wiki/sources/descriptions/fiord__ADB-Debug-Detect-Checker.md - wiki/sources/descriptions/fynks__awesome-android-root.md - wiki/sources/descriptions/fuqiuluo__rnidbg.md - wiki/sources/descriptions/fuqiuluo__ovo.md - wiki/sources/descriptions/fuqiuluo__android-wuwa.md - wiki/sources/descriptions/forcequitOS__bad_query.md - wiki/sources/descriptions/droidrun__droidrun.md - wiki/sources/descriptions/Genymobile__scrcpy.md - wiki/sources/descriptions/Genymobile__genymotion-kernel.md - wiki/sources/descriptions/barry-ran__QtScrcpy.md - wiki/sources/descriptions/badabing2005__PixelFlasher.md - wiki/sources/descriptions/ShivamXD6__ROM-Shifter.md - wiki/sources/descriptions/BossKoopa__BWSR.md - wiki/sources/descriptions/BuSung-dev__Root-My-Galaxy.md - wiki/sources/descriptions/alex193a__Root-My-Pixel.md - wiki/sources/descriptions/YuKongA__ghostlock-app.md - wiki/sources/descriptions/JoinChang__ghostlock-oneplus.md - wiki/sources/descriptions/dreamland-blog__KSU-Rust-Frida.md - wiki/sources/descriptions/MiChongs__Frida-RS.md - wiki/sources/descriptions/MMRLApp__WebUI-X-Portable.md - wiki/sources/descriptions/cfig__Android_boot_image_editor.md - wiki/sources/descriptions/bmax121__KernelPatch.md - wiki/sources/descriptions/bmax121__APatch.md - wiki/sources/descriptions/5ec1cff__TrickyStore.md - wiki/sources/descriptions/beakthoven__TrickyStore.md - wiki/sources/descriptions/block__stoic.md - wiki/sources/descriptions/ByNameModding__BNM-Android.md - wiki/sources/descriptions/binsnake__fARM64.md - wiki/sources/descriptions/brunodev85__winlator.md - wiki/sources/descriptions/ant4g0nist__rudroid.md - wiki/sources/descriptions/WindySha__bypassHiddenApiRestriction.md - wiki/sources/descriptions/WsttXm__RiskEngine.md - wiki/sources/descriptions/VarshaWanjari0__Auto-Android-App-Modding-Tool.md - wiki/sources/descriptions/UnityTech__GamesTestAutomationExample.md - wiki/sources/descriptions/AitiX__Fastlogs.md - wiki/sources/descriptions/AirtestProject__Airtest.md - wiki/sources/descriptions/TrungNguyen1909__aarch64-sysreg-ida.md - wiki/sources/descriptions/cognis-digital__rootsentry.md - wiki/sources/descriptions/Rem01Gaming__meowna_detector.md - wiki/sources/descriptions/savagedamage__android-security-wizard.md - wiki/sources/descriptions/NetKingJ__awesome-android-security.md - wiki/sources/descriptions/NPC2000__AppPealing-new.md - wiki/sources/descriptions/Xposed-Modules-Repo__com.fuck.iab.md - wiki/sources/descriptions/NepMods__InjectARM64.md - wiki/sources/descriptions/Nirad-Maharaj__Disable-Call-Recording-BookRestore-.md - wiki/sources/descriptions/IAIK__armageddon.md - wiki/sources/descriptions/IIIImmmyyy__ArmShellCode.md - wiki/sources/descriptions/GrapheneOS-Archive__kernel_msm-coral.md - wiki/sources/descriptions/Guardsquare__proguard.md - wiki/sources/descriptions/Guardsquare__flutter-re-demo.md - wiki/sources/descriptions/DeNA__mempatch.md - wiki/sources/descriptions/Maxamedxasa__SakoREStudio.md - wiki/sources/descriptions/AshrafMorningstar__hayday-bot.md - wiki/sources/descriptions/wumingzhinu__VirtualMachine.md updated: 2026-09-15 confidence: high --- # Mobile Security Android and iOS game security: APK/IPA analysis, native/IL2CPP reversing, root/jailbreak ecosystems, dynamic instrumentation ([[frida]]), and mobile anti-cheat (root/Frida/emulator detection). Apply [[research-rigor]] before treating root, hook, emulator, or integrity signals as attribution—behavior is strongly version-, OEM-, entitlement-, signing-, kernel-, and policy-dependent. (source: wiki/sources/skills/mobile-security.md) Record the **device, OS build, ABI, package signer, entitlements, privilege state, and collection method** before drawing conclusions about root, hook, emulator, integrity, or attestation signals. Apply [[research-rigor]] for version-sensitive attestation or bypass claims; route general engine, network-authority, or desktop-kernel questions to their narrower skill topics. (source: wiki/sources/skills/mobile-security.md) ## Topic routing | Question lane | Route | |---------------|-------| | Package/signing, platform policy, root/jailbreak, attestation | [[mobile-trust-boundaries]]; Android/iOS lanes below | | IL2CPP/Mono, Unreal, overlays, traffic, mobile AC | [[il2cpp]], [[unreal-object-model]], [[mobile-anti-cheat]], [[mobile-network-trust-evidence]]; [[overviews/game-engine]] | | eBPF, Android kernels, HarmonyOS, CVEs, emulators | eBPF / kernel / HarmonyOS sections below; [[overviews/reverse-engineering]] | | Backend purchases, entitlements, replay | game-server-security skill topic | | Build/update provenance, sideload supply chain | game-supply-chain-security skill topic | | Repository resource selection | [[resource-selection]], [[repository-navigation]] | | Disputed implementation or detectability claims | [[research-rigor]] | Use sibling skill topics when one boundary dominates the question. (source: wiki/sources/skills/mobile-security.md) ## Trust boundaries Separate **package/signing**, **runtime/process isolation**, **platform/device integrity**, and **server authorization/game rules** before attributing cheating or trusting a client assertion. See [[mobile-trust-boundaries]] for the boundary map, baseline dimensions (device/build/ABI, signer, entitlements, required privilege), and evidence-report fields. | Question | Preserve in the report | |----------|------------------------| | What boundary was crossed? | Ordinary app access vs developer build vs privileged/kernel vs server | | What changed in the observation? | Module/memory provenance, process lifecycle, control-channel exposure | | What could be missed? | Uncovered startup, native vs managed execution, observer effects | | Is a detector conclusion justified? | Defined signal, exact tested configuration, benign/debug comparison, FPR/FNR limits | Platform integrity: record **SELinux** enforcement/domain/denials for root and modified-kernel hosts; validate **Play Integrity** request identity, binding, and freshness on the backend ([[pif-config-generator]], [[zamr]] for research configs); verify **App Attest** attestations/assertions server-side with challenge/counter handling; inspect actual **Network Security Configuration** and build variant before inferring release TLS/pinning from debug captures. Route verified purchases, entitlement transitions, and account authorization to game-server-security; build provenance and update channels to game-supply-chain-security. (source: wiki/sources/skills/mobile-security.md) KernelSU/APatch architecture: root-enabled apps still split user-space credentials, privileged services, and kernel components—compare exact release, boot-image provenance, and module configuration rather than ranking frameworks by name. Privileged instrumentation ([[frida]] modes, [[zygisk]] inject paths, eBPF loaders) creates an observable surface along the full privileged path; one absent local signal does not establish a clean device. ## Root frameworks | Solution | Level | Stealth | GKI | Module system | |----------|-------|---------|-----|---------------| | [[magisk]] | User/init | Medium | Yes | Mature (DenyList / Shamiko root-hide) | | [[kernelsu]] | Kernel | High | Yes | Growing (Magisk-module API compat) | | [[apex-su]] | Kernel (KernelSU fork) | High+ | Yes (GKI 2.0) | KernelSU-compatible; Rust userspace + stealth IOCTL | | [[apatch]] | Kernel (KernelPatch boot patch) | High | Yes | KPM modules; SuperKey above root (stock GKI) | | [[apatch-kpm]] | Kernel (KPM collection) | High | Yes | Example KPM module pack for [[apatch]] | Debug-oriented KernelSU fork [[kernelsu-debug]] (MlgmXyysd; relaxed manager checks, permissive SELinux options, init script support; kernel C + Android app/build assets; profile control; Android security research / system debugging; cheat / KernelSU modified for debugging) trades production hardening for lab convenience beside upstream [[kernelsu]]. (source: wiki/sources/descriptions/MlgmXyysd__KernelSU_Debug.md) [[apatch]] (bmax121; Android kernel + system patch; SuperKey above root; cheat / Android root) applies [[kernelpatch]] boot-image patching on stock GKI Android without custom kernel sources. APatch **KPM** (KernelPatch Module) collections such as [[apatch-kpm]] (C/C++; kernel modding/debug extensions for the APatch module lane) extend root at kernel scope — same KPM class as ACE title RE (`acepeek` in [[honor-of-kings-re-research]]). (source: wiki/sources/descriptions/bmax121__APatch.md) (source: wiki/sources/descriptions/bmax121__KernelPatch.md) (source: wiki/sources/descriptions/lzghzr__APatch_kpm.md) Android kernel root patch toolkit [[skroot-linux-kernel-root]] (abcz316; C/C++ patch + Java/JNI app tooling; deeply hidden root, su install/inject, many kernel versions without full rebuild; cheat / Android root) targets stock-kernel root-hide research beside KernelPatch/APatch lanes. (source: wiki/sources/descriptions/abcz316__SKRoot-linuxKernelRoot.md) Curated Android root resource index [[awesome-android-root]] (fynks; documentation/list; cheat / Android root) aggregates frameworks, modules, and bypass references; flags stricter **Play Integrity** on Android 14/15 when pairing root with game integrity checks. (source: wiki/sources/descriptions/fynks__awesome-android-root.md) Broader Android security learning index [[awesome-android-security]] (NetKingJ; theory/tools/write-ups/PoCs/CVE reports; kernel exploitation, app testing, Frida workflows, Samsung-focused references; cheat / Android (Samsung) Security Research References) complements that root lane for pentesters and mobile RE practitioners. (source: wiki/sources/descriptions/NetKingJ__awesome-android-security.md) Integrated operational corpus [[android-security-wizard]] (savagedamage; SKILL.md + 20 companion docs; APK/DEX/native RE, Frida/Shizuku/Objection/Ghidra workflows, DexGuard/Bangcle protector bypass, ARM64 kernel exploit methodology, malware triage, Android 14–18 platform deltas; cheat / Guide) extends that learning lane with a structured assessment playbook. (source: wiki/sources/descriptions/savagedamage__android-security-wizard.md) AOSP and custom-ROM platform engineering index [[awesome-android-aosp]] (Akipe; build systems, kernels, device trees, Treble, SELinux, debugging, vendor workflows; low-level platform map vs app development; cheat / Guide) situates the stack beneath root and APK tooling for mobile and game security researchers. (source: wiki/sources/descriptions/Akipe__awesome-android-aosp.md) Root-only USB serial number spoofing such as [[usbsn]] (ekknod; C++/Java; peripheral HWID surface; Some Tricks / Android) sits in the same root-dependent device-identity lane beside mount/prop hide work. (source: wiki/sources/descriptions/ekknod__usbsn.md) Xposed/LSPosed identifier spoofing via [[android-faker]] (Android1500; IMEI, Android ID, MAC, SIM, and tracking-relevant fields; randomization + manual edit; privacy / fingerprint testing on rooted Xposed hosts; cheat / Android) complements profile-based [[hidemyandroid]] in the same per-app hook lane. (source: wiki/sources/descriptions/Android1500__AndroidFaker.md) Post-wipe automatic identity regeneration via [[device-reset-spoofer]] (GJR787878; LSPosed; sentinel-file detection on app data clear; togglable Android ID/GAID/IMEI/MAC/GSF ID/build fingerprint hooks; manual reset; Android 7–16; cheat / Xposed) extends that lane for ban-evasion after clearing game data. (source: wiki/sources/descriptions/GJR787878__DeviceResetSpoofer.md) In-app USB connection and USB debugging detection masking via [[usb-detection-bypass]] (RytterMohn; Kotlin + native C++ LSPosed/Xposed; scoped per-app hooks on SystemProperties, UsbManager, USB/battery broadcasts, getprop/dumpsys, and sysfs reads so target processes see disconnected, non-debuggable USB; cheat / Xposed) supports anti-cheat testing while tethered or with developer options enabled. (source: wiki/sources/descriptions/RytterMohn__UsbDetectionBypass.md) Root-orchestrated identity rotation such as [[nexus]] (AtawurRahmanTanvir; Kotlin/Compose; macro-execution via `su` into DeviceSpoofingEngine/BuildPropEngine for Android ID/MAC/IMEI/`build.prop`, NetworkEngine/DnsTunnelEngine for IP/DNS, MemoryPurgeEngine cache purge, GmailAutomationEngine telemetry cleanup; Ghost Module silent multi-layer ops; live terminal console; device fingerprint evasion / anti-ban identity rotation; cheat / Android) extends that lane with privileged system-wide sanitization beyond per-app Xposed hooks. (source: wiki/sources/descriptions/AtawurRahmanTanvir__NEXUS.md) Zygisk hardware-profile spoofing such as [[copg]] (AlirezaParsi; C++ Zygisk module + JS WebUI; per-app CPU/GPU/build-prop/IMEI/Widevine/SIM/GAID spoof; stealth copy-on-write or unload-before-launch vs resident GPU/DRM hooks; bypass hardware-gated FPS/graphics tiers; mobile game fingerprint research; cheat / Android) extends that identity lane via Magisk-style Zygisk specialization-path hooks. (source: wiki/sources/descriptions/AlirezaParsi__COPG.md) Kernel-level roots avoid a filesystem `su` binary and can hide from mount-namespace / package-manager probes that target classic Magisk artifacts—detectors such as [[magiskdetector]], [[magisk-detection]] (apkunpacker; archive of Android root/Magisk POC APKs—Zygisk, hook/instrumentation, bootloader/ROM, root-app checks; sample hashes for cross-tool comparison; source: wiki/sources/descriptions/apkunpacker__MagiskDetection.md), [[dirty-sepolicy]] (LSPosed; App Zygote AIDL bind → runtime permissive SELinux rule injection without root/kernel mods; SELinux access checks from zygote context detect userspace `su`; Detection:Android root; source: wiki/sources/descriptions/LSPosed__DirtySepolicy.md), [[root-app-detector]] (apkunpacker; Java POC; launch known root-manager package/activity pairs and interpret `SecurityException`; rescan UI; Detection:Android root; source: wiki/sources/descriptions/apkunpacker__RootAppDetector.md), [[applist-detector]] (Dr-TSNG; Kotlin + native C++ detection library/demo; package inspection, FS artifacts, syscall file probes, Xposed status, dual/work-profile anomalies; mobile anti-cheat / root-detection research; source: wiki/sources/descriptions/Dr-TSNG__ApplistDetector.md), [[magisk-killer]] (canyie; forked subprocess + pipe IPC; Magisk/MagiskHide tracer, bootloader, property-area, and PTS checks outside caller trace scope; source: wiki/sources/descriptions/canyie__MagiskKiller.md), [[meowna-detector]] (Rem01Gaming; C/NDK PoC; missing logd socket + package-trace indicators for root-hide modules that disrupt logging services; source: wiki/sources/descriptions/Rem01Gaming__meowna_detector.md), [[detection]], and [[keyattestation]] still combine FS, process, property, attestation, and behavioral checks. (source: wiki/sources/skills/mobile-security.md) Offensive Magisk `su`-daemon research such as [[magisk-eop]] (canyie; Java/C PoC; race or logic flaw in root-grant path → unprivileged app to root without user approval; source: wiki/sources/descriptions/canyie__MagiskEoP.md) documents trust-boundary failures in Magisk's root-management design. Offensive root-hide samples such as [[hideroot]] (C/C++; Cheat / Magisk) study the same hide surface from the attacker side. (source: wiki/sources/descriptions/longpoxin__hideroot.md) GKI LKM root-hide framework [[kasumi]] (Anatdx; ftrace/tracepoint hooks on syscalls, VFS, and procfs; mount/SELinux/file-attribute spoofing; kernel-level path manipulation; cheat / Kernel-level path manipulation and hiding framework for Android GKI/Linux) extends that lane below userspace Magisk/Zygisk modules. (source: wiki/sources/descriptions/Anatdx__Kasumi.md) Riru Zygote-injection root-hide module [[riru-momo-hider]] (canyie; C/Java; syscall + Java API hooks against MagiskDetector/RootBeer; mount spoof, Magisk file hide, property-query block; Cheat / Magisk) targets the same detector surface via Riru's pre-app specialize path. (source: wiki/sources/descriptions/canyie__Riru-MomoHider.md) Portable ptrace MagiskHide module [[magiskhide]] (Magisk v24.0+ DenyList hidelist without Zygisk; root-detection bypass via ptrace interception; Android 11+) restores post-removal hide for researchers. (source: wiki/sources/descriptions/gmh5225__MagiskHide.md) Zygisk-based MagiskHide-style module [[zygisk-magiskhide]] (PShocker; native mount concealment + sensitive system-property patching; multi-ABI module packaging; mobile security research / anti-detection testing; source: wiki/sources/descriptions/PShocker__Zygisk-MagiskHide.md) targets the same hide surface via the Zygisk specialization path. Zygisk root-hide module [[nohello]] (MhmRdd; native code + Android build tooling; blacklist/whitelist modes + mount-rule unmount logic; Magisk/KernelSU/APatch; root-detection resistance research; cheat / Zygisk module to hide root) extends that lane with configurable per-app targeting. (source: wiki/sources/descriptions/MhmRdd__NoHello.md) Boot-loop auto-rescue module [[rescuex]] (Magisk/KernelSU/APatch; boot watchdog, tiered module disable, snapshots/rollback, safe mode, WebUI; offline recovery when faulty modules block boot) sits in the same module-ecosystem lane for developers testing experimental root modules. (source: wiki/sources/descriptions/jiayuxuan123__RescueX.md) Standalone MMRL WebUI X portable host [[webui-x-portable]] (MMRLApp; Kotlin/Compose HybridWebUI runtime; JS bridge for root shell/filesystem/module metadata; Magisk/KernelSU/APatch/SukiSU; non-root portable mode + optional spoofed package names; module browse/install/configure without full MMRL manager; cheat / Android root module WebUI) complements that lane for HTML/JS module configuration UIs. (source: wiki/sources/descriptions/MMRLApp__WebUI-X-Portable.md) Dedicated Magisk module manager [[fox-magisk-module-manager]] (Fox2Code; Kotlin Android app; online repo search/download/install, update checks, custom repos, local vs remote module views, richer metadata/compatibility for developers; rooted module management; Cheat / Magisk) complements stock Magisk manager workflows for module discovery and lifecycle. (source: wiki/sources/descriptions/Fox2Code__FoxMagiskModuleManager.md) Policy-controlled deep storage cleanup module [[baize]] (Kotlin/C; libsu RootService + native rule engine; four-tier risk tiers, whitelists, quarantine/audit; cache/log/APK-residue scans with symlink-safe deletes; Cheat / Magisk) complements that lane for rooted operators who need filesystem hygiene without touching protected downloads or databases. (source: wiki/sources/descriptions/xgl34222220-ops__BaiZe.md) Magisk module [[magisk-tailscaled]] (anasfanani; userspace Tailscale daemon; VPN coexistence; service scripts + tunnel helpers; CLI login/SSH/ADB-over-tailnet on arm/arm64; Cheat / Magisk) supports persistent remote lab access on rooted Android devices. (source: wiki/sources/descriptions/anasfanani__Magisk-Tailscaled.md) Samsung Knox-gated app restoration on rooted Galaxy hardware via [[knoxpatch]] (LSPosed Xposed hooks plus optional KnoxPatch Enhancer Magisk/KernelSU module; root-detection bypass, property spoofing, Knox SDK / Samsung Attestation Key / Keystore / Knox Matrix API patches; One UI Android 9–16) studies OEM integrity checks on modified Samsung devices. (source: wiki/sources/descriptions/salvogiangri__KnoxPatch.md) [[flagsecurepatcher]] (disable `FLAG_SECURE` + screenshot listeners; Cheat / Magisk documentation) sits in the adjacent Android screen-capture bypass lane. (source: wiki/sources/descriptions/j-hc__FlagSecurePatcher.md) ## APK & native analysis Static lane: [[apktool]] decode/rebuild (resources, smali, manifest) — Windows GUI bundle [[apktoolgui]] (AndnixSH; C#/.NET; apktool + signapk + zipalign + baksmali; drag-and-drop, ADB helpers, framework management; legitimate APK analysis/modification; `[Apk]`) (source: wiki/sources/descriptions/AndnixSH__APKToolGUI.md) — VS Code integrated workbench [[apklab]] (APKLab; TypeScript; Apktool + JADX + signing + HTTPS patching helpers; decode/disasm/decompile/rebuild/sign/install/dependency bootstrap; cross-platform desktop IDE; mobile security / malware / tampering testers; `[Apk]`) (source: wiki/sources/descriptions/APKLab__APKLab.md) → [[jadx]] DEX→Java → [[apkid]] packer/protector ID → native `.so` RE in IDA/Ghidra; Bash orchestration [[apk-sh]] (ax; pull/decode/rebuild/patch, Frida gadget inject, split/bundle merge, apksigner re-sign; multi-arch; no root required) wraps that decode→patch→sign loop in one CLI for mobile RE workflows. (source: wiki/sources/descriptions/ax__apk.sh.md); on-device ARM64 ROM/APK toolkit [[tool-tree]] (Zenlua; Kotlin/Java + Bash; boot/dtbo/ext4/erofs/f2fs/payload/super/APK/APKS/APEX/CAPEX unpack-pack; apktool-style decode/build, signing, BusyBox; root or non-root; Addon/Apkon modules) complements desktop lanes for field firmware and package manipulation. (source: wiki/sources/descriptions/Zenlua__Tool-Tree.md); Termux on-device APK modding TUI [[auto-android-app-modding-tool]] (UAMT; Python; Frida Gadget + custom `.so` inject; patchelf vs APKEditor smali auto-select for `libil2cpp.so`/`libunity.so`; multi-ABI gadget fetch, zipalign, v1/v2/v3 sign; no root; VarshaWanjari0) wraps patch→rebuild→sign on Android hardware. (source: wiki/sources/descriptions/VarshaWanjari0__Auto-Android-App-Modding-Tool.md); Morphe universal patch catalog [[nai64-patches]] (Nai64; Kotlin/Gradle; ~100 optional patches—ad removal, license/Play Integrity bypass, root/emulator hide, SSL pinning bypass, telemetry block, device/manifest spoof; APK rebuild inside Morphe; mobile game RE / modding; cheat / Morphe patch source) complements that decode→patch→sign lane for integrity-heavy Android titles. (source: wiki/sources/descriptions/Nai64__Nai64Patches.md); non-host-architecture emulation in IDA via [[ews]] (Unicorn; ARM/x86/x64; trace + asm/disasm; Android native libs / embedded / automotive firmware) (source: wiki/sources/descriptions/deadeert__EWS.md); educational Rust Android ELF user-mode emulator [[rudroid]] (ELF loader, memory management, syscall handling, filesystem abstractions, ARM64 Unicorn execution scaffolding; walkthrough docs + sample binaries; cheat / Android native RE / emulation) (source: wiki/sources/descriptions/ant4g0nist__rudroid.md); ARM64 branch-obfuscation deobf via [[deobfbr]] (Mrack; Python; Unicorn emulation + Capstone/Keystone + ELF parse; function start/end → reconstructed `.so`; malware/game-protection native RE; libtprt.so; source: wiki/sources/descriptions/Mrack__DeObfBR.md). (source: wiki/sources/descriptions/iBotPeaches__Apktool.md) Quick structural triage GUI [[android-classyshark]] (Google ClassyShark; APK/DEX/AAR/class inspection — hierarchies, method counts, dependencies, multidex) complements decode/decompile before deeper RE. (source: wiki/sources/descriptions/google__android-classyshark.md) Multi-decompiler suite [[bytecode-viewer]] (CFR, Procyon, FernFlower, JD-GUI, Krakatau; tabbed bytecode/decompiled source/Smali for JAR/class/DEX/APK; compare outputs in one GUI) complements that lane for side-by-side decompiler comparison. (source: wiki/sources/descriptions/gmh5225__bytecode-viewer.md) JVM/Android bytecode editing workstation [[recaf]] (Col-E; multi-decompiler + bytecode assembly/recompile, deep search, deobfuscation-oriented transforms; `[Java]`) adds edit/patch/recompile workflows beside view/compare. (source: wiki/sources/descriptions/Col-E__Recaf.md); DEX control-flow obfuscator [[black-obfuscator]] (CodingGay; Java; modified dex2jar pipeline; configurable depth, package targeting, rule-based processing; GUI + Android Studio plugin; mobile app protection / anti-RE; `[Dex]`) (source: wiki/sources/descriptions/CodingGay__BlackObfuscator.md); modular Python black-box APK obfuscator [[obfuscapk]] (ClaudiuGeorgiu; apktool decompile → smali/resources/manifest obfuscation passes → rebuild; multiple obfuscators; early AAB support via external decompiler; mobile RE resilience / signature-evasion evaluation; `[Android]`) (source: wiki/sources/descriptions/ClaudiuGeorgiu__Obfuscapk.md); CLI APK/game protection packer beto2-dev/Hyapk (Kotlin CLI + C runtime; per-method HyVm VMP or Dex2C, ChaCha20-Poly1305 opcode encryption, smali renaming, resource encryption, anti-tamper/anti-debug, anti-Frida/root/emulator heuristics; Anti Cheat Binary Packer lane) (source: wiki/sources/descriptions/beto2-dev__Hyapk.md) Unified APK assessment CLI [[nightowl]] (Python; nine-section scan; Flutter/RN/Cordova/Unity detection; RASP profiling; auto [[frida]] bypass scripts; MASTG Semgrep; JSON output) orchestrates jadx/apktool/androguard/Semgrep/Frida in one pass. (source: wiki/sources/descriptions/moaaz01__nightowl.md) Unity IL2CPP: extract `libil2cpp.so` + `global-metadata.dat` → dumper/headers → hook via [[frida]] or inline hooks (see [[il2cpp]]). Live Frida runtime metadata harvesters such as [[frida-il2cpp-datacollector]] (Android/iOS; class/method/field/type collection for SDK builds; CE MonoDataCollector port) sit beside static dumpers when attach-time enumeration is preferred. (source: wiki/sources/descriptions/gmh5225__frida-il2cpp-datacollector.md) Android IL2CPP/Mono hook script templates such as [[il2cpp-hook-scripts]] (gmh5225; Frida + native templates for method intercept, logic patches, runtime data extraction) complement dump/harvest tooling when reusable hook scaffolds are needed. (source: wiki/sources/descriptions/gmh5225__Il2Cpp-HookScripts.md) Frida runtime parse/hook frameworks such as [[il2cpp-hookscripts]] (axhlzy; TypeScript **il2cpp-hooker** npm; batch hooks, return-value edits, QBDI emulation, JNI `RegisterNatives` hooking, MCP companion) offer structured Unity IL2CPP instrumentation beside script-template collections. (source: wiki/sources/descriptions/axhlzy__Il2CppHookScripts.md) Managed Mono builds use extracted DLLs + dnSpy/ILSpy or runtime hooks. ## Instrumentation & hooking - **[[frida]]** — attach/spawn, Java/ObjC/native intercept; mobile ACs probe Frida artifacts ([[antifrida]], [[frida-detection]], native [[detect-frida]] with pipe/thread/`.text` integrity checks plus O-LLVM hardening; system-library memory-vs-disk CRC checks such as [[memdetection]] (Mrack; Java + Rust/JNI; `libc.so`/`libart.so`; Frida/Xposed/cloning demo; source: wiki/sources/descriptions/Mrack__MemDetection.md); write-up collections such as [[anti-frida]] with libc prologue hook-detection examples); bypass script collections such as [[anti-frida-bypass]] (apkunpacker; Frida JS; libc/process-introspection hooks; procfs string masking; multiple app-protection variants; mobile RE / Frida-detection resilience testing) sit on the offensive side of that lane. (source: wiki/sources/descriptions/apkunpacker__AntiFrida_Bypass.md) Organized Android hook script kits such as [[frida-mobile-kit]] (unrandoms; SSL pinning bypass OkHttp/TrustManager/Conscrypt/Flutter/React Native, traffic/crypto logging, root/SafetyNet bypass, method tracing and string dumps; Python CLI; Cheat / Frida) (source: wiki/sources/descriptions/unrandoms__frida-mobile-kit.md) complement technique collections such as [[frida-detection-bypass]] (aimardcr; debugger/port/protocol/memory-artifact bypass; JS + CLI + native JNI; non-gadget-only injection; Debugger Detection Bypass) extend that offensive lane. (source: wiki/sources/descriptions/aimardcr__FridaDetectionBypass.md) Layered RASP script [[ultimate-frida-bypass]] (Ishanoshada; nineteen Java/native hooks; Talsec/freeRASP/PairIP; port/netstat detection, threat callbacks, SSL pinning, Crashlytics suppression, libc scans) targets Talsec demo and similar protected Android apps. (source: wiki/sources/descriptions/Ishanoshada__Ultimate-Frida-Bypass.md) Source-level Frida patch/build automation via [[florida]] (Ylarod; Android anti-detection `frida-server`; string/symbol/artifact renaming; scripted reproducible builds). (source: wiki/sources/descriptions/Ylarod__Florida.md) Build-from-source anti-detection Frida via [[phantom-frida]] (TheQmaks; Python patch scripts; randomized strings/symbols/artifacts; WSL build; JavaScript tests). (source: wiki/sources/descriptions/TheQmaks__phantom-frida.md) Upstream-tracking Android patch automation via [[strongr-frida-android]] (CrackerCat; core patches to strings/pipes/symbols/protocol behaviors; lightweight build workflow). (source: wiki/sources/descriptions/CrackerCat__strongR-frida-android.md) Android fingerprint-reduction patch set [[frida-stealth]] (AsenOsen; default ports, socket names, thread names, loop labels, `frida-core`/`frida-gum` markers; patch files + build instructions). (source: wiki/sources/descriptions/AsenOsen__frida-stealth.md) CI polymorphic arm64 `frida-server` builds via [[morphida]] (1013503897; per-build upstream clone; randomized static fingerprints; NDK symbol strip; CI strings gate; adb helpers). (source: wiki/sources/descriptions/1013503897__Morphida.md) Stealth repacks such as [[fridare]]; boot-persistent Florida server modules such as [[florida-zygisk]] (Magisk/KernelSU/APatch); Magisk boot module [[magisk-hluda]] (Exo1i; stealth-modified `frida-server` at boot; module scripts + C++ update/download helper; HTML/JS WebUI for start/stop/status/custom params; persistent instrumentation / reduced detection). (source: wiki/sources/descriptions/Exo1i__MagiskHluda.md) (source: wiki/sources/descriptions/darvincisec__DetectFrida.md) Runtime JNI native-method discovery via [[frida-find-jni-native-methods]] (JavaScript hooking + memory analysis; map Java `native` stubs to `.so` implementations). (source: wiki/sources/descriptions/hackcatml__frida-findJNINativeMethods.md) ART interpreter smali instruction tracing via [[frida-smali-trace]] (SeeFlowerX; JS/TS Frida agents hook ART interpreter paths; detailed execution logs; IDA static offset/register prep; Android RE / runtime behavior analysis; cheat / Smali trace) (source: wiki/sources/descriptions/SeeFlowerX__frida-smali-trace.md) Android seccomp-backed SVC/syscall tracing via [[frida-seccomp]] (Abbbbb; Frida JS + Python orchestration; seccomp trap handling; SVC capture with stack traces and register args/returns; multi-process logging; linker symbol inspection + Frida CModule redirect/replay; mobile RE / game-security syscall visibility) (source: wiki/sources/descriptions/Abbbbbi__Frida-Seccomp.md) Agent-driven mobile RE skill set [[mobile-re-skill]] packages decision-tree workflows plus composable Frida JS modules (Java→JNI→native→libc→syscall/SVC layers) and a six-phase anti-detection pipeline for root/Frida/SO-load/crash hardening on authorized Android assessments. (source: wiki/sources/descriptions/index-login__MobileRE-Skill.md) Browser IDE [[frida-ide]] (MrOplus; FastAPI Frida backend + React/Monaco; device/process management, spawn/attach, one-click `frida-server`, APK pull + apktool/[[jadx]], SSL pinning/root/trace/crypto snippets, Claude Code hook extraction, codeshare import) consolidates script editing and APK triage for Android game-security workflows. (source: wiki/sources/descriptions/MrOplus__frida-ide.md) VS Code workbench [[vscode-frida]] (ChiChou; unofficial extension; target selection, script dispatch, REPL, device logs, iOS/Android sessions; TypeScript + Python; `frida-tools` integration) runs Frida workflows inside the editor beside [[frida-ide]]. (source: wiki/sources/descriptions/ChiChou__vscode-frida.md) Web dashboard [[grapefruit]] (ChiChou; TypeScript; Frida-powered iOS/Android runtime exploration; method/crypto hooks, filesystem/SQLite, logs/crash reports, keychain/keystore, traffic capture, Java/ObjC introspection, environment manipulation) complements [[frida-ide]] and [[vscode-frida]] for mobile pentest workflows. (source: wiki/sources/descriptions/ChiChou__grapefruit.md) iOS IPA decrypt/dump CLI [[bagbak]] (ChiChou; Node.js/TypeScript; Frida runtime-decryption agent; extensions and embedded frameworks; USB/remote jailbroken devices; deprecated; `bagbak@5` requires Frida 17) acquires decrypted IPAs for iOS binary analysis. (source: wiki/sources/descriptions/ChiChou__bagbak.md) Flask dashboard [[mast-orchestrator]] (GliTcHZzZ67; ADB device discovery, root verification, one-click arch-matched `frida-server` deploy, whitelisted SSL pinning/root/crypto hooks, GitHub Raw/Codeshare script fetch, live browser hook output, token-auth API) automates the same rooted-Android Frida assessment lane for authorized pentesters. (source: wiki/sources/descriptions/GliTcHZzZ67__mast-orchestrator.md) Multi-device terminal orchestrator [[moabille]] (jafarm189; Python TUI; simultaneous Android/iOS; dual-pane file transfer; scrcpy mirror; automated Frida + Objection; ADB/iproxy/ioscpy) complements web dashboards for desktop mobile pentest workflows. (source: wiki/sources/descriptions/jafarm189__MOABile.md) Root-detection behavior tracing via [[root-detection-low-level]] (3v1lC0d3; Frida JS; `java.io.File`/`Runtime.exec` hooks; keyword path filters; Java stack traces; malware/AC root-check RE). (source: wiki/sources/descriptions/3v1lC0d3__Root_Detection_Low_level.md) End-to-end protected Supercell title automation such as [[hayday-bot]] (AshrafMorningstar; Python + Frida JS + TypeScript anti-telemetry + native C++; in-memory Hay Day crop automation via guest ARM64 `libg.so` hooks on LDPlayer 9; Promon SHIELD gadget bypass, Quago telemetry block, emulator/root fingerprint spoof; `libg.so`/JNI RE utilities; cheat / Frida) illustrates the full mobile AC-evasion + function-call automation stack. (source: wiki/sources/descriptions/AshrafMorningstar__hayday-bot.md) - **Java/ART hooks** — [[canyie-pine]] (canyie; ART runtime Java method hooking; inline hooks + method replacement; Xposed-compatible before/after API; Android 7.0+; no root; Android RE / app modification) (source: wiki/sources/descriptions/canyie__pine.md); [[yahfa]] (PAGalaxyLab; ART method hooking; Java + native backup-and-hook APIs; static/virtual/JNI/framework method examples; reusable library + demo/plugin modules; Android runtime instrumentation / security research / dynamic behavior modification) (source: wiki/sources/descriptions/PAGalaxyLab__YAHFA.md); Block **JVMTI** attach tooling [[stoic]] (debuggable Android API 26+; no APK rewrite; live method hooks, heap inspection, internal API calls via Kotlin/Java plugins; first attach <3s; developer tooling / Android RE) (source: wiki/sources/descriptions/block__stoic.md); hidden **non-SDK API** bypass library [[bypass-hidden-api-restriction]] (WindySha; Java/Kotlin + JNI/CMake native; packaged dependency + startup init; Android 9–12; compatibility testing / security research needing restricted platform interfaces) (source: wiki/sources/descriptions/WindySha__bypassHiddenApiRestriction.md); pure-Java alternative [[android-hidden-api-bypass]] (LSPosed; HiddenApiBypass + LSPass; invoke restricted methods/constructors, read hidden fields, manage exemption prefixes; no native code; modern Android dependency packaging; advanced instrumentation / compatibility / security research) (source: wiki/sources/descriptions/LSPosed__AndroidHiddenApiBypass.md); game-oriented LSPosed/LSPatch module template [[lsposed-universal-template]] (Jordan231111; libxposed API 102; Java hooks + runtime feature registry + movable overlay mod menu; optional ShadowHook/JNI native pattern scan and module lookup; Unity/Unreal/Cocos2d-x/Godot engine detection; anti-cheat satellite process filters; Frida recon + IL2CPP/native workflow docs; Gradle/CMake; authorized mobile game RE) (source: wiki/sources/descriptions/Jordan231111__lsposed-universal-template.md) - **App virtualization** — [[virtual-app]] (ServenScorpion; Android application virtualization framework; cloned apps in isolated container; Java/XML + native C/C++ hooks; Xposed compatibility + SandHook instrumentation; virtual package/process/component management; mobile RE / behavior analysis / multi-instance sandbox) (source: wiki/sources/descriptions/ServenScorpion__VirtualApp.md); host-no-root container VM [[zn-toolbox]] (Chinaapps; Twoyi fork; Rust native core + Kotlin Compose UI; built-in root + LSPosed inside isolated guest; multi-profile containers + Scrcpy remote control; Chinese UI; app analysis / hooking / game modding sandbox on non-rooted phones) (source: wiki/sources/descriptions/Chinaapps__ZN-Toolbox.md); full guest Android VM [[virtualmachine]] (wumingzhinu; VM Studio; native C isolation engine + Kotlin UI; chrooted rootfs, syscall translation, Vulkan/OpenGL ES display; Magisk root toggle, Xposed module loading, Google Play services, camera/sensor/VPN passthrough; hook-friendly sandbox for mobile game/AC behavior testing) (source: wiki/sources/descriptions/wumingzhinu__VirtualMachine.md); historical deprecation notice only for [[blackbox]] (FBlackBox; README-only snapshot; project removed; prior Android virtualization discussions) (source: wiki/sources/descriptions/FBlackBox__BlackBox.md); contrasts with no-root Virtual Space inject via [[android-virtual-inject]] and configurable no-root inject platform [[inject-arm64]] (NepMods; Java/Kotlin + C/C++ native hooks; virtualized app-space payload inject; ARM32/ARM64; newer Android; cheat / Non-root injection) (source: wiki/sources/descriptions/NepMods__InjectARM64.md); complements Xposed module scaffolding via [[xposed-module-kit]]; Inka **AppSealing** disable + decrypted-DEX dump via [[apppealing-new]] (NPC2000; LSPosed + Magisk; Java hooks + native [[dobby]]; root/cheat-detection bypass; mobile AC / packer RE) (source: wiki/sources/descriptions/NPC2000__AppPealing-new.md); defensive AppSealing long-form reversal [[appsealing-reversal]] (ARandomPerson7; Java/native analysis, detection/telemetry/dex-loading, anti-debug/process-kill, hook-based bypass validation; shielding-quality research) (source: wiki/sources/descriptions/ARandomPerson7__Appsealing-Reversal.md) - **Native hooks** — Substrate, [[and64-inline-hook]] (Rprop; lightweight C++ ARM64 inline hooking; instruction patch + branch relocation + trampolines; executable-memory + I-cache flush; mobile RE / instrumentation / game-security experimentation; Android ARMv8 inline hook framework), [[android-inline-hook-arm64]] (GToad; C/C++/ARM64 asm NDK framework; pure inline hooking + trampoline stubs + register-level handler examples; mobile RE / native function interception; Android ARMv8 inline hook framework), [[bwsr]] (BossKoopa; cross-platform C inline hooking for Arm64/Arm64e; iOS, Android, Linux, macOS; low-level patching primitives + multi-platform build paths; portable runtime code interception for security researchers / systems developers), xHook, Dobby (PLT/inline on ARM64 `.so`). (source: wiki/sources/descriptions/Rprop__And64InlineHook.md) (source: wiki/sources/descriptions/GToad__Android_Inline_Hook_ARM64.md) (source: wiki/sources/descriptions/BossKoopa__BWSR.md) Classic Android native DBI via [[adbi]] (WaterlooBridge fork; hijack injector + base hooking library; ARM/Thumb inline entry hooks; NDK C/C++ + sample runtime instruments; mobile RE / runtime analysis / security research). (source: wiki/sources/descriptions/WaterlooBridge__adbi.md) Original crmulliner lineage in the same cheat / DBI / Android RE lane. (source: wiki/sources/descriptions/crmulliner__adbi.md) Per-instruction native tracing via [[qbdi-tracer-android]] (QBDI + [[dobby]]; Android linker SO-load hooks, backtrace capture, memory scan/pattern match; ARM64 cross-compile for Android/iOS; cheat / Android assembly instruction tracing). (source: wiki/sources/descriptions/g2wfw__qbdi-tracer-android.md) Pure-Rust `no_std` AArch64 disassembly/encoding via [[farm64]] (iced-x86-shaped API; zero-heap decode; SVE/SME/SIMD/FP; semantic round-trip encode; wasm/bare-metal friendly; cheat / RE tools) supports embedded ARM64 RE tooling beside hook frameworks. (source: wiki/sources/descriptions/binsnake__fARM64.md) Python static ARM ELF inline-hook tooling such as [[pyasm-patch]] (axhlzy; LIEF + Keystone + Capstone; merge code sections, GOT patch, inline hooks with LDR fixup; Unity IL2CPP `libil2cpp.so`; InitArray hooks + IDA breakpoints; cheat / Android RE) complements runtime inject frameworks when analysts patch `.so` offline. (source: wiki/sources/descriptions/axhlzy__PyAsmPatch.md) ARM64 ELF static GOT hook patchers such as [[elf-got-patcher]] (LeoChen-CoreMind; code-cave shellcode injection, `.init_array` RELA hijack, config-driven ASLR-safe GOT redirection; ARM/ARM64 Android native `.so`; cheat / Android RE) extend that offline patch lane. (source: wiki/sources/descriptions/LeoChen-CoreMind__elf-got-patcher.md) ARM64 shellcode generation framework [[armshellcode]] (IIIImmmyyy; position-independent Android arm64-v8a payloads; Dobby symbol resolution; ELF/proc-maps parsing, syscall wrappers, modular loader + custom linker scripts; exploit / runtime code-injection research; cheat / Android arm arm64-v8a ShellCode Generate) (source: wiki/sources/descriptions/IIIImmmyyy__ArmShellCode.md) Cross-platform runtime memory patching via [[kittymemory]] (MJx0; C++; Android + iOS; memory scan, pointer validation, Keystone assembly patch generation, prebuilt binaries + examples; mobile game RE / controlled in-memory modification; README `[Runtime code patching]`) sits in the same native patch lane beside hook libraries. (source: wiki/sources/descriptions/MJx0__KittyMemory.md) Native mod-loader frameworks such as [[android-mod-loader]] (AndroidModLoader; C++ NDK; inject/manage mods; patching, memory write, function hook, interface-based mod APIs; ARM hooking, dependency handling, IL2CPP utilities, mod templates; cheat / Android Mod Loader) extend that lane for structured runtime game modding. (source: wiki/sources/descriptions/AndroidModLoader__AndroidModLoader.md) - **[[zygisk]]** — Magisk Zygisk modules inject at `preAppSpecialize` / `postAppSpecialize` before `Application.onCreate` (DEX dump, ImGui menus such as [[zygisk-imgui-menu]] (fedes1to; cURL + ImGui; `hook.cpp`; cheat / render-draw) (source: wiki/sources/descriptions/fedes1to__Zygisk-ImGui-Menu.md), Frida gadget via [[zygisk-frida]], early native load, injectors such as [[zygisk-myinjector]]). (source: wiki/sources/descriptions/lico-n__ZygiskFrida.md) (source: wiki/sources/descriptions/jiqiu2022__Zygisk-MyInjector.md) Standalone transparent Zygisk API reimplementation via [[rezygisk]] (PerformanC; C; Magisk/KernelSU/APatch; lighter binaries, module packaging; Zygisk-compatible runtime for module developers). (source: wiki/sources/descriptions/PerformanC__ReZygisk.md) KernelSU-focused standalone Zygisk runtime [[zygisk-on-kernelsu]] (Dr-TSNG; Zygisk API compatibility for KernelSU; can replace Magisk built-in Zygisk; KernelSU/Magisk/APatch platform notes; Zygisk module support outside default Magisk stack). (source: wiki/sources/descriptions/Dr-TSNG__ZygiskOnKernelSU.md) Standalone Zygisk runtime [[zygisk-mod]] (Admirepowered; Kotlin + native; KernelSU/APatch/Magisk; alternative module-loading path when built-in or closed Zygisk stacks are unavailable; process injection and module experimentation for security/modding research). (source: wiki/sources/descriptions/Admirepowered__Zygisk_mod.md) Runtime Zygisk-style injection probes such as [[detect-zygisk]] (apkunpacker; C++/JNI POC; fork child + `ptrace` attach + `PTRACE_GETEVENTMSG`; sample APK/logs across Zygisk forks; mobile AC / root-detection research) study the defender side of that early-inject surface. (source: wiki/sources/descriptions/apkunpacker__DetectZygisk.md) User-space library injection demo [[demo]] (JingMatrix; Kotlin + native C++/CMake; soinfo linked-list checks, virtual memory map inspection, module unload counter monitoring; Zygisk injection detection; mobile AC research). (source: wiki/sources/descriptions/JingMatrix__Demo.md) Zygote-injection game-mod samples such as [[android-mod-games-by-inject-zygote]] (gmh5225; C/C++; kernel-level work, OpenGL, networking; cheat / injection:android) illustrate the same early-process modding surface. (source: wiki/sources/descriptions/gmh5225__Android-ModGamesByInjectZygote.md) Android Studio–built native `.so` injectors such as [[android-dll-injector]] (gmh5225; payload must match target arch; cheat / injection:android) sit in the same attach-and-load lane beside ptrace injectors. (source: wiki/sources/descriptions/gmh5225__Android-DLL-Injector.md) Native injection frameworks such as [[android-super-inject]] (cs1ime; ptrace or Zygote hooking to load custom `.so` into target processes; SELinux-protected system-service injection; some configs without root; cheat / injection:android) extend that lane. (source: wiki/sources/descriptions/cs1ime__AndroidSuperInject.md) - **Managed DI (rooted)** — single ARM64 injector+agent binary, localhost HTTP RPC for script/session control, delayed start after `boot_completed` (avoid zygote contention). Modes: **Attach** (ptrace → dlopen agent), **Spawn** (zygote pause at fork), **Watch-SO** (eBPF dlopen trigger). Stealth tiers: NORMAL (RWX patch), WXSHADOW (shadow pages), RECOMP (minimal inline + recompile). [[ksu-rust-frida]] (Rust KernelSU/Magisk module; Zygote-fork Frida gadget inject before app code; attach/spawn/watch-so + HTTP RPC) targets the same workflow on [[kernelsu]] roots. (source: wiki/sources/descriptions/dreamland-blog__KSU-Rust-Frida.md) [[frida-rs]] (MiChongs; KernelSU module wrapping official `frida-server`; Rust supervisor `frida-ksud` + Material 3 WebUI; multi-ABI; loopback default + token for non-local exposure) supervises stock Frida server lifecycle on [[kernelsu]] roots. (source: wiki/sources/descriptions/MiChongs__Frida-RS.md) [[rust-frida]] implements a Frida-like ARM64 stack (QuickJS, Java/native/stealth hooks, QBDI) designed to pair with [[mkpms]] wxshadow KPM stealth (R^X page-split breakpoint/hook; bypass self-read integrity). (source: wiki/sources/descriptions/kkkbbb__rustFrida.md) (source: wiki/sources/descriptions/kkkbbb__mkpms.md) Operational pattern: lifecycle `start/stop/restart/status`; analysis mode may disable conflicting Zygisk modules, reboot, instrument, then restore. ## Memory manipulation Root paths: `/proc//mem` pread/pwrite, GameGuardian-style editors, ceserver remote debug, custom `/dev` drivers ([[rw-proc-mem33]], [[root-socket-kit]], [[rwmem]], [[android-mem-edit]]). (source: wiki/sources/descriptions/abcz316__rwProcMem33.md) Single-header `/proc/pid/mem` library [[android-memory-tool]] (C/C++; minimal read/write API without ptrace attach; runtime inspection/modification; cheat / RPM; gmh5225) complements that root path. (source: wiki/sources/descriptions/gmh5225__Android-MemoryTool.md) C++ memory toolkit [[c-android-memory-tool]] (Anonym0usWork1221; process search, read/write, offset scan, result management, value freeze via reusable class interface; direct mappings + memory files; cheat-engine style rooted Android workflows; cheat / RPM) extends that root path with structured scan/edit/freeze APIs. (source: wiki/sources/descriptions/Anonym0usWork1221__C-Android-Memory-Tool.md) Java memory utility library [[writemem]] (ExploitTheLoop; range search, offset filter, read/write, periodic freeze across `/proc` maps; map parsing, data conversion, socket server for remote values; rooted Android game memory experimentation/automation; cheat / Android memory) extends that lane as an embeddable Java toolkit. (source: wiki/sources/descriptions/ExploitTheLoop__writemem.md) Lightweight native Android memory scanners such as [[cheap-engine]] (exact/range/changed-unchanged value search, edit, pointer scan; simplified Cheat Engine alternative; gmh5225) sit in the same GameGuardian-style scan/edit lane. (source: wiki/sources/descriptions/gmh5225__cheap-engine.md) Open-source Android memory editing platform [[ace-the-game]] (KuhakuPixel; C++ native scan engine + Kotlin/Java client; process inspection, value edit/freeze, modding/injection tooling; rooted and non-rooted paths; cheat / Game Hacking Tools) extends that lane as a full-stack attach-and-modify workflow. (source: wiki/sources/descriptions/KuhakuPixel__AceTheGame.md) NDK memory tampering toolkit [[mempatch]] (DeNA; C++; address handling, patching, snapshots, range tracking, optional value freeze; platform abstraction + test assets; vulnerability assessment / dev support; cheat / Memory tampering tool) complements that lane for structured Android memory modification workflows. (source: wiki/sources/descriptions/DeNA__mempatch.md) Full-featured CE-style Android memory debugger [[memdbg]] (C++/Lua 5.4; Vulkan+ImGui overlay; root engine; attach, multi-type scan, pointer/structure analysis, HW/SW breakpoints, speedhack, Auto Assemble, trainer tables, disassembly, watchpoints, `.so` injection; single ELF for root/Termux aarch64; cheat / Android Memory Explorer; dbcyyds) extends that lane for deep in-process inspection. (source: wiki/sources/descriptions/dbcyyds__MemDbg.md) Cross-platform remote debugger/scanner [[dynadbg]] (DoranekoSystems; Tauri/React client + Rust/C/C++ backend; memory scanning, watchpoints, code tracing, host-remote workflows; Android/iOS; GUI-driven dynamic analysis for mobile RE / game security) (source: wiki/sources/descriptions/DoranekoSystems__DynaDbg.md) Minimal Kotlin+NDK Android CE clone [[charlyengine]] (Jetpack Compose UI + native `/proc` daemon; scan/rescan/inject/freeze, per-title saved sessions, live terminal stream, Termux shell protocol; cheat / Android Memory Explorer; andoridcharlyroot-debug) extends the same lane with a lightweight UI + daemon workflow. (source: wiki/sources/descriptions/andoridcharlyroot-debug__charlyengine.md) Loaded native `.so` segment dump + ELF reconstruction without `ptrace` via [[memdumper]] (32/64-bit; bypasses basic anti-debug attach checks). (source: wiki/sources/descriptions/kp7742__MemDumper.md) Zygisk-module variant [[zygisk-memdump]] dumps `.so` from process memory via Magisk specialization hooks (C/C++; modding / hooking / memory analysis). (source: wiki/sources/descriptions/hackcatml__zygisk-memdump.md) iOS jailbroken: H5GG, Flex, [[ceserver-ios]] (0xiuks; C/C++ Cheat Engine ceserver port; jailed and jailbroken workflows; memory search/edit, breakpoints, watchpoints, pointer scan, instruction patching; Windows plugins for iOS stack traces and RTTI; desktop CE remote attach; cheat / iOS RE) (source: wiki/sources/descriptions/0xiuks__ceserver-ios.md). Runtime patching libraries such as [[kittymemory-ios]] (memory patch, function hook, pattern-scan APIs; jailbreak-independent iOS runtime code patching; cheat / iOS memory explorer; gmh5225) (source: wiki/sources/descriptions/gmh5225__KittyMemory-IOS.md). TrollStore external memory workstation [[vansonmod]] (vaenshine; ObjC++/C++ Theos; attach without tweak injection; value scan, hex edit, pointer chains, signature scan, JS scripts, IPA archive management; jailbreak adds RVA patch, ARM64 presets, hardware watchpoints; cheat / TrollStore iOS memory editor) (source: wiki/sources/descriptions/vaenshine__VansonMod.md). Frida-backed Cheat Engine servers such as [[frida-ceserver]] expose the ceserver protocol over [[frida]] attach (Android/iOS/desktop; non-rooted Android where attach works) for desktop CE remote scan/write. (source: wiki/sources/descriptions/gmh5225__frida-ceserver.md) ## In-app purchase (IAP) & billing Client-side Play Billing hooks such as [[freedom]] intercept the billing service interface and return fake purchase confirmations—useful for studying IAP verification weaknesses on Android games that trust local billing callbacks without robust server-side receipt checks. (source: wiki/sources/descriptions/gmh5225__freedom.md) Multi-store billing hook module [[com-fuck-iab]] (FKIAB; LSPosed/Xposed; intercepts Google Play, Bazaar, and Myket billing service binders; embeds Frida Gum for compiled TypeScript per-package scripts; restore purchases / bypass local checks; Cheat / Xposed) extends that lane for regional storefronts and scriptable per-title IAP analysis. (source: wiki/sources/descriptions/Xposed-Modules-Repo__com.fuck.iab.md) ## Mobile anti-cheat Layered client checks (root/jailbreak, [[frida]], emulator, integrity, debugger, hooks, VPN/proxy) plus regional stacks (Tencent ACE, NetEase, per-title SDKs)—see [[mobile-anti-cheat]]. Local device-integrity inspector [[duck-detector-refactoring]] (eltavine; Jetpack Compose + modular Kotlin + native C++/assembly probes; root/hook/mount/attestation/virtualization cards with structured findings and method coverage; cheat / Android root) complements open-source multi-check collections. (source: wiki/sources/descriptions/eltavine__Duck-Detector-Refactoring.md) Offline multi-check root/hook inspector [[advanced-root-checker]] (Laert-Android; Java; su/BusyBox/Magisk/KernelSU/APatch/Zygisk/Xposed/LSPosed, root cloaking, SELinux, Frida/debugger/hook anti-tamper, risk score; Android 5.0+; cheat / Android root) sits in the same local assessment lane. (source: wiki/sources/descriptions/Laert-Android__Advanced-Root-Checker.md) Kotlin + NDK integrity library [[device-trust]] (Xheghun; coroutine API + native C++ probes for root, Frida/Xposed hooks, emulator fingerprints, bootloader/SELinux signals; weighted risk score with configurable thresholds or raw signal export; ARM64/ARMv7/x86/x86_64; fraud prevention / auth hardening / game anti-cheat) sits in the same client-side RASP lane. (source: wiki/sources/descriptions/Xheghun__DeviceTrust.md) Android risk-control SDK [[risk-engine]] (WsttXm; JNI native checks + system-property analysis; root, emulator, Frida/Xposed hooks, debugger, VPN, sandbox; device fingerprinting + management platform; fraud prevention / game anti-cheat) sits in the same lane. (source: wiki/sources/descriptions/WsttXm__RiskEngine.md) Cross-platform Python runtime-integrity scorer [[rootsentry]] (cognis-digital; zero-dependency CLI/library; root/jailbreak, emulator, Frida/Xposed hook, and tamper evidence → TRUSTED→CRITICAL posture verdicts; fleet cohort analysis + MITRE ATT&CK for Mobile mapping; Kotlin/Swift reference collectors; RASP / attestation pipelines) complements SDK-embedded RASP in the same lane. (source: wiki/sources/descriptions/cognis-digital__rootsentry.md) Zero-dependency Android RASP library [[rootect]] (SloMR; Kotlin + native C++ syscall probes for Magisk/KernelSU/Frida/Xposed/repack/emulator; scored risk reports + optional Key Attestation; sample app + reference server; Anti Cheat / Detection:Android root) sits beside [[device-trust]] and [[rootsentry]] for on-device integrity telemetry. (source: wiki/sources/descriptions/SloMR__Rootect.md) Open-source Android AC sample [[anticheat-android-cheap-engine]] (gmh5225; C/C++; sample client-side anti-cheat implementation for defensive researchers) complements commercial RASP SDKs in the same lane. (source: wiki/sources/descriptions/gmh5225__Anticheat-android-cheap-engine.md) Open-source Android AC research [[android-anti-cheat]] (codetronik; C/C++; anti-cheat, modding, and hooking on Android; defensive engineers studying open-source AC systems) sits in the same lane. (source: wiki/sources/descriptions/codetronik__AndroidAntiCheat.md) G-Presto native AC reverse-engineering [[g-presto-anti-cheat-reverse-engineered]] (ARandomPerson7; reconstructed C/C++ CPU/emulator checks, Dex handling, encrypted loading; detection-path and anti-tamper structure study) documents a commercial mobile protector for controlled RE. (source: wiki/sources/descriptions/ARandomPerson7__G-Presto-Anti-Cheat-Reverse-Engineered.md) Hybrid Java+JNI anti-cheat engine [[lazenca-s]] (Lazenca; debugging, rooting, speed-hack, binary modification, and VM indicators; mobile game protection experiments / AC detection study; Android Platform) complements those open-source samples. (source: wiki/sources/descriptions/Lazenca__Lazenca-S.md) Android anti-debug / memory-analysis reference [[antidebugandmemorydump]] (Java + native; emulation + debugging; defensive anti-cheat / anti-debug research; gmh5225) sits in the same debugger-resistance and memory-dump study lane. (source: wiki/sources/descriptions/gmh5225__AntiDebugandMemoryDump.md) Java ADB/debug-state checker [[adb-debug-detect-checker]] (fiord; determines whether ADB debugging is available; reference for Android ADB-detection heuristics) complements that lane. (source: wiki/sources/descriptions/fiord__ADB-Debug-Detect-Checker.md) End-to-end attestation relay PoC [[android-hardware-attestation-demo]] (Quarkslab; Frida `KeystoreAttestation.generateAttestedKey` hook + clean-device oracle; genuine TEE/StrongBox chain substitution, no crypto forgery) illustrates how backend hardware Key Attestation can pass on rooted analysis phones when validation binds only to the attestation nonce. (source: wiki/sources/descriptions/quarkslab__android-hardware-attestation-demo.md) Keystore-layer attestation evasion module [[trickystore]] (5ec1cff; modifies key-attestation certificate chains; per-app package/keybox config; leaf vs generated cert modes + security-patch-level spoof; Android 10+/12+; integrity / attestation research) — beakthoven fork is a complete Keystore-trick rewrite in the same cheat / HWID lane. (source: wiki/sources/descriptions/5ec1cff__TrickyStore.md) (source: wiki/sources/descriptions/beakthoven__TrickyStore.md) Defensive attestation inspector [[keyattestation]] (VisionR1 fork; Java/Kotlin generate/parse/verify attestation evidence; certificate-chain save/load; local/remote revocation lists; RSA attestation; Cheat / Bootloader) complements that offensive lane for mobile integrity and bootloader research. (source: wiki/sources/descriptions/VisionR1__KeyAttestation.md) Per-app VPN fingerprint hiding such as [[vpnhide]] (LSPosed `system_server` Binder filters + GKI kretprobe / KernelPatch / Zygisk native ioctl·netlink·`/proc/net` interception; optional localhost ports block for Clash/sing-box probes; no in-process target hooks) sits in the same client-side environment-evasion lane. (source: wiki/sources/descriptions/okhsunrog__vpnhide.md) Client RASP/fingerprint SDKs include [[droidshield]], freeRASP family ([[free-rasp-community]] hub + native Android [[free-rasp-android]]; native iOS [[free-rasp-ios]]; cross-platform [[free-rasp-unity-poc]] / [[free-rasp-reactnative]] / [[free-rasp-capacitor]] / [[free-rasp-cordova]] / [[free-rasp-flutter]] / [[free-rasp-kmp]]; root/jailbreak/Frida/Xposed/repackaging/tamper/integrity; OWASP MASVS V8; source: wiki/sources/descriptions/talsec__Free-RASP-Community.md), open-source Cordova plugin [[cordova-plugin-rootguard]] (Binuka97; Java + Objective-C + JS bridge; Magisk/KernelSU/APatch, Frida/Gum/debugger probes; SAFE/COMPROMISED/UNKNOWN tri-state + optional evidence telemetry; local risk sensor for hybrid apps; source: wiki/sources/descriptions/Binuka97__cordova-plugin-rootguard.md), [[react-native-shieldscan]] (NoobDigital; TS + Kotlin/Swift; root/jailbreak, Frida, debugger, emulator, hook frameworks, developer mode; weighted risk score + screenshot/recording protection; source: wiki/sources/descriptions/NoobDigital__react-native-shieldscan.md), [[react-native-device-risk-signals]] (AfanasievN; TurboModule New Architecture; Kotlin/ObjC++/TS; raw typed probe outcomes for root/jailbreak, emulator, Frida/debugger, VPN/proxy, hardware/locale/app/runtime—no client risk score or vendor upload; host-controlled consent/timeouts; backend fraud-prevention enrichment; source: wiki/sources/descriptions/AfanasievN__react-native-device-risk-signals.md), [[trustdevice-android]] / [[trustdevice-ios]], Android device-lock / HWID research such as [[device-warlock]] (Java/C++; networking, SDK generation, native hooking), and Unity soft-AC [[com-sipvlib-anticheat]]. (source: wiki/sources/descriptions/talsec__Free-RASP-iOS.md) (source: wiki/sources/descriptions/imxiaoc996__DeviceWarLock.md) Overlay/tapjacking defense via [[android-overlay-protection]] (Java; `TYPE_APPLICATION_OVERLAY` detection + `filterTouchesWhenObscured`; callback alerts for sensitive UI flows) sits in the same client-hardening lane opposite offensive overlay PoCs such as [[android-overlay-malware-example]] (foreground-app monitor + pixel-perfect phishing via `WindowManager.addView` or `startActivity`; banking-trojan pattern) and cheat-side floating overlays such as [[android-native-surface]]. (source: wiki/sources/descriptions/geeksonsecurity__android-overlay-protection.md) (source: wiki/sources/descriptions/geeksonsecurity__android-overlay-malware-example.md) Title research such as [[honor-of-kings-re-research]] pairs IL2CPP/`libtersafe` with ACE surfaces; [[dfm-android-unicorn]] emulates ARM64 coordinate-decryption for ACE/`libtersafe` titles via Unicorn. (source: wiki/sources/descriptions/libtersafe__dfm_android_unicorn.md) Google **pairipcore** Android app-protection RE notes via [[pairipcore]] (Solaree; integrity checks, pseudo-VM injection, control-flow obfuscation, dynamic symbol resolution, anti-debug, optional root gates; educational documentation—not a bypass tool) sit in the same commercial native-protection study lane beside AppSealing/DexGuard-class protectors. (source: wiki/sources/descriptions/Solaree__pairipcore.md) Behavioral detection test bench [[laneguard]] (JoshKappler; TypeScript/Next.js; simulated real-money mobile skill-game lane-change driving; attacker ladder + client detector ensemble with ROC calibration; economic constraints as stronger server-side binding than client motor forensics; Anti Cheat / behavioral) complements environment-integrity RASP in the skill-wagering lane. (source: wiki/sources/descriptions/JoshKappler__laneguard.md) ## eBPF tracing User/kernel probes without custom LKM on compatible GKI (BTF, SELinux, lockdown, attach points permitting): [[stackplz]] (SeeFlowerX; eBPF stack tracing + hook analysis; Go + C eBPF; syscall/uprobe/hardware-breakpoint capture on ARM64; args/registers/stacks; filtering, structured output, optional Frida RPC; rooted mobile security / game protection RE; cheat / eBPF-based debugger for Android) (source: wiki/sources/descriptions/SeeFlowerX__stackplz.md), [[edbg]] (Sh11no; eBPF-based lightweight Android ARM64 CLI debugger; GDB-like breakpoints/memory/registers/threads; file+offset breakpoint model for fast startup and anti-debug resistance; rooted mobile RE / game security) (source: wiki/sources/descriptions/Sh11no__eDBG.md), [[edbgserver]] (Satar07; Rust eBPF debugger server for Android and Linux; Arm64/x86_64; breakpoints/stepping/memory/registers/signals/library info; avoids ptrace; low-intrusion RE in monitored environments) (source: wiki/sources/descriptions/Satar07__edbgserver.md), [[tracee]] (Linux/Android runtime security + forensics via eBPF; behavioral detections + container/K8s monitoring; source: wiki/sources/descriptions/aquasecurity__tracee.md); corpus includes [[btrace]] (app behavior), [[peetch]] (TLS/sniff), [[android-ebpf]] (syscall/network/process/perf tracing examples for loading eBPF on Android) (source: wiki/sources/descriptions/gmh5225__android_ebpf.md), [[android-bpf-sys]] (PShocker; minimal `raw_syscalls/sys_enter` tracepoint → BPF map; C++ userland readback via Android bpf libs; syscall monitoring / security analysis; cheat / EBPF) (source: wiki/sources/descriptions/PShocker__Android_bpf_sys.md), and [[ehook]] (ARM64 uprobe hook framework; Go orchestration + C eBPF; on-enter/on-leave handlers with memory R/W wrappers; rooted mobile game RE / runtime tracing; ShinoLeah; cheat / eBPF hook) (source: wiki/sources/descriptions/ShinoLeah__eHook.md), plus in-memory DEX recovery via [[ebpf-dex-dumper]] (LLeavesG; Go; eBPF probes; UID/package filter; method-execution traces; ART DEX dump + auto-repair; rooted ARM64; dynamically loaded bytecode recovery; cheat / DexDumper based eBPF on Android Platform) (source: wiki/sources/descriptions/LLeavesG__eBPFDexDumper.md). Programs/maps/links remain observable; CO-RE improves portability but does not guarantee run-everywhere. ## Network & SSL pinning Traffic capture via mitmproxy / Charles; agent MCP [[android-proxy-mcp]]; all-in-one Android device control via [[lamda]] (FIRERPA; on-device server + Python API; UI automation, WebRTC mirror, one-click MITM, built-in [[frida]], network proxy, MCP agents; root/non-root; virtual-display background automation; frida-tools/tcpdump on-device) consolidates Appium/mitmproxy/frida-server/adb stacks for mobile security testing and protocol RE. (source: wiki/sources/descriptions/firerpa__lamda.md) Self-hosted browser dashboard [[rootraven]] (Kakaxh1; Python/Flask + vanilla JS; ADB, [[frida]], [[jadx]], Burp proxy, SSH, logcat; pre-built SSL pinning, root/jailbreak, anti-debug, biometric, and crypto hooks; manifest/SharedPreferences/deep-link/OWASP MASVS modules; game client and anti-cheat assessment) unifies device management, dynamic analysis, and static recon in one web command center. (source: wiki/sources/descriptions/Kakaxh1__RootRaven.md) Multi-device terminal orchestrator [[moabille]] (jafarm189; Python TUI; simultaneous Android/iOS sessions; dual-pane file transfer; scrcpy mirror; automated Frida + Objection setup; ADB/iproxy/ioscpy; arrow-key navigation; cheat / Frida) consolidates desktop mobile pentest workflows beside browser dashboards. (source: wiki/sources/descriptions/jafarm189__MOABile.md) LLM-native device automation via [[droidrun]] (Python; natural-language Android/iOS control through ADB + accessibility APIs; multi-provider LLM support; scripter agents, custom tools, structured output; `[MCP for Android]`) complements that lane for AI-driven app testing and QA workflows. (source: wiki/sources/descriptions/droidrun__droidrun.md) Upstream [[scrcpy]] (Genymobile; C/Java; USB/TCP Android mirror and control; audio forwarding, recording, virtual display, HID input; high performance, low latency, minimal device footprint; no root; testing, automation, mobile app/game debugging) is the reference implementation. (source: wiki/sources/descriptions/Genymobile__scrcpy.md) Qt GUI scrcpy client [[qtscrcpy]] (barry-ran; C++; MediaCodec mirror over USB/TCP; keyboard/mouse, drag-and-drop, recording, multi-device; no root; desktop display/control for developers and QA) adds low-latency visual Android sessions beside agent stacks. (source: wiki/sources/descriptions/barry-ran__QtScrcpy.md) VPN-based on-device capture such as [[pcapdroid]] (open-source; track/analyze/block per-app connections; PCAP export; HTTP inspect + TLS decrypt; cheat / Android Network Explorer) complements MITM stacks for mobile game wire RE. (source: wiki/sources/descriptions/emanuele-f__PCAPdroid.md) No-root USB Wi-Fi RF tooling such as [[rtl8852au-userspace]] (RTL8852AU userspace driver; libusb monitor mode, channel hopping, 802.11 frame injection; cheat / Android Network Explorer) complements VPN capture for raw wireless RE without root. (source: wiki/sources/descriptions/damanoreshkan-beep__rtl8852au-userspace.md) Frida universal TrustManager hooks for pinning bypass. Static-analysis script generator [[auto-generate-frida-bypass-scripts-for-ssl-pinning-root-detection-on-android-ios]] scans APK/IPA binaries for known SSL stacks (OkHttp, TrustKit, Flutter, gRPC) and root/jailbreak SDKs (RootBeer, Play Integrity, commercial protectors), then emits targeted [[frida]] hooks via a three-layer injection design (Android 12+). (source: wiki/sources/descriptions/infosecrajesh__Auto-generate-Frida-bypass-scripts-for-SSL-pinning-root-detection-on-Android-iOS.md) Universal drop-in script [[ssl-bypass]] (0xCD4; Frida JS; Java and native SSL pinning plus root-detection hooks across popular libraries; no per-app customization; broad Android version support; authorized mobile pentest / RE) offers a one-script alternative beside signature-driven generators. (source: wiki/sources/descriptions/0xCD4__SSL-bypass.md) Certificate user→system modules such as [[move-certificate]] support MITM on rooted devices. ## Kernel drivers & CVE lanes Official AOSP GKI common kernel upstream [[kernel-common]] (aosp-mirror; vendor-shared base; Android patches, Bazel build, Rust toolchain; kernel attack-surface / defense study; `[GKI]`) sits upstream of per-device OEM trees and out-of-tree driver scaffolds. (source: wiki/sources/descriptions/aosp-mirror__kernel_common.md) Custom multi-vendor GKI common 5.10 fork [[android-kernel-gki-common-5-10]] (ExWhyZed9; ABI symbol defs for Samsung/Qualcomm/MediaTek/ASUS/Motorola/OnePlus+; ZenX build script; Redmi Note 11T Pro(+)/POCO X4 GT; GKI-compliant custom kernels across platforms; cheat / Android Kernel Source) complements per-device OEM trees. (source: wiki/sources/descriptions/ExWhyZed9__android_kernel_gki_common_5.10.md) LKM / GKI `vendor_dlkm` patterns for process memory R/W, syscall hook, Binder IPC intercept ([[android-kernel-hacking-toolkit]], [[kasumi]] (Anatdx; ftrace/tracepoint syscall/VFS/procfs hooks + mount/SELinux/file-attribute spoof for root hide; GKI/Linux; source: wiki/sources/descriptions/Anatdx__Kasumi.md), [[kernel-hack]], [[memkernel]] (Poko-Apps; C/C++ kernel + userland; custom-interface process memory R/W; kernel-build integration; cheat / `[RPM]`; source: wiki/sources/descriptions/Poko-Apps__MemKernel.md), [[kernel-driver-hack]] (Jiang-Night; C; Android/Linux device-interface ioctl process memory R/W + module base lookup; kernel module build + userland client; game memory RE / kernel tooling; source: wiki/sources/descriptions/Jiang-Night__Kernel_driver_hack.md), [[compile-android-driver]], [[kernel-build-action]] (GitHub Actions automated kernel build; TypeScript/Python; cheat / Android kernel driver), [[kernel-build-scripts]] (Bash GKI/non-GKI repo sync, patch, defconfig, packaging, release; KernelSU/SUSFS flows; Pixel/OnePlus/Xiaomi; cheat / kernel build scripts; source: wiki/sources/descriptions/TheWildJames__kernel_build_scripts.md), [[oppo-oplus-realme-sm8750]] (Andrea-lyz; automated OPPO/OnePlus/Realme SM8750 + MT6991 kernel builds; OKI/GKI modes, f2fs compatibility patches, KernelSU integration; cheat / Android Kernel Source; source: wiki/sources/descriptions/Andrea-lyz__oppo_oplus_realme_sm8750.md), [[android-kernel-driver-template]] (GKI AArch64 product-kernel scaffold; source: wiki/sources/descriptions/gmh5225__android-kernel-driver-template.md), [[android-drivesignity]] (ARMv8.3 driver signature verification bypass for unofficial/modified LKM load; source: wiki/sources/descriptions/gmh5225__AndroidDriveSignity.md)). Android system-call hook tooling such as [[abyss]] (C/C++; asset pipelines, SDK generation, hooking; cheat / RE tools) sits in the same syscall-hook lane. (source: wiki/sources/descriptions/iofomo__abyss.md) KernelPatch/APatch KPM cross-process memory read via ioctl hook such as [[kpm-memreader]] (`libtersafe`; cheat / Android kernel driver). (source: wiki/sources/descriptions/libtersafe__KPM-MemReader.md) KPM uprobe mass-hook module [[kernel-trace]] (AndroidReverser-Test; C/C++ Linux/Android kernel module; uprobes for simultaneous bulk user-space function hooks; userspace headers for library/offset/metadata config; tracefs output; register/clear probe APIs; dynamic analysis / low-level behavior tracing; cheat / Android kernel driver). (source: wiki/sources/descriptions/AndroidReverser-Test__Kernel-Trace.md) ARM64 LKM driver modules such as [[ovo]] (process R/W, `mmuhack` page-table manipulation, kernel TCP IPC, touch simulation, `peekaboo` stealth access; C++/Rust SDKs; cheat / Android kernel driver). (source: wiki/sources/descriptions/fuqiuluo__ovo.md) [[android-wuwa]] (stealthy process memory via CFI/kprobe bypass at load, software + ARM64 AT page-table walk, `phys_to_virt` R/W, PTE injection bypassing VMA, DMA buffer sharing, IOCTL/socket IPC, module/signal hiding; cheat / Android aarch64 rootkit). (source: wiki/sources/descriptions/fuqiuluo__android-wuwa.md) Integrated kernel + Zygisk RE stack [[integrated-kernel-module]] (Dispa1r; lsdriver LKM + wxshadow W^X shadow-page hooks + rfrida_zygisk Frida agent; PTE-remap memory R/W, HW/PTE/single-step breakpoints, `do_el0_svc` syscall monitor, virtual touch/gyro/GNSS; ptrace-less anonymous-mmap ELF linker; userspace tooling + optional MCP; rooted Android game RE / anti-cheat research). (source: wiki/sources/descriptions/Dispa1r__Integrated_kernel_module.md) Lightweight ARM64 kernel inline-hook scaffold [[android-kernel-inline-hook-framework]] (ChwnWang0; full instruction relocation for B/BL/ADRP/LDR literal/CBZ/TBZ; 64-bit trampoline long jumps; automatic WP/memory-permission bypass; Android kernel RE / driver and syscall hook research). (source: wiki/sources/descriptions/ChwnWang0__Android-kernel-inline-hook-framework.md) ARM64 Linux **silent syscall hook** PoC [[arm64-silent-syscall-hook]] (3intermute; C; patches kernel SVC/exception-handler path instead of `sys_call_table`; manual function splicing + trampoline-style patching; selected syscall redirect with reduced table-tamper indicators; stealth rootkit + hook-detection research; README ARM64 Patching exception handler). (source: wiki/sources/descriptions/3intermute__arm64_silent_syscall_hook.md) Structured Android kernel exploitation guide/lab [[android-kernel-exploitation]] (kernel debug setup, ARM/AArch64 layout, UAF/heap overflow/race classes, KASLR/PAN/PXN bypass, full exploit chains; cheat / Android Kernel Exploitation) complements CVE catalogs [[android-vuln]] and PoC/exploit list [[android-vuln-poc-exp]] (documentation/list; cheat / Android Kernel CVE) and runnable C PoC collection [[android-kernel-cve-pocs]] (ScottyBauer; crafted ioctl, race conditions, vendor/Wi-Fi driver memory manipulation; reproduce bugs, validate mitigations, study exploit primitives; cheat / List) (source: wiki/sources/descriptions/cloudfuzz__android-kernel-exploitation.md) (source: wiki/sources/descriptions/jiayy__android_vuln_poc-exp.md) (source: wiki/sources/descriptions/ScottyBauer__Android_Kernel_CVE_POCs.md); io_uring-focused Android kernel privesc PoC [[bad-io-uring]] (Markakd; C/NDK; per-device exploit variants; boot-image unpack + kernel-symbol extraction helpers; Pixel 6 root; cheat / Root for Pixel 6) (source: wiki/sources/descriptions/Markakd__bad_io_uring.md); Mali GPU kernel exploit chain [[pixel-gpu-exploit]] (0x36; C/C++; integer-overflow logic flaws + info leak → arbitrary kernel memory R/W; SELinux disablement + root; Pixel 7/8 Pro Android 14; GPU driver attack-surface study; cheat / Root for Pixel7/8 Pro with Android 14) (source: wiki/sources/descriptions/0x36__Pixel_GPU_Exploit.md); application PoCs [[cve-2024-0044]], [[android-privilege-cve-2022-20452-leakvalue]] (LazyValue deserialization LPE; unprivileged app → system-level access; Java/Kotlin PoC; gmh5225; source: wiki/sources/descriptions/gmh5225__Android-privilege-CVE-2022-20452-LeakValue.md); kernel/TEE PoCs [[cve-2019-2215]] (Binder epoll UAF temporary root; Pixel 2/XL; Sep 2019 firmware) (source: wiki/sources/descriptions/jsirichai__CVE-2019-2215.md), hands-on reproduction lab [[android-kernel-exploitation-lab]] (0xbinder; environment setup, kernel source prep/patching, emulator guidance, privilege-escalation analysis, GDB/syzkaller/AFL++ fuzzing; mobile kernel security training; cheat / CVE-2019-2215) (source: wiki/sources/descriptions/0xbinder__android-kernel-exploitation-lab.md), [[cve-2020-0041]] (Binder transaction-buffer bounds-check bug; Pixel 3; Feb 2020 firmware; pending-node reallocation → kernel R/W + root; Blue Frost Security full chain adds Chrome renderer sandbox escape via Binder IPC) (source: wiki/sources/descriptions/j4nn__CVE-2020-0041.md) (source: wiki/sources/descriptions/bluefrostsecurity__CVE-2020-0041.md), [[cve-2021-1961]], ARM cache side-channel toolkit [[armageddon]] (IAIK; C + Python; Prime+Probe, Flush+Reload, Evict+Reload, Flush+Flush, cache template attacks on ARM mobile; mobile privacy, crypto side channels, TrustZone observation; README Cache attacks on ARM) (source: wiki/sources/descriptions/IAIK__armageddon.md), [[cve-2026-43499-popsicle]], packaged Pixel installer [[root-my-pixel]], multi-vendor one-tap [[ghostlock-app]], vendor-native exploit toolkit [[ghostlock-oneplus]] (JoinChang; futex PI UAF; locked-bootloader OnePlus/OPPO/realme/Xiaomi + KernelSU; source: wiki/sources/descriptions/JoinChang__ghostlock-oneplus.md), [[cve-2026-64560-analysis]] (posix-cpu-timers non-leader `exec()` race UAF trigger PoC; Linux x86_64 + Android arm64; patch verification / KASAN; source: wiki/sources/descriptions/villager1314__CVE-2026-64560-Analysis.md), [[poc-cve-2025-38352]] (posix-cpu-timers thread-group-exit vs timer-fire race UAF; LTS 6.12.33 full preemption; Sep 2025 Android Security Bulletin ITW; source: wiki/sources/descriptions/farazsth98__poc-CVE-2025-38352.md), Dirty Pipe [[dirtypiperoot]] / [[dirtypipe-android]]. ## HarmonyOS / OpenHarmony HarmonyOS NEXT apps compile ArkTS/ArkJS to `.abc` ArkCompiler bytecode—a separate RE surface from standard APK/DEX workflows. [[arkdecompiler]] parses that bytecode, reconstructs control flow, and emits readable JavaScript/TypeScript for mobile security researchers; [[dayu]] offers another Open/HarmonyOS `.abc` parser/decompiler (author disclaims maintenance/correctness guarantees). OpenHarmony differs from Android in IPC/capability model—do not assume apktool/jadx workflows transfer directly. (source: wiki/sources/descriptions/jd-opensource__arkdecompiler.md) (source: wiki/sources/descriptions/hx1997__dayu.md) Android virtual-container / Linux VE probes such as [[conbeerlib]] (cgroup / fs / env / hardware; Docker/LXC/K8s/WSL) sit in the same emulator·container detection lane. (source: wiki/sources/descriptions/su-vikas__conbeerlib.md) Classic Android emulator artifact checks via [[anti-emulator]] (QEMU props / build fingerprints / sensors / FS signatures; per-heuristic Java API) sit in the same Anti-Emulator lane. (source: wiki/sources/descriptions/strazzere__anti-emulator.md) Multi-heuristic Android emulator detection via [[android-emulator-detection]] (gmh5225 Java/Kotlin scoring library—QEMU/Genymotion/BlueStacks props, sensors, telephony, MAC/IMEI; reveny Java/C++ plugin fork) sits beside those VE probes. (source: wiki/sources/descriptions/gmh5225__Android-Emulator-Detection.md) (source: wiki/sources/descriptions/reveny__Android-Emulator-Detection.md) Genymotion virtual-device Linux kernel source [[genymotion-kernel]] (Genymobile; full kernel tree with Android configs and Genymotion patches; emulator development and kernel-level behavior in virtualized Android; cheat / Android Emulator) complements that stack beside upstream [[scrcpy]]. (source: wiki/sources/descriptions/Genymobile__genymotion-kernel.md) Stealth Frida server repackaging (string/symbol/artifact hex-replace; rooted and rootless iOS installs) via [[fridare]] sits in the same anti-Frida / instrumentation lane. (source: wiki/sources/descriptions/suifei__fridare.md) Boot-auto-start Florida anti-detection `frida-server` modules such as [[florida-zygisk]] (Ylarod source patches; random port; KernelSU toggle) sit in that same persistent instrumentation lane. (source: wiki/sources/descriptions/thelok1s__florida-zygisk.md) Class/function-trace and return-value-modify helpers such as [[frida-android-hook]] (iOS-oriented scripts noted) sit in the cheat / Frida instrumentation lane. (source: wiki/sources/descriptions/noobpk__frida-android-hook.md) ## Key sub-areas **Android:** [[apktool]]/[[jadx]] (Java APK decode/rebuild + smali; `[Apk]`) (source: wiki/sources/descriptions/iBotPeaches__Apktool.md) (DEX→Java decompiler CLI+GUI for APK/DEX/AAR) (source: wiki/sources/descriptions/skylot__jadx.md) (agent-facing apktool via [[apktool-mcp-server]] MCP tools; headless JADX MCP via [[delamain]] for AI-driven APK/DEX/AAB decompile, xrefs, and Frida-hook generation) (source: wiki/sources/descriptions/zinja-coder__apktool-mcp-server.md) (source: wiki/sources/descriptions/xjoker__delamain.md); Rust multi-format static analysis [[glass]] (ARM64/x86-64; ELF/Mach-O/DEX/PE; disasm/CFG/xrefs/pattern match/patch; built-in MCP — `disasm`, `search`, `cfg-of`, `dex-callers`, `bin-search`, `insn-search` on APK/IPA/AArch64 via `glass mcp`) (source: wiki/sources/descriptions/azw413__Glass.md); offline mobile RE suite [[sako-restudio]] (Capstone disasm + IR decompiler + ptrace debugger + call graph + SakoScript plugins; APK/ELF/PE/DEX; Jetpack Compose; SQLite projects; optional local/OpenAI-compatible AI explain) (source: wiki/sources/descriptions/Maxamedxasa__SakoREStudio.md); DEX↔JAR bridge via [[dex2jar]] (d2j-baksmali / APK sign / DEX manip; feed JD-GUI/CFR) (source: wiki/sources/descriptions/pxb1988__dex2jar.md); native C++ DEX bytecode generation via [[dexbuilder]] (LSPosed; AOSP-derived dexmaker alternative; LSPosed runtime integration; Android framework/tooling developers; source: wiki/sources/descriptions/LSPosed__DexBuilder.md); smali/Dalvik bytecode editor via [[dalvikus]] (Android RE tool / smali editor; ethical research) (source: wiki/sources/descriptions/loerting__dalvikus.md); Python Dalvik VM emulator via [[dalivm]] (DEX opcode execution, class loading, Android API mocking, static analysis, string decryption, Multi-DEX; no Android runtime required) (source: wiki/sources/descriptions/fatalSec__DaliVM.md); Java Android deobfuscation framework via [[simplify]] (CalebFenton; virtual Dalvik execution + optimizer passes — constant propagation, dead-code removal, reflection cleanup; demo materials; obfuscated APK/DEX analysis; `[Java]`) (source: wiki/sources/descriptions/CalebFenton__simplify.md); standalone C Fast APK/DEX/JAR Java decompiler [[garlic]] (PE/ELF/Mach-O/DEX/APK + ARM; CLI) (source: wiki/sources/descriptions/neocanable__garlic.md); radare2 Garlic DEX/Dalvik decompiler plugin [[r2garlic]] (DEX/APK + ELF/PE/Mach-O via r2 IO; in-memory streams) (source: wiki/sources/descriptions/radareorg__r2garlic.md); Java bytecode shrink/optimize/obfuscate via [[proguard]] (Guardsquare; remove unused classes/fields/methods; bytecode optimize + symbol rename; Gradle/CLI; software protection / deployment hardening; `[Java]`) (source: wiki/sources/descriptions/Guardsquare__proguard.md); ProGuard/R8 name recovery + HTML hierarchy reports via [[obfu-de-scate]] (Python APK deobf) (source: wiki/sources/descriptions/user1342__Obfu-DE-Scate.md); high-performance native-assisted DEX search/deobfuscation via [[dexkit-android]] (LuckyPray; C++ NDK + JNI/Kotlin; class/method discovery by strings, relations, opcode patterns; Gradle/prefab/CMake embed; hook-point discovery + obfuscated code navigation; cheat / dex deobfuscator) (source: wiki/sources/descriptions/LuckyPray__DexKit-Android.md); Android packed-sample unpack tooling via [[android-unpacker]] (malware RE; Sample Unpacker; handle samples carefully) (source: wiki/sources/descriptions/strazzere__android-unpacker.md); automated static DEX/resource unpacker via [[kavanoz]] (Python; Bangcle/Ijiami/Qihoo 360+ packer ID + decrypt; banker malware focus; Sample Unpacker) (source: wiki/sources/descriptions/eybisi__kavanoz.md); APK/DEX packer·obfuscator·anti-analysis fingerprinting via [[apkid]] (YARA; “PEiD for Android”; ProGuard/DexGuard/Bangcle/Ijiami+) (source: wiki/sources/descriptions/rednaga__APKiD.md); DEX bytecode-to-native method protection via [[nmmp]] (Nativ Method Map Protector; JNI bridges; blocks standard DEX decompile recovery) (source: wiki/sources/descriptions/maoabc__nmmp.md); ELF import hide/retrieve via [[android-native-import-hide]] (C++; hooking/debugging; Anti Cheat → Compile Time) (source: wiki/sources/descriptions/reveny__Android-Native-Import-Hide.md); Android library remap-hide via [[android-library-remap-hide]] (two-lib remap; cheat / hide research) (source: wiki/sources/descriptions/reveny__Android-Library-Remap-Hide.md); APK signature-crack study via [[asctool]] (Kotlin; Some Tricks / Android) (source: wiki/sources/descriptions/stars-one__ASCTool.md); APK v1/v2/v3 signature copy/extract/patch via [[apksigcopier]] (Python; Signing Block transplant / compare APKs) (source: wiki/sources/descriptions/obfusk__apksigcopier.md); standalone APK signing via [[apksigner]] (Android Apk Sign Tool; stable basic re-sign after mod/repack) (source: wiki/sources/descriptions/jixiaoyong__ApkSigner.md), Magisk ([[magisk]] systemless root / `su` daemon / modules / MagiskHide) (source: wiki/sources/descriptions/topjohnwu__Magisk.md) / [[kernelsu]] (kernel su; Kotlin/Rust kernel-level root) (source: wiki/sources/descriptions/tiann__KernelSU.md) / APatch (e.g. [[cheese]] Magisk install on Quest 3/3S via Adreno CVE-2025-21479, no boot-partition rewrite; [[move-certificate]] user→system CA module for Android 7–15; Pixel-prop disguise module [[easypixel]] (source: wiki/sources/descriptions/the-dise__EasyPixel.md); Magisk+LSPosed device-identity profile collection [[spoofing-collection]] (boot-time prop rewrite + `Build` API hooks; Samsung/OnePlus/Pixel/Xiaomi targets; Play Integrity / attestation research) (source: wiki/sources/descriptions/mrx7014__SpoofingCollection.md); `/dev/input` touch/key record-replay Magisk module [[event-replay]] (timed replay + command socket + gesture traces) (source: wiki/sources/descriptions/qq703048949__event_replay.md); native ARM64 uinput virtual-touch injector [[android-virtual-touch]] (NDK; tap/swipe/multi-touch via `/dev/input/event*`; rooted; game automation / input testing) (source: wiki/sources/descriptions/muchenspace__android_virtualTouch.md); C/C++ Android touch-input driver development such as [[android-touch]] (triggerbot & aimbot / input-path research) (source: wiki/sources/descriptions/gmh5225__android_touch.md); Magisk/Zygisk virtual camera module [[android-virtualcam-manager]] (ArtHook Camera1 NV21/surface injection; no LSPosed; camera spoofing / liveness AC research) (source: wiki/sources/descriptions/smithluke874__Android-VirtualCam-Manager.md); boot-image modification via [[magiskboot]] (C/C++ Boot Image Modification Tool) (source: wiki/sources/descriptions/svoboda18__magiskboot.md), GitHub Actions Linux builds via [[magiskboot-linux]] (source: wiki/sources/descriptions/gmh5225__magiskboot-linux.md), NDK-on-Linux builds via [[magiskboot-ndk-on-linux]], and POSIX standalone builds via [[magiskboot-build]] (scripts/patches from Magisk tree; no full Magisk suite) (source: wiki/sources/descriptions/ookiineko__magiskboot_build.md), and Gradle-based [[android-boot-image-editor]] (Kotlin/Java; boot/recovery/vendor_boot; AVB signing, LZ4/XZ/GZIP, EROFS/sparse; boot formats v0–4; JDK 11+; cfig) (source: wiki/sources/descriptions/cfig__Android_boot_image_editor.md) for unpack/repack; Qualcomm AVB bypass PoC [[qualcomm-avb-exploit-poc]] (atlas4381; crafted partition data skips boot-image verification → persistent code execution on Qualcomm devices; cheat / Unlocking qualcomm bootloader) (source: wiki/sources/descriptions/atlas4381__qualcomm_avb_exploit_poc.md); Ghidra Hexagon QDSP6 SLEIGH extension [[ghidra-hexagon-sleigh]] (CUB3D; Qualcomm firmware/binary disasm/decomp; QMI handler discovery, QuRT task ID, RTTI annotation, Q6Zip/DLPager decompression via emulation; mobile security RE) (source: wiki/sources/descriptions/CUB3D__ghidra-hexagon-sleigh.md); Android OTA `payload.bin` partition dumps via [[payload-dumper]] (Python) (source: wiki/sources/descriptions/vm03__payload_dumper.md) and high-perf Go [[payload-dumper-go]] (parallel xz decompress / checksum / zip-with-payload) (source: wiki/sources/descriptions/ssut__payload-dumper-go.md); Magisk artifact / mount-namespace detection via archived [[magiskdetector]] AppZygote+AIDL isolated checks; multi-check Android root/Xposed/Frida/VPN/dev-options collection via [[detection]] (Java; FS/process/property/native probes) (source: wiki/sources/descriptions/rushiranpise__detection.md); Kotlin native Android root detector [[android-native-root-detector]] (Detection:Android root) (source: wiki/sources/descriptions/reveny__Android-Native-Root-Detector.md); hardware-backed key attestation / bootloader integrity via [[keyattestation]] Keymaster/KeyMint AIDL cert checks; Samsung TrustZone S-Keymaster TA key-extraction research via [[keybuster]] (`libkeymaster_helper`; CVE-2021-25444/25490; USENIX Security'22) (source: wiki/sources/descriptions/shakevsky__keybuster.md); native Android freeRASP sample [[free-rasp-android]] (Kotlin; `TalsecConfig` + `ThreatListener`; root/Magisk/Frida/emulator/tamper/integrity/screen-capture/location·WiFi-spoof; `TalsecSecurity-Community` Maven) (source: wiki/sources/descriptions/talsec__Free-RASP-Android.md); client-side Android RASP SDK [[droidshield]] for root/debugger/Frida-Xposed/emulator/tamper signals with polymorphic per-build check ordering; Unity freeRASP plugin [[free-rasp-unity-poc]] (Talsec; C# → Android/iOS bridges; root/jailbreak/Frida/emulator/integrity/debug/screen-capture callbacks) (source: wiki/sources/descriptions/talsec__Free-RASP-Unity-POC.md); Unity UPM soft-AC package [[com-sipvlib-anticheat]] (server-verified GameTime; IntegrityChecker debugger/root/jailbreak/emulator/clock-drift) (source: wiki/sources/descriptions/phajmvawnsix__com.sipvlib.anticheat.md); React Native freeRASP plugin [[free-rasp-reactnative]] (Talsec; TS/JS + Kotlin/Swift; Magisk/KernelSU/Frida/tamper/integrity/`useFreeRasp`) (source: wiki/sources/descriptions/talsec__Free-RASP-ReactNative.md); Capacitor freeRASP sibling [[free-rasp-capacitor]] (Talsec; TS + Kotlin/Swift bridge; root/jailbreak/Frida/Shadow/tamper/rebinding/screen-capture) (source: wiki/sources/descriptions/talsec__Free-RASP-Capacitor.md); Cordova freeRASP sibling [[free-rasp-cordova]] (Talsec; TS + Kotlin/Swift; root/jailbreak/Frida/tamper/integrity/bootloader/automation/screen-capture/time·location-spoof/insecure Wi-Fi) (source: wiki/sources/descriptions/talsec__Free-RASP-Cordova.md); React Native Nitro RASP SDK [[rs-native-kit-security]] (Kotlin/Swift + TS; JSI via Nitro Modules; root/jailbreak/Frida/Xposed/Magisk/emulator/integrity/VPN/proxy/screen-capture + device risk engine) (source: wiki/sources/descriptions/rajssinde__rs-native-kit-security.md); device-fingerprinting / integrity SDK [[trustdevice-android]] (TrustDecision Kotlin/Java; unique IDs + risk signals; ProGuard; `[Android]` lane) (source: wiki/sources/descriptions/trustdecision__trustdevice-android.md)) (source: wiki/sources/descriptions/zhuowei__cheese.md) (source: wiki/sources/descriptions/ys1231__MoveCertificate.md) (source: wiki/sources/descriptions/xiaoxindada__magiskboot_ndk_on_linux.md) (source: wiki/sources/descriptions/vvb2060__MagiskDetector.md) (source: wiki/sources/descriptions/vvb2060__KeyAttestation.md) (source: wiki/sources/descriptions/venkata-ram__DroidShield.md), upstream OrangeFox Recovery build tree [[android-bootable-recovery-ofrp]] (Ctapchuk; full OFRP codebase; recovery UI, partition management, flashing; C/C++, build scripts, XML, Java; firmware developers / power users; cheat / OrangeFox Recovery) (source: wiki/sources/descriptions/Ctapchuk__android_bootable_recovery-OFRP.md), custom recovery device trees such as [[ofrp-device-xiaomi-mondrian]] (OFRP/TWRP for Redmi K60 Pro / Snapdragon 8 Gen 2) (source: wiki/sources/descriptions/ymdzq__OFRP-device_xiaomi_mondrian.md) and Pixel Experience Plus ROM device trees such as [[device-xiaomi-mondrian]] (board/audio/display/codec/vendor overlays for Redmi K60 / POCO F5 Pro on Qualcomm Waipio / SM8475) (source: wiki/sources/descriptions/flakeforever__device_xiaomi_mondrian.md), curated Android ROM reference lists such as [[android-rom-list]] (documentation/list; cheat / Android ROM) (source: wiki/sources/descriptions/musabcel__android_rom_list.md), PixelOS official device support metadata such as [[official-devices]] (PixelOS-AOSP; Markdown/JSON device lists, API data, changelog notes, release templates; authoritative support matrix; cheat / PixelOS device trees) (source: wiki/sources/descriptions/PixelOS-AOSP__official_devices.md), PixelOS source-tree manifest repo [[manifest]] (XML repo manifests + snippets; `repo init`/sync and ROM build docs; revision-locked upstream project selection; cheat / Android ROM) (source: wiki/sources/descriptions/PixelOS-AOSP__manifest.md); cross-platform Pixel flashing GUI [[pixel-flasher]] (bootloader unlock, factory/OTA flash, Magisk/KernelSU/APatch root, boot-image patch, backup; self-contained executable; cheat / Android ROM tool for Pixel) (source: wiki/sources/descriptions/badabing2005__PixelFlasher.md), on-device custom-ROM flash/backup/migration app [[rom-shifter]] (ShivamXD6; Kotlin/Jetpack Compose + custom shell backend; flash wizard, partition backup/restore, batch APK install, app/device data migration, debloat/systemize utilities; Magisk/KernelSU/APatch root; cheat / Android) (source: wiki/sources/descriptions/ShivamXD6__ROM-Shifter.md), Xiaomi HyperOS bootloader account-binding bypass PoC [[xiaomi-hyperos-bootloader-bypass]] (MlgmXyysd; PHP automation + Docker/shell helpers + ADB libraries; reproducible unlock workflow; mobile bootloader restriction research; cheat / bootloader bypass) (source: wiki/sources/descriptions/MlgmXyysd__Xiaomi-HyperOS-BootLoader-Bypass.md), one-tap temporary Pixel root via [[root-my-pixel]] (alex193a; Kotlin + JNI; NebuSec IonStack CVE-2026-43499 + ReSukiSU/KernelSU late-load; Shizuku-elevated shell; Pixel 7–10; exploit logging; cheat / Android root) (source: wiki/sources/descriptions/alex193a__Root-My-Pixel.md), multi-vendor one-tap root via [[ghostlock-app]] (YuKongA; NDK pselect race CVE-2026-43499; Rust boot/OTA offset extractor; per-kernel JSON tables; KernelSU/ReSukiSU; cheat / Android root) (source: wiki/sources/descriptions/YuKongA__ghostlock-app.md), Xiaomi K70e (duchamp) one-tap root via [[duchamp-root]] (Colorful-glassblock; IonStack CVE-2026-43499; LD_PRELOAD `preload.so`; embedded KernelSU `ksud`; Android 16 offsets; cheat / Android root) (source: wiki/sources/descriptions/Colorful-glassblock__duchamp-root.md), Samsung Galaxy one-tap KernelSU installer [[root-my-galaxy]] (BuSung-dev; Kotlin/Compose + NDK; firmware-profile matching by kernel release/build/SDK/ABI/page size; external exploit + KernelSU feed; KASLR timing probes; CVE-2026-43499; cheat / Android root) (source: wiki/sources/descriptions/BuSung-dev__Root-My-Galaxy.md), DIY Android kernel explorers such as [[op7t]] (source: wiki/sources/descriptions/yhnu__op7t.md), ARM64 kernel emulators such as [[rnidbg]] (Rust rewrite of unidbg; kernel-level work, graphics, animation; cheat / Android kernel explorer) (source: wiki/sources/descriptions/fuqiuluo__rnidbg.md), ARM64 LKM driver modules such as [[ovo]] (process R/W, `mmuhack`, kernel TCP IPC, touch simulation; C++/Rust SDKs; cheat / Android kernel driver) (source: wiki/sources/descriptions/fuqiuluo__ovo.md), out-of-tree Android kernel driver build/ABI automation such as [[compile-android-driver]] (kade / Kadeflow; GKI and non-GKI) (source: wiki/sources/descriptions/systemnb__compile_android_driver.md), aarch64 LKM research toolkits such as [[android-kernel-hacking-toolkit]] (filecopy / hideproc / propedit / syscall_hijack; CFI bypass, kprobes, mmuhack) (source: wiki/sources/descriptions/systemnb__android-kernel-hacking-toolkit.md), Android/Linux game-memory LKMs such as [[kernel-hack]] (kernel R/W / process management / verification; Kconfig build) (source: wiki/sources/descriptions/rogxo__kernel_hack.md), Xiaomi Pad 6 (pipa) kernel sources such as [[android-kernel-xiaomi-pipa]] (source: wiki/sources/descriptions/utziacre__android_kernel_xiaomi_pipa.md), OnePlus 8/8T/8Pro/(9R?) SM8250 kernel sources such as [[android-kernel-oneplus-sm8250]] (source: wiki/sources/descriptions/utziacre__android_kernel_oneplus_sm8250.md), POCO F3/F4 (SM8250) custom Xiaomi kernel sources such as [[kernel-xiaomi-sm8250]] (Danda420; AnyKernel3 flashable packaging, device defconfigs, GitLab CI, GKI ABI for Qualcomm; Snapdragon 870/888; source: wiki/sources/descriptions/Danda420__kernel_xiaomi_sm8250.md), OnePlus Nord SM7250 KernelSU-integrated kernel sources such as [[android-kernel-oneplus-sm7250-wksu]] (source: wiki/sources/descriptions/psavarmattas__android_kernel_oneplus_sm7250-WKSU.md), Redmi Note 8/8T (ginkgo) KernelSU kernel sources such as [[pc-ginkgo]] (source: wiki/sources/descriptions/mylove90__pc_ginkgo.md), Redmi Note 10 Pro (sweet) KernelSU kernel sources such as [[android-kernel-xiaomi-sweet]] (Qualcomm; source: wiki/sources/descriptions/fiqri19102002__android_kernel_xiaomi_sweet.md), Motorola Dubai (Moto Edge 30) SM7325 Snapdragon 778G GKI kernel sources such as [[android-kernel-motorola-dubai]] (GKI ABI, Qualcomm drivers, Motorola device tree; source: wiki/sources/descriptions/SM7325-AE__android_kernel_motorola_dubai.md), Redmi K60 / POCO F5 Pro (mondrian) SM8475 Snapdragon 8+ Gen 1 GKI kernel sources such as [[android-kernel-xiaomi-sm8475]] (GKI ABI, Qualcomm Waipio platform, device configs; Pixel Experience Plus; source: wiki/sources/descriptions/LowTension__android_kernel_xiaomi_sm8475.md), POCO X7 Pro ROOTURK GKI 6.6 kernel sources such as [[rooturk-kernel]] (RooTurkk; Android 15 GKI 6.6; AnyKernel3 + Bazel; built-in KernelSU Next + SuSFS root hiding + game-oriented idle tuning; mobile kernel RE / kernel-integrity bypass research; source: wiki/sources/descriptions/RooTurkk__ROOTURK-Kernel.md), Pixel 4 XL (coral) msm-floral KernelSU kernel sources such as [[kernelsu-pixel4xl]] (su injection / SELinux / syscall hook; source: wiki/sources/descriptions/msnx__KernelSU-Pixel4XL.md), GrapheneOS hardened Pixel 4/4XL MSM kernel sources such as [[kernel-msm-coral]] (Qualcomm MSM tree; hardened configs + Android security patches; hardened-kernel study on Snapdragon; source: wiki/sources/descriptions/GrapheneOS-Archive__kernel_msm-coral.md), legacy Linux 4.4 KernelSU backport such as [[kernelsu-4.4]] (gmh5225; su / SELinux / APK signature verification; Google GCC 4.9; cheat / Android root) (source: wiki/sources/descriptions/gmh5225__KernelSU-4.4.md), Samsung Exynos 5433 kernel sources such as [[android-kernel-samsung-universal5433]] (Note 4 / Alpha; Linux 3.10) (source: wiki/sources/descriptions/universal5433__android_kernel_samsung_universal5433.md), Samsung SM7150 kernel sources such as [[android-kernel-samsung-sm7150]] (source: wiki/sources/descriptions/pascua28__android_kernel_samsung_sm7150.md), Samsung Galaxy A14 5G (A146B / a14x) KernelSU kernel sources such as [[a146b-ksu]] (gmh5225; modified kernel tree + KernelSU patches for custom ROM builders; cheat / Android Kernel Source) (source: wiki/sources/descriptions/gmh5225__A146B-KSU.md), Huawei MT6761 (Helio P22) kernel sources such as [[android-kernel-huawei-mt6761]] (source: wiki/sources/descriptions/huawei-mediatek-devs__android_kernel_huawei_mt6761.md), Huawei hi6250 KernelSU kernel sources such as [[android-kernel-huawei-hi6250-8-exp]] (source: wiki/sources/descriptions/gmh5225__android_kernel_huawei_hi6250-8_Exp.md), Huawei Nova 2 ARM64 KernelSU vendor-kernel port such as [[kernel-su-huawei-nova2]] (CoolestEnoch; full kernel tree + device tree + KernelSU framework patches; Android kernel configs; vendor BSP integration study; cheat / KernelSU for huawei; source: wiki/sources/descriptions/CoolestEnoch__kernel-su-huawei-nova2.md), Android Kernel CVE reference lists such as [[android-vuln]] (documentation/list for cheat / Android Kernel CVE research) (source: wiki/sources/descriptions/tangsilian__android-vuln.md), Android Application CVE PoCs such as [[cve-2024-0044]] (Android 12/13; crafted payload → unauthorized app data-directory access) (source: wiki/sources/descriptions/nahid0x1__CVE-2024-0044.md), Android Kernel CVE PoCs such as [[cve-2026-43499-popsicle]] (Xiaomi 17 Pro Max / popsicle LPE; LD_PRELOAD; uid 0 + SELinux off on 6.12 kernels) (source: wiki/sources/descriptions/x-spy__CVE-2026-43499-popsicle.md), Qualcomm QSEECOM/TrustZone kernel R/W via [[cve-2021-1961]] (Widevine DRM TA ION buffer abuse; Pixel 3 / blueline; `/proc/version` + SELinux off) (source: wiki/sources/descriptions/tamirzb__CVE-2021-1961.md), Dirty Pipe (CVE-2022-0847) Pixel 6 temporary-root apps such as [[dirtypiperoot]] (vuln check + native C; pipe page-cache overwrite of read-only files) (source: wiki/sources/descriptions/tiann__DirtyPipeRoot.md), permanent Magisk v24.3 install via multi-stage [[dirtypipe-android]] (module-loader corruption + ARM64 shellcode; SELinux/cred patch) (source: wiki/sources/descriptions/polygraphene__DirtyPipe-Android.md), syscall dispatcher patching PoCs such as [[dpatch]] (writable syscall-table copy + dispatcher jump) (source: wiki/sources/descriptions/xmmword__dpatch.md), Android app perf profiling demos such as [[simpleperf-demo]] (simpleperf / Perf) (source: wiki/sources/descriptions/yabinc__simpleperf_demo.md), Zygisk modules such as [[zygisk-dump-dex]] (`libdexfile.so` hook → DEX dump; Android 14/15) (source: wiki/sources/descriptions/ri-char__zygisk-dump-dex.md), eBPF-based in-memory DEX dumpers such as [[ebpf-dex-dumper]] (LLeavesG; Go; ART activity capture + auto-repair; UID/package filter; method traces; rooted ARM64; low-intrusion alternative to Zygisk hooks; cheat / DexDumper based eBPF on Android Platform) (source: wiki/sources/descriptions/LLeavesG__eBPFDexDumper.md), and in-dev Zygisk ImGui mod menus such as [[zygisk-imgui-mod-menu]] (cheat / render-draw) (source: wiki/sources/descriptions/reveny__Zygisk-ImGui-Mod-Menu.md) and hobby sample [[zygisk-imgui-modmenu]] (ImGui with Zygisk; cheat / render-draw) (source: wiki/sources/descriptions/gmh5225__zygisk-imgui-modmenu.md); Unity-focused Zygisk ImGui templates such as [[imgui-zygisk-unity]] (OpenGL ES context share + touch translation; Unity render-pipeline hook; cheat / render-draw) (source: wiki/sources/descriptions/lbertitoyt__ImGUI-Zygisk-Unity.md); LSPosed/Xposed GPS location-spoof modules such as [[locusmimic]] (Kotlin/Jetpack Compose; map picker / saved locations / per-app·system·mock-provider modes; HideMockLocation forks; adb broadcast automation; location-based AC evaluation) (source: wiki/sources/descriptions/wchunlin1006__LocusMimic.md) plus standalone mock-location apps such as [[anywhere]] (cxOrz; Java; OpenStreetMap picker + overlay joystick walk/run/cycle + location history; bundled LSPosed module hides mock-provider flags; Cheat / Xposed) (source: wiki/sources/descriptions/cxOrz__AnyWhere.md); profile-based identifier/environment anti-detect via [[hidemyandroid]] (Android ID, GAID, IMEI, root/LSPosed/VPN hiding; per-profile configs; Cheat / Xposed) (source: wiki/sources/descriptions/Xposed-Modules-Repo__com.wowsoftware.hidemyandroid.md); Xposed/LSPosed module scaffolds such as [[xposed-module-kit]] (HookTemplate/MethodHook/PackageHook helpers; Python `.class`/JAR scanner → MethodHook stubs; root-detection bypass example; Xposed API 82–93) (source: wiki/sources/descriptions/mabbcoll13__xposed-module-kit.md); no-root Virtual Space injectors such as [[android-virtual-inject]] (inject through Virtual Space; not for AC-protected games; cheat / injection:android) (source: wiki/sources/descriptions/reveny__Android-Virtual-Inject.md); ptrace-based Android injectors such as [[android-ptrace-injector]] (C/C++; cheat / injection:android) (source: wiki/sources/descriptions/reveny__Android-Ptrace-Injector.md); historical LD_PRELOAD injectors such as [[android-ld-preload-injector]] (any version/arch; dead / not working; cheat / injection:android) (source: wiki/sources/descriptions/reveny__Android-LD-Preload-Injector.md); Rust emulation-centered Android inject research such as [[yaui]] (cheat / injection:android) (source: wiki/sources/descriptions/ohchase__yaui.md); ptrace-free Rust injectors such as [[linjector-rs]] (modding-focused code injection without ptrace; cheat / injection:android) (source: wiki/sources/descriptions/erfur__linjector-rs.md), ART/syscall hooks, eBPF tracers (process-aware sniff / OpenSSL TLS key extract / decrypt-proxy such as [[peetch]]; PCAPng + Scapy; IPv4 TLS 1.2) (source: wiki/sources/descriptions/quarkslab__peetch.md), Android app dynamic behavior tracking via eBPF such as [[btrace]] (C/C++/Go; cheat / RE tools) (source: wiki/sources/descriptions/null-luo__btrace.md), kernel drivers, ACE/AppSealing-class protectors; Honor of Kings (sgame) RE workspace [[honor-of-kings-re-research]] (Frida/IL2CPP/`libtersafe` + KernelPatch acepeek KPMs vs Tencent ACE) (source: wiki/sources/descriptions/wwweeeqqu__honor-of-kings-RE-research.md); agent-facing HTTP/HTTPS capture via [[android-proxy-mcp]] (mitmdump + SQLite + NL query) (source: wiki/sources/descriptions/zhizhuodemao__android_proxy_mcp.md); Android ImGui native-app samples such as [[android-native-app-imgui]] (Java/C++; cheat / render-draw) (source: wiki/sources/descriptions/vrolife__android_native_app_imgui.md); Rust ARM64 cdylib ImGui mod-menu scaffolds such as [[android-imgui-menu]] (EGL/Vulkan render-chain hooks + inline hooking + constructor auto-load; cheat / render-draw) (source: wiki/sources/descriptions/horoni__android_imgui_menu.md); native GLES ImGui mod-menu templates such as [[imgui-native-modmenu]] (C++; OpenGL ES + touch/JNI hooks; `[Imgui Menu for Android]`) (source: wiki/sources/descriptions/s4m33r89__Imgui-Native-ModMenu.md); title-specific PUBG Mobile bypass + ImGui samples such as [[bypass-pubg-mobile-imgui]] (C/C++; hooking / memory analysis; cheat / game:pubgm) (source: wiki/sources/descriptions/mut1234__BYPASS-PUBG-MOBILE-IMGUI.md); native Android NDK PUBG RE/manipulation toolkits such as [[china-pubg]] (Super-Cssdiv; inline hooks, ptrace injectors, memory tooling, ImGui rendering, offset/map/patch helpers; cheat architecture / mobile AC detection-surface research; cheat / game:pubgm) (source: wiki/sources/descriptions/Super-Cssdiv__ChinaPubg.md); version-pinned PUBG Mobile cheat source packages such as [[pubgm-shitty-source]] (Mood-Coding; C++; aim/entity/overlay modules; bundled driver artifacts + privileged-memory helper scripts; version-specific external workflow; cheat / game:pubgm) (source: wiki/sources/descriptions/Mood-Coding__pubgm_shitty_source.md); internal Call of Duty Mobile mod-menu samples such as [[codm-esp-aimbot-mod-menu]] (injectable native library + overlay ESP / aimbot; gmh5225; cheat / game:codm) (source: wiki/sources/descriptions/gmh5225__CODM-ESP-Aimbot-Mod-Menu.md); pak extractors such as [[pubg-mobile-pak-extract]] (pre–1.1.0; post-update encryption unsupported; asset RE) (source: wiki/sources/descriptions/halloweeks__pubg-mobile-pak-extract.md); versioned UE4 SDK + offset dumps such as [[pubgm-sdk-and-offsets]] (PUBG Mobile 1.5 / 1.9; ARM32 class hierarchy; `[Offset]`) (source: wiki/sources/descriptions/gmh5225__pubgm_sdk_and_offsets.md); Android memory hacking walkthroughs such as [[pubg-mobile-memory-hacking-examples]] (entity/player/weapon reads; scan + value modify; cheat / game:pubgm) (source: wiki/sources/descriptions/gmh5225__pubg_mobile_memory_hacking_examples.md); Gameloop emulator PC cheat samples such as [[pubg-mobile-memory-hacking]] (atulkunal999; C++; kernel-driver RPM + DirectX ESP/aimbot; bundled UE SDK headers; DSEFix driver load + process-enumeration window attach; cheat / game:pubgm [Emulator]) extend that lane when mobile titles run on Tencent GameLoop with Windows kernel memory access. (source: wiki/sources/descriptions/atulkunal999__pubg_mobile_memory_hacking.md); historical PUBG Mobile 1.6 decompiled native archives such as [[pubgm1.6-deadgame]] (`libtersafe.so` + `libUE4.so` from a large APK unpack; offline ACE/UE4 symbol reference for dead builds) (source: wiki/sources/descriptions/gmh5225__PUBGM1.6-DeadGame.md); client patcher/modding samples such as [[pubgm-pubgpatcher]] (gmh5225; C/C++/Java; networking / asset pipelines / modding; cheat / game:pubgm) (source: wiki/sources/descriptions/gmh5225__PUBGM-PUBGPatcher.md); PUBG-centered OpenGL hooking/modding samples such as [[pubg]] (C/C++; cheat / game:pubgm; gmh5225) (source: wiki/sources/descriptions/gmh5225__pubg.md); Android Unity ImGui mod-menu templates such as [[imgui-unity]] (OpenGL ES + IL2CPP/Mono hooks; cheat / render-draw) (source: wiki/sources/descriptions/springmusk026__Imgui-Unity.md) and layout-enhanced sibling [[imgui-unity-with-layout]] (tabs / categorized options / save-load; C++) (source: wiki/sources/descriptions/springmusk026__ImGui-Unity-With-Layout.md); gmh5225 [[imgui-unity-android]] (Dear ImGui via OpenGL ES in Unity's Android render pipeline; mod menus + debug UI; cheat / render-draw) (source: wiki/sources/descriptions/gmh5225__ImGui-Unity-Android.md); gmh5225 [[android-mod-menu-imgui]] (native C++ ImGui mod-menu template; OpenGL ES + touch + JNI game hooks; configurable layouts/toggles; README `[Imgui For Unity]`) (source: wiki/sources/descriptions/gmh5225__Android-Mod-Menu-ImGui.md); external out-of-process ImGui overlay samples such as [[external-imgui-android]] (gmh5225; OpenGL ES 3.0; SurfaceView overlay service + NDK JNI; Unreal Engine memory tools + math structs; README `[External Imgui Menu for Android]`) (source: wiki/sources/descriptions/gmh5225__External-ImGui-Android.md); native C/C++ compositor-surface overlays such as [[android-native-surface]] (gmh5225 + SsageParuders forks; `ANativeWindow`/SurfaceFlinger transparent overlay without app-level permissions; Android 10–14 AOSP-compatible surface draw + screen recording; cheat menus / ESP; README `[Android Native Overlay]`) (source: wiki/sources/descriptions/gmh5225__Android_Native_Surface.md) (source: wiki/sources/descriptions/SsageParuders__Android_Native_Surface.md); Java `WindowManager` floating-menu + semi-JNI native hook templates such as [[android-modmenu-semijni]] (toggles/sliders ↔ C++ patch/hook callbacks) (source: wiki/sources/descriptions/springmusk026__Android-ModMenu-SemiJni.md); Kotlin floating-view overlay + native C++/JNI IL2CPP menu templates such as [[android-mod-menu-kotlin]] (Kotlin UI ↔ memory patch / function hooks) (source: wiki/sources/descriptions/springmusk026__Android-Mod-Menu-Kotlin.md); widely used Java + native C/C++ floating mod-menu framework such as [[android-mod-menu]] (LGLTeam; IL2CPP + native games; KittyMemory, MSHook, And64InlineHook, string obfuscation; ARMv7/ARM64; Base64 embedded assets; runtime toggle / hook prototyping; cheat / Floating mod menu for Android) (source: wiki/sources/descriptions/LGLTeam__Android-Mod-Menu.md); Android cheat templates such as [[android-cheat-template]] span Unity/OpenGL/hooking scaffolds (sanqiuu; cheat / game engine explorer:Unity) (source: wiki/sources/descriptions/sanqiuu__AndroidCheatTemplate.md) and kernel-level OpenGL + memory-analysis forks for Sausage Man (gmh5225; cheat / game:sausage man) (source: wiki/sources/descriptions/gmh5225__AndroidCheatTemplate.md); NDK Unity cheat scaffolds such as [[cheat-unity-games]] (SsageParuders; C/C++ VSCode/NDK; Il2CppResolver + [[dobby]] hooks; shared-object build scripts; Android injection / native-layer Unity study; cheat / game engine explorer:Unity) (source: wiki/sources/descriptions/SsageParuders__CheatUnityGames.md); C++20 Android IL2CPP name-based modding libraries such as [[bnm-android]] (ByNameModding; class/method/field runtime access + patching + hook-framework integration; supported Unity versions; reusable mod foundation; cheat / `[Modding il2cpp games]`) sit in the same native Unity mod lane. (source: wiki/sources/descriptions/ByNameModding__BNM-Android.md); Android Unity IL2CPP ImGui menu frameworks such as [[polarimgui]] (Polarmods; C++ native + Android Studio build tooling; native `.so` packaging for target APK architectures; in-game UI rendering; mobile mod-menu / cheat UI prototyping; README Imgui On Android) (source: wiki/sources/descriptions/Polarmods__PolarImGui.md); Octowolve [[unity-imgui-android]] (C++ native template; [[dobby]] hooks on `eglSwapBuffers` + Unity input injection; touch/key overlay; IDA+SigMaker tutorial for `nativeInjectEvent` in libunity; mod-menu prototyping / mobile Unity RE; README `[Imgui For Unity]`) (source: wiki/sources/descriptions/Octowolve__Unity-ImGUI-Android.md); OpenGL ES chams samples such as [[android-opengl-es-chams]] (gmh5225; chams-focused GLES draw/shader hooks with annotated headers; cheat / render-draw [Chams]) sit in the same mobile render-draw lane. (source: wiki/sources/descriptions/gmh5225__Android-OpenGL-ES-Chams.md); Android Terminal Emulator lane via [[termux-app]] (Termux; no-root Linux env / pkg+apt / proot sysroot) (source: wiki/sources/descriptions/termux__termux-app.md), experimental Termux fork [[neotty]] (full Linux system usage; cheat / Android Terminal Emulator) (source: wiki/sources/descriptions/gmh5225__neotty.md), modern Termux-oriented terminal [[neoterm]] (NeoTerrm; Java/Kotlin + Android XML UI; mobile shell usability, docs, release distribution; portable CLI for mobile security practitioners) (source: wiki/sources/descriptions/NeoTerrm__NeoTerm.md), and [[android-terminal-emulator]] (jackpal; VT-100 codes; built-in Android shell) (source: wiki/sources/descriptions/jackpal__Android-Terminal-Emulator.md); on-device ADB/root/shell utility [[ashellyou]] (DP-Hridayan; Kotlin + Jetpack Compose + Material 3; embedded ADB library; Shizuku/root local execution, OTG/wireless remote devices, push/pull explorer, logcat, bookmarks; PC-free debugging workflow; cheat / Android Terminal) (source: wiki/sources/descriptions/DP-Hridayan__aShellYou.md); rooted Android File Explorer [[xfiles]] (prebuilt APKs in Releases; Cheat Android File Explorer) (source: wiki/sources/descriptions/pgp__XFiles.md); full-featured Kotlin/Compose on-device manager [[file-explorer]] (SysAdminDoc; libsu/Shizuku for `Android/data`·`obb`, dual-pane, APK analyzer, hex editor, Magisk/KernelSU/APatch module browser, AES vaults, SMB/SFTP/WebDAV; Cheat Android File Explorer) (source: wiki/sources/descriptions/SysAdminDoc__FileExplorer.md); lightweight Kotlin/Java Material 3 baseline [[raival-file-explorer]] (Raival-e; core file ops, multi-tab navigation, task handling, integrated code editor, deep content search; Gradle Android project for extension/study; Cheat Android File Explorer) (source: wiki/sources/descriptions/Raival-e__File-Explorer.md); full-featured package manager and viewer [[app-manager]] (MuntashirAkon; Java/Android + native; component inspection, permission/app-op control, backup/restore, logcat, tracker scanning, APK install/edit/sign, root/ADB ops; deep app auditing and RE-oriented device admin; Cheat Android File Explorer) (source: wiki/sources/descriptions/MuntashirAkon__AppManager.md); open-source file explorer [[butler]] (d4rken-org; Kotlin/Compose; root/Shizuku/ADB/shell; app manager, APK export, regex search; Cheat Android File Explorer) (source: wiki/sources/descriptions/d4rken-org__butler.md); Windows ADB file manager [[adb-file-manager]] (gmh5225; C#/.NET dual-pane Explorer UI; faster than MTP; Cheat Android File Explorer) (source: wiki/sources/descriptions/gmh5225__AdbFileManager.md); Chinese File Explorer guide [[note]] (`Guide-zh` docs; Cheat Android File Explorer) (source: wiki/sources/descriptions/nzcv__note.md). **iOS:** native freeRASP SDK [[free-rasp-ios]] (TalsecRuntime XCFramework; Swift SPM/Xcode; jailbreak/Frida/hook/simulator/tamper/signature/Secure Enclave/passcode/device-binding/VPN/screenshot/screen-recording/time-spoof callbacks via `TalsecConfig` + `Talsec.start`) (source: wiki/sources/descriptions/talsec__Free-RASP-iOS.md); jailbreak tooling, runtime ObjC class-dump via [[dynadump]] (DerekSelander; dlopen-assisted; Apple binaries/shared cache; dylib/class/interface dump + demangled signatures; macOS/iOS RE) (source: wiki/sources/descriptions/DerekSelander__dynadump.md), Logos hooks, sideloading / AltStore for non-jailbreak paths; non-jailbreak IPA patch tooling such as [[ipapatch]] (C/C++/ObjC; Patch iOS Apps without Jailbreak) (source: wiki/sources/descriptions/paradiseduo__IPAPatch.md); iOS file-exploit call-recording notification suppression via [[disable-call-recording-bookrestore]] (Nirad-Maharaj; bl_sbx; replace system audio assets to mute call-recording alert tones; README claims non-jailbreak file-exploit path while description notes jailbroken context; cheat / iOS file explorer) (source: wiki/sources/descriptions/Nirad-Maharaj__Disable-Call-Recording-BookRestore-.md); pure-Go sideload tweak injector [[xkvm-ios-injector]] (CLI/TUI; dylib/`.deb` injection, rootful/rootless/roothide package conversion, App Store IPA decrypt, ElleKit/Substrate/Orion embedding, Mach-O repack + ad-hoc sign; cheat / iOS sideload) (source: wiki/sources/descriptions/xscope0__xkvm-ios-injector.md); Python CLI repackager/signing utility [[ios-packager]] (addrianyy; certificate metadata parse, Info.plist/entitlements update, provisioning profile fetch, codesign; template-driven packaging; repeated resign/deploy during mobile app/game security testing) (source: wiki/sources/descriptions/addrianyy__ios_packager.md); perma-signed jailed IPA installer [[trollstore]] (CoreTrust/AMFI bypass; arbitrary entitlements; no re-sign after reboot) (source: wiki/sources/descriptions/opa334__TrollStore.md); jailbreak-detection bypass tooling such as [[shadow]] (modern iOS jailbreaks; per-app success not guaranteed; cheat / iOS jailbreak) (source: wiki/sources/descriptions/jjolano__shadow.md) and [[ihide]] (Kc57; per-app jailbreak-hiding tweak; MobileSubstrate/ObjC hooks; Settings-panel enable/disable; common jailbreak-detection bypass; mobile app/game security testing; cheat / iOS jailbreak) (source: wiki/sources/descriptions/Kc57__iHide.md); non-jailbreak network location spoofing via [[ios-location-spoofer]] (MITM Apple map lookup responses; WiFi BSSID + cell-tower coord patch; Surge/Shadowrocket/Loon/Stash/QX modules; motion-state spoof; location-picker web UI; JavaScript) (source: wiki/sources/descriptions/mekos2772__ios-location-spoofer.md) and sibling [[wloc]] (Yu9191; gs-loc WLOC protobuf MITM patch; online picker + Shortcuts; GCJ-02→WGS84; indoor/WiFi positioning only; no jailbreak) (source: wiki/sources/descriptions/Yu9191__wloc.md); Swift identifier obfuscation via [[swiftshield]] (SourceKit-driven type/method rename; conversion map for crash logs; vs RE / jailbreak tweaks) (source: wiki/sources/descriptions/rockbruno__swiftshield.md); Swift string crypter [[swift-string-obfuscator]] (AC Compile Time / String Crypter; two-file split also noted) (source: wiki/sources/descriptions/pykaso__Swift-String-Obfuscator.md); Android/iOS native LLVM obfuscator [[dprotect]] (CFF / insn sub / string encrypt / opaque predicates / MBA IR passes) (source: wiki/sources/descriptions/open-obfuscator__dProtect.md); historical kernel `tfp0` exploit study via [[oob-entry]] (iOS 3.0–10.3.4; C/C++; cheat / iOS jailbreak) (source: wiki/sources/descriptions/staturnzz__oob_entry.md); runtime dylib inject via [[opainject]] (`task_for_pid` / Mach remote thread → `dlopen`; jailbreak + tfp0; Cheat / Injection:IOS) (source: wiki/sources/descriptions/opa334__opainject.md); synthetic touch injection via [[ptfaketouch]] (gmh5225; private IOKit or UIKit internals; programmatic touch into the iOS event pipeline for UI automation and game bot input; cheat / iOS input simulation) (source: wiki/sources/descriptions/gmh5225__PTFakeTouch.md); title-specific iOS cheat sources such as [[last-island-of-survival-ioscheat-source]] (gmh5225; Last Island of Survival / Last Day Rules; Objective-C runtime manipulation for gameplay mods; cheat / iOS game hacking) (source: wiki/sources/descriptions/gmh5225__LastIslandOfSurvival-iOSCheat-Source.md); semi-untethered rootless jailbreak [[dopamine]] (iOS 15.0–15.4.1; kernel R/W + PAC/PPL/AMFI; Sileo/procursus under `/var/jb`; Swift/ObjC) (source: wiki/sources/descriptions/opa334__Dopamine.md); iOS 15/16 RootHide Dopamine 2 fork [[dopamine2-roothide]] (C/C++/ObjC; kernel-level / plugins; cheat / iOS jailbreak) (source: wiki/sources/descriptions/roothide__Dopamine2-roothide.md); iOS 15 untethered jailbreak [[ios-jailbreak-fugu15]] (gmh5225; Fugu15 kernel exploit chain → root, codesign bypass, full-privilege code execution; cheat / iOS jailbreak) (source: wiki/sources/descriptions/gmh5225__IOS-jailbreak--Fugu15.md); iOS 16 jailbreak tool [[def1nit3lyn0tajailbreaktool]] (KpwnZ; iOS 16.0–16.6.1; kernel exploitation + trustcache build paths; Objective-C/C native; post-exploitation workflows; cheat / iOS jailbreak) (source: wiki/sources/descriptions/KpwnZ__Def1nit3lyN0tAJa1lbr3akTool.md); checkm8 developer jailbreak [[palera1n]] (iOS 15+ A8–A11; rootful/rootless; AMFI/codesigning off + Sileo bootstrap) (source: wiki/sources/descriptions/palera1n__palera1n.md); userland exploit chains such as [[lightsaber]] (iOS 18.4–18.6.2 JS injection into SpringBoard / other processes; derived from DarkSword) (source: wiki/sources/descriptions/zeroxjf__lightsaber.md); WIP DarkSword kernel-exploit study via [[lara]] (iOS 17.1.1–26.0.1; font overwrite / app bypass / file manager / DirtyZero2; C/C++/Swift) (source: wiki/sources/descriptions/rooootdev__lara.md); XNU kernel KRW exploit [[dirty-zero]] (CVE-2025-24203; zero-day/recent XNU bug → reliable kernel R/W; jailbreak-chain component; cheat / iOS jailbreak) (source: wiki/sources/descriptions/jailbreakdotparty__dirtyZero.md); DarkSword kernel r/w playground [[darksword-kexploit-fun]] (iOS/iPadOS 17.0–26.0.1 except A19/M5; sandbox escape / SSV root FS overwrite / PAC·TaskROP / AMFI·sandbox·APFS; ObjC/C) (source: wiki/sources/descriptions/wh1te4ever__darksword-kexploit-fun.md); iOS 26–27 sandbox-escape PoC [[bad-query]] (Xcode; app/daemon/plug-in/App Group/system-container path access; developer PoC for container isolation research; not a practical jailbreak) (source: wiki/sources/descriptions/forcequitOS__bad_query.md); XNU 1-day exploit practice [[xnu-1day-practice]] (Mach IPC voucher / IOSurface / IOAccelerator PoCs + KRW helpers; C/ObjC; CVE-2019–2025 lab) (source: wiki/sources/descriptions/wh1te4ever__xnu_1day_practice.md); QEMU ARM64 full-system iOS/XNU emulation via [[xnu-qemu-arm64]] (Aleph Security fork; launchd/bash, unsigned binaries, SSH tunnel, optional KVM; iOS machine models for kernel/runtime lab study; cheat / xnu) (source: wiki/sources/descriptions/alephsecurity__xnu-qemu-arm64.md); Apple Silicon QEMU fork [[qemu-apple-silicon]] (ChefKissInc; full QEMU tree + platform mods; hardware-accelerated ARM virtualization on macOS; iOS device emulation; iOS security RE / app testing and analysis; IOS Emulator) (source: wiki/sources/descriptions/ChefKissInc__qemu-apple-silicon.md); Apple Silicon macOS virtualized iPhone CLI [[vphone-cli]] (Lakr233; Swift + Python firmware patchers for iBoot/kernel/TXM, jailbreak patch sets, ramdisk builders, CFW; Virtualization.framework PCC research VM; SIP/AMFI disabled, DFU/restore/ramdisk; iOS security RE / virtualized iOS lab) (source: wiki/sources/descriptions/Lakr233__vphone-cli.md); native macOS SwiftUI VM manager [[vphone-ws]] (zqxwce; wraps [[vphone-cli]]; browse/create/boot/clone/export/delete iOS research VMs; creation wizard + host readiness checks; IOS Emulator) (source: wiki/sources/descriptions/zqxwce__vphone-ws.md); one-script pre-jailbroken vphone bundle [[vphone-aio]] (34306; shell script + compressed archive; automates download/merge/extract of [[vphone-cli]] on macOS; SIP disabled + AMFI bypassed; full bootstrap; ready jailbroken iOS lab for app analysis/testing; cheat / IOS Emulator) (source: wiki/sources/descriptions/34306__vphone-aio.md); iOS 27 beta CFW jailbreak toolkit [[usbliter8-fun]] (34306; usbliter8 SecureROM exploit → PWN DFU; RP2350/Pico 2 + Lightning; Python CFW build/restore + DeviceTree/kernel patches + SSH ramdisk + userland binary patch; USB Restricted Mode / sandbox / AMFI trust-cache / SEP workarounds; bootstrap + package manager; A12/A13 iPhone 11 Pro only; destructive — breaks SEP/WiFi/baseband/Apple services; cheat / iOS jailbreak) (source: wiki/sources/descriptions/34306__usbliter8-fun.md); Swift jailed-device system UI customization app [[mdc0]] (34306; iOS 15.0–18.3.2; exploit path writes normally read-only system files for dock/blur/lockscreen tweaks + respring helper; CVE-2025-24203; cheat / iOS jailbreak) (source: wiki/sources/descriptions/34306__mdc0.md); QEMU Darwin VM [[darwin-vm]] (jprx; boot iOS/macOS to root shell; virtual iPhone 12–17 and M1–M5 Macs; custom qemu-sptm fork; SPTM/TXM/MIE kernel debug; GDB/LLDB attach; IOS Emulator) (source: wiki/sources/descriptions/jprx__darwin-vm.md); iOS 14.0–14.4.2 kernel R/W exploit app [[humptylock]] (Coruna Pendulum PE extension; lockf / Mach OOL-port spray / NECP kalloc grooming / pipe corruption → stable KRW; PAC unsign + kernel-base discovery; iPhone 6s–11 Pro; C/ObjC Xcode) (source: wiki/sources/descriptions/wh1te4ever__HumptyLock.md); checkra1n-era XNU kernel function hooking via [[xnuspy]] (A8–A11 checkm8 devices; no 4K support; cheat / iOS memory explorer) (source: wiki/sources/descriptions/jsherman212__xnuspy.md); XNU kernel file-descriptor exploit framework [[kfd]] (felix-pb; C; chains XNU bugs → stable kernel R/W; iOS 15/16; jailbreak/sandbox-escape research; cheat / iOS jailbreak) (source: wiki/sources/descriptions/felix-pb__kfd.md); iOS kernel memory explorer [[kfd-explorer]] (Python/Swift; kernel-level memory browse/analysis; cheat / iOS memory explorer) (source: wiki/sources/descriptions/hackcatml__kfd-explorer.md); XNU `kern_aio.c` AIO+kevent UAF PoC [[cve-2026-xnu-aio-kevent-uaf]] (crazymind90; sandbox app without entitlements; AIO completes/frees before kevent registration → kernel panic/double-free; iOS 26.2, patched 26.3; cheat / iOS jailbreak kernel research) (source: wiki/sources/descriptions/crazymind90__CVE-2026-XNU-AIO-KEVENT-UAF.md); jailbroken iOS userland REST memory server [[memory-server]] (Rust HTTP; process enum/region list/read/pattern scan/filter on port 3030; PC-side Python client; cheat / iOS memory explorer) (source: wiki/sources/descriptions/gmh5225__memory_server.md); iOS modding engine [[h5gg]] (JavaScript APIs + HTML5 UI; memory edit, local/remote script load, dynamic plugins, static pointer-chain search; jailbroken and non-jailbroken runtime modes; h5frida plugin for ObjC/C++ hook/patch; cheat / IOS cheat engine) (source: wiki/sources/descriptions/H5GG__H5GG.md); leaked WebKit exploit toolkit [[coruna]] (multi-version iOS chains; partially deobfuscated; locally hostable scripts; cheat / iOS jailbreak) (source: wiki/sources/descriptions/khanhduytran0__coruna.md); IDA iOS reversing helper [[ida-ios-helper]] (needs vtable symbols) (source: wiki/sources/descriptions/yoavst__ida-ios-helper.md); Ghidra-based desktop IPA/macOS bundle decompiler [[malimite]] (LaurieWired; Java; automatic Apple resource decoding, Swift class reconstruction, Swift/ObjC binary support; iOS/macOS app RE, malware analysis, code auditing; cheat / iOS and macOS Decompiler) (source: wiki/sources/descriptions/LaurieWired__Malimite.md); LLM ARM64→C/ObjC/Swift pseudo-code for Mach-O (apps / kernelcache / DSC) via [[aimachdec]] (source: wiki/sources/descriptions/s3rg0x__AIMachDec.md); Binary Ninja Objective-C analysis workflow via [[workflow-objc]] (Vector35; C++; cleans up objc_msgSend dynamic-dispatch patterns into clearer direct-call HLIL when targets are inferable; macOS/iOS static RE; Cheat / `[Objective-C]`) (source: wiki/sources/descriptions/Vector35__workflow_objc.md); Apple runtime metadata browser [[runtime-viewer]] (MxIris-Reverse-Engineering; Swift/ObjC app; live ObjC/Swift interface inspection from loaded binaries/frameworks; export, framework loading, local/network access; WIP injection; macOS/iOS dynamic RE; Objective-C Runtime Viewer for macOS and iOS) (source: wiki/sources/descriptions/MxIris-Reverse-Engineering__RuntimeViewer.md); iOS kernelcache IDA analysis via [[ida-kernelcache-ng]] (pip package + `cli.py`; cheat / IDA Plugins) (source: wiki/sources/descriptions/gilboz__ida_kernelcache_ng.md); AArch64 MSR/SYS register naming via [[aarch64-sysreg-ida]] (TrungNguyen1909; Python; embedded ARMv8 register DB + optional Apple register JSON; XNU kernelcache MSR readability; cheat / IDA Plugins) (source: wiki/sources/descriptions/TrungNguyen1909__aarch64-sysreg-ida.md); C++ virtual-call resolution for iOS kernelcaches via [[ida-kcpp]] (IDAPython; class hierarchy from ida_kernelcache; double-click vcall navigation + xref tracking; cheat / IDA Plugins) (source: wiki/sources/descriptions/cellebrite-labs__ida_kcpp.md); PPL gate-call resolution for iOS/macOS kernelcaches via [[pplorer]] (IDAPython; PPL call site ↔ underlying PPL function; Ctrl-Shift-X + context-menu navigation; cheat / IDA Plugins) (source: wiki/sources/descriptions/cellebrite-labs__PPLorer.md); A12/A13 Apple PPL bypass library [[momentarius]] (C; IOMobileFramebuffer GPU firmware exploit → IOSurface physmem + ARM64 PTE/shellcode hooks → kernel R/W; Vortex/Tempest + Lightning/Thunder paths; cheat / iOS jailbreak kernel research) (source: wiki/sources/descriptions/staturnzz__momentarius.md); ANE multi-bug kernel R/W exploit chain [[weightbufs]] (0x36; Objective-C/C; chains ANE-related vulnerabilities on Neural-Engine-capable Apple devices; IOKit/IOSurface helpers; iOS 15 + macOS 12; tested device ranges and reliability notes; multi-stage XNU exploitation study; cheat / iOS jailbreak) (source: wiki/sources/descriptions/0x36__weightBufs.md); ImGui mod-menu samples such as [[imgui-ios-mod-menu]] (cheat / render-draw research) (source: wiki/sources/descriptions/xProHackerx__imgui-ios-mod-menu.md); Theos tweak mod-menu templates such as [[ios-mod-menu-template-for-theos]] (Logos/`tweak.xm`; 50×50 icon assets via base64 in standard template; cheat / `[IOS mod menu]`) (source: wiki/sources/descriptions/joeyjurjens__iOS-Mod-Menu-Template-for-Theos.md); Frida XPC message tracing on iOS/macOS via [[xpc-tracer]] (xpcspy variant; IPC RE in the cheat / Frida lane) (source: wiki/sources/descriptions/miticollo__xpc-tracer.md); QEMU-based VM host [[utm]] for iOS/macOS (Hypervisor.framework or JIT; Windows/Linux guests on Apple devices; `IOS Emulator` lane) (source: wiki/sources/descriptions/utmapp__UTM.md); device-fingerprinting / integrity SDK [[trustdevice-ios]] (TrustDecision CocoaPod; ObjC/Swift risk signals; `[IOS]` lane) (source: wiki/sources/descriptions/trustdecision__trustdevice-ios.md). Android Minecraft Bedrock Edition MITM cheat clients such as [[oxclient]] (Kotlin/Gradle; local packet relay; CloudburstMC Bedrock codecs + NBT; Microsoft device-code login; KillAura/CrystalAura/fly/speed/ESP modules; packet listeners + event bus; Bedrock multiplayer cheating + protocol RE; cheat / game:minecraft mobile) sit in the Android protocol-relay lane beside network capture tooling such as [[android-proxy-mcp]] and opposite Bedrock server-side AC proxies such as [[oomph]]. (source: wiki/sources/descriptions/adanainv3-creator__OxClient.md) **Unity/Unreal mobile:** Unity mobile game test-automation reference such as [[games-test-automation-example]] (UnityTech; Appium + in-game instrumentation logs; Android/iOS CI-style pipelines; Game Testing / QA automation) (source: wiki/sources/descriptions/UnityTech__GamesTestAutomationExample.md) sits in the defensive QA lane beside offensive Unity mobile tooling below. Cross-platform game/app UI automation via [[airtest]] (AirtestProject; Python; image-recognition UI targeting without process injection; device farms, CLI/Python APIs, HTML reports, IDE + Poco object hierarchy; Android/iOS/desktop; UI Automation Framework) complements Appium/instrumentation-first workflows when black-box regression is needed. (source: wiki/sources/descriptions/AirtestProject__Airtest.md) Distributed-build debug/bug-reporting via [[fastlogs]] (AitiX; Unity UPM + GameMaker GML clients; self-hosted Node.js/SQLite ingest; logs, device info, screenshots, and scene snapshots → short viewer links; WebGL/mobile/console targets where engine console is unreachable; headless send + remote command channel for QA/agents; Game Develop / debug) complements that QA lane for remote build triage. (source: wiki/sources/descriptions/AitiX__Fastlogs.md) Authorized mobile/game build validation orchestration via [[blc-gamesec-lab]] (BLCCoreStudio; Python CLI; BLCReverseLab intake, DEX/native version-diff intelligence, evidence graphs, incremental anti-cheat regression retest scoping; `blc.gamesec.report/v1`; authorized defensive assessment only) complements that QA lane for build-to-build security regression planning. (source: wiki/sources/descriptions/BLCCoreStudio__BLCGameSecLab.md) Exposed 8 Ball Pool cheat source such as [[alaa-8ball-pool-source-exposed]] (gmh5225; aim assist, trajectory prediction, shot-power calc from physics reads + guideline overlay; billiard mobile cheat pattern) sits in the title-specific physics-cheat lane beside overlay templates. (source: wiki/sources/descriptions/gmh5225__Alaa-8ball-pool-source-exposed.md) Curated Android modding repo collections such as [[android-modding]] (IL2CPP dump forks including kagurazakasanae Il2CppDumper YuanShen for Genshin `UserAssembly.dll`; cheat/guide offensive RE) sit in the same explorer lane as standalone templates. (source: wiki/sources/descriptions/jbro129__android-modding.md) APK-to-Android-Studio translators such as [[fakerandroid]] (gmh5225; javaScaffolding + fakeCpp JNI `.so` hooks + IL2CPP C++ scaffolding; smali-aware rebuild; cheat / game engine explorer:Unity) complement decode-only lanes when researchers need a runnable Gradle project for Unity IL2CPP modding. (source: wiki/sources/descriptions/gmh5225__FakerAndroid.md) Engine triage for packages via [[game-engine-detector]] (Python; which engine an `.apk` / `.ipa` uses) before deeper dumps. (source: wiki/sources/descriptions/walzer__game-engine-detector.md) Native Android UE4 SDK dumpers such as [[ue4dumper]] (C/C++; modding / SDK generation) sit in the Unreal side of that mobile explorer lane after engine fingerprinting. (source: wiki/sources/descriptions/kp7742__UE4Dumper.md) Emulator-targeted UE4 SDK dump forks such as [[ue4dumper-emulator]] (gmh5225; modding / SDK generation / memory analysis) extend that lane when titles run on Android emulator images. (source: wiki/sources/descriptions/gmh5225__UE4Dumper_Emulator.md) APK-oriented UE4 SDK dump tooling such as [[ue4-apk-dumper]] (gmh5225; UObject hierarchy / property offsets / function pointers from Android UE4 packages; `[SDK Dump For Android]`) sits in the same mobile Unreal explorer lane for physical-device and package-based workflows. (source: wiki/sources/descriptions/gmh5225__UE4-Apk-Dumper.md) Native Android NDK UE4 dump toolkits such as [[andue4dumper]] (MJx0; C++; external executable or injectable shared library; engine offsets/classes/structs/enums/functions + symbol JSON for IDA/Ghidra; `[SDK Dump For Android]`) extend that lane with NDK-built runtime dump workflows on physical Android devices. (source: wiki/sources/descriptions/MJx0__AndUE4Dumper.md) ImGui-equipped Android UE memory/SDK utilities such as [[bigwhite-tool]] (BigWhite666; C/C++; GName/GObject metadata traversal, process memory R/W, SDK dump generation; Vulkan/OpenGL overlay; NDK CMake; offset finding, runtime inspection, SDK extraction; `[SDK Dump For Android]`) complement those NDK dump toolkits with interactive runtime inspection. (source: wiki/sources/descriptions/BigWhite666__BigWhiteTool.md) iOS MobileSubstrate UE4 dump tweaks such as [[ios-ue4dumper]] (MJx0; C++/ObjC++; arm64/arm64e; pattern-based engine-structure discovery; offsets/classes/structs/enums/functions + symbol JSON for IDA/Ghidra; `[SDK Dump For IOS]`) extend that lane to jailbroken iOS Unreal titles. (source: wiki/sources/descriptions/MJx0__iOS_UE4Dumper.md) Lightweight native mobile engines such as [[skylicht-engine]] (Irrlicht evolution; Android/iOS source) sit in the adjacent Game Engine / mobile source lane beside Unity/Unreal package triage. (source: wiki/sources/descriptions/skylicht-lab__skylicht-engine.md) Cross-platform C++ 2D frameworks such as [[cocos2d-x]] (cocos2d-iphone lineage; multi-platform 2D games and graphical apps; Game Engine / source) extend that adjacent mobile native-engine lane. (source: wiki/sources/descriptions/cocos2d__cocos2d-x.md) Cross-platform C++ engines such as [[cocos4]] (COCOS 4; script bindings + rendering; write-once-run-anywhere; Game Engine / source) extend that lane beside [[cocos2d-x]]. (source: wiki/sources/descriptions/cocos__cocos4.md) The [[cocos-engine]] runtime (Cocos Creator editor framework; 3D/2D; Game Engine / source) is the production runtime behind Cocos Creator mobile and native titles in that lane. (source: wiki/sources/descriptions/cocos__cocos-engine.md) [[il2cpp]] (`libil2cpp.so` / UnityFramework + metadata), SDK dumps, memory editors (GameGuardian, [[h5gg]] for iOS) (source: wiki/sources/descriptions/H5GG__H5GG.md); CLI Android/Linux scanners such as [[mypower]] (SLJIT JIT scan expressions, pointer chains, snapshot diffs, Unity U3D object inspect). (source: wiki/sources/descriptions/vrolife__mypower.md) Root-privilege Unix-socket memory IPC kits such as [[root-socket-kit]] (LKM + Magisk/KernelSU/APatch JNI client; GUI search/edit; `OpenProcess` / `ReadMemory`) sit in the same Android memory-editor / root-ops lane. (source: wiki/sources/descriptions/systemnb__RootSocketKit.md) Upstream ARM64 Linux kernel driver suite [[rw-proc-mem33]] (process R/W, HW breakpoints, CE-style server demos, module hiding; abcz316) anchors that lane; forks such as [[rwmem]] (reliability caveats) extend it. (source: wiki/sources/descriptions/abcz316__rwProcMem33.md) (source: wiki/sources/descriptions/ri-char__rwMem.md) C++ Android memory editors such as [[android-mem-edit]] (process memory edit) sit in the same lane. (source: wiki/sources/descriptions/mrcang09__Android-Mem-Edit.md) Native `.so` memory-loading tooling such as [[so-loader]] (C/C++; Cheat / Android memory loading) sits in the adjacent memory-loading lane beside injectors such as [[android-ptrace-injector]]. (source: wiki/sources/descriptions/lockedbyte__so_loader.md) In-process ELF loaders such as [[mojoelf]] (buffer/non-filesystem ELF load; alternative to `dlopen()`) complement that lane for offensive memory-loading research. (source: wiki/sources/descriptions/icculus__mojoelf.md) Linux/Android HWBP process watching via [[pwatch]] (debug without attaching a conventional debugger) sits in the adjacent cheat / debugging research lane; C/C++ variant [[pwatch-c]] (enenH) covers the same HWBP lane (source: wiki/sources/descriptions/enenH__pwatch-c.md). (source: wiki/sources/descriptions/ri-char__pwatch.md) ARM64 Linux kernel HWBP module [[hardware-breakpoint]] (Ylarod; exported APIs + proc interfaces; execution/watch breakpoints by symbol or address; trigger stats; symbol resolve + phys I/O→virt map; kernel debugging / security research on Android/embedded; HWBP on linux/android) extends that lane with in-kernel breakpoint management. (source: wiki/sources/descriptions/Ylarod__hardware-breakpoint.md) IDA Android native `.so` breakpoint setup via [[ida-android-breakpoint]] (Python IDA plugin; static RE / debug prep; cheat / IDA Plugins) complements that lane for ARM/Android game `.so` workflows. (source: wiki/sources/descriptions/lj94093__IDAAndroidBreakpoint.md) Live Android full-memory minidump capture via [[lldbext-dump]] (LLDB Python extension → Windows-compatible `.dmp`; mapped regions / threads / modules; Unicorn replay companion) sits in the same native RE / offline dump lane. (source: wiki/sources/descriptions/mrexodia__lldbext-dump.md) APK IL2CPP disassembly/diff via [[il2cpp-spy]] (select two APKs → show differences). (source: wiki/sources/descriptions/yukiarrr__Il2cppSpy.md) iOS Unity speed/modding tooling such as [[unityspeedtools]] (C/C++ / Objective-C; IL2CPP analysis) sits in the same explorer:Unity lane. (source: wiki/sources/descriptions/xxzzddxzd__unitySpeedTools.md) Android IL2CPP `Time` speed-hack tooling such as [[android-il2cpp-modspeed]] (C++ native; `deltaTime` / `timeScale` / fixed timestep; `[Il2Cpp hack speed]`) complements that lane. (source: wiki/sources/descriptions/oobbb__android-il2cpp-modspeed.md) Fall Guys Android IL2CPP Frida mod-menu samples such as [[fallguys-frida-modmenu]] (repinek; TypeScript + [[frida-il2cpp-bridge]] + frida-java-menu overlay; Objection/APKEditor APK patch; movement/teleport/ban-bypass; cheat / game:fallguys mobile) sit in the title-specific Unity mobile mod-menu lane beside generic IL2CPP speed hooks. (source: wiki/sources/descriptions/repinek__fallguys-frida-modmenu.md) Among Us Android IL2CPP Frida mod-menu samples such as [[malum-menu-android]] (astra1dev; TypeScript + [[frida-il2cpp-bridge]] + frida-java-menu overlay; Objection Frida gadget embed for non-root; NoClip/speedhack/ESP/ship-control/cosmetics; cheat / game:among-us mobile) sit in the same title-specific Unity mobile mod-menu lane. (source: wiki/sources/descriptions/astra1dev__MalumMenu-Android.md) Title-specific Pokemon GO IL2CPP dump tooling such as [[pokemongo-dumper]] (gmh5225; C#/C++; cheat / game:pokemongo) sits in the same Unity mobile explorer lane. (source: wiki/sources/descriptions/gmh5225__PokemonGoDumper.md) On-device Android GUI IL2CPP dump tooling such as [[il2cppdumpdroidgui]] (Poko-Apps; Il2CppDumper GUI adaptation; APK releases with docs/config; Android 6–14; armeabi-v7a/arm64-v8a; follows upstream Il2CppDumper; cheat / `[Il2Cpp Dump GUI]`) simplifies mobile dump workflows without Termux CLI. (source: wiki/sources/descriptions/Poko-Apps__Il2cppDumpDroidGUI.md) Zygisk runtime IL2CPP dump modules such as [[zygisk-il2cppdumper]] (Perfare; C/C++; post-load metadata extraction; bypasses static encryption/obfuscation/packing on protected mobile Unity builds; cheat / `[Il2Cpp Dump for Android Platform]`) complement GUI/static dump lanes when analysts need rooted Zygisk injection. (source: wiki/sources/descriptions/Perfare__Zygisk-Il2CppDumper.md) Fork [[zygisk-il2cppfucker]] (Darlenepurpleblack444; in-process memory R/W, instance scan, `il2cpp_runtime_invoke`, Lua 5.4 + overlay; live RE without external attach) extends that Zygisk IL2CPP lane beyond metadata dump. (source: wiki/sources/descriptions/Darlenepurpleblack444__Zygisk-Il2CppFucker.md) Title-specific Call of Duty Mobile IL2CPP dump packages such as [[codm-dumper]] (Poko-Apps; release distribution; armv7/arm64; Termux; `dump.cs` / `ida.py` / IDA JSON; author-deprecated; cheat / `[il2cpp dump]`) sit in the same title-specific Unity mobile dump lane. (source: wiki/sources/descriptions/Poko-Apps__CodMDumper.md) All-in-one Battle Cats desktop toolkit [[battle-cats-complete]] (Rust; `.pack`/APK/XAPK import, encrypted-archive decrypt/extract, cat/enemy/stage parse, animation render, MP4/AVIF/WebP/GIF export, pack mod + APK sign; modding / asset RE) sits in the adjacent title-specific mobile modding lane. (source: wiki/sources/descriptions/omochikaeri15__battle-cats-complete.md) Android-hosted authoritative game-server stacks such as [[mapleserver-android]] (gmh5225; MapleStory GMS-083 private-server logic on-device; character management / world simulation; cheat / mobile-security / game:maplestory) sit in the adjacent mobile private-server lane beside client modding templates. (source: wiki/sources/descriptions/gmh5225__MapleServerAndroid.md) **Flutter/Dart:** Flutter freeRASP plugin [[free-rasp-flutter]] (Dart + Kotlin/Swift; Talsec runtime; root/jailbreak/Frida/debugger/emulator/tamper/device-binding/Appium/VPN/location-spoof; optional termination; freemium client hardening for games and high-value apps). (source: wiki/sources/descriptions/talsec__Free-RASP-Flutter.md) AOT snapshot symbol recovery via [[unflutter]] (Dart VM snapshot metadata → class/function/type names from Flutter APKs/iOS apps) (source: wiki/sources/descriptions/zboralski__unflutter.md). Guardsquare Flutter RE experiment kit [[flutter-re-demo]] (Python IDA scripts; reFlutter/DWARF Dart rename, VM memory import, object/xref recovery, decompilation aids; Frida runtime capture; obfuscated/non-obfuscated sample APKs; Flutter app protection / Dart decompilation study). (source: wiki/sources/descriptions/Guardsquare__flutter-re-demo.md) **Kotlin Multiplatform:** KMP freeRASP plugin [[free-rasp-kmp]] (shared Kotlin + Gradle multiplatform; native Talsec runtime per platform; root/jailbreak/Frida/untrusted installs/automation/suspicious apps; threat callbacks + optional termination; client hardening for KMP mobile apps including games). (source: wiki/sources/descriptions/talsec__Free-RASP-KMP.md) ## Related concepts [[research-rigor]] · [[mobile-trust-boundaries]] · [[mobile-anti-cheat]] · [[laneguard]] · [[android-hardware-attestation-demo]] · [[trickystore]] · [[freedom]] · [[android-modding]] · [[fakerandroid]] · [[arkdecompiler]] · [[rescuex]] · [[webui-x-portable]] · [[zamr]] · [[pif-config-generator]] · [[fox-magisk-module-manager]] · [[flagsecurepatcher]] · [[anti-screenshot-capture]] · [[zygisk]] · [[frida]] · [[ksu-rust-frida]] · [[rust-frida]] · [[mkpms]] · [[frida-android-hook]] · [[frida-mobile-kit]] · [[florida]] · [[phantom-frida]] · [[strongr-frida-android]] · [[frida-stealth]] · [[morphida]] · [[fridare]] · [[florida-zygisk]] · [[magisk-hluda]] · [[rezygisk]] · [[frida-il2cpp-datacollector]] · [[il2cpp-hook-scripts]] · [[il2cpp-hookscripts]] · [[frida-ceserver]] · [[ceserver-ios]] · [[h5gg]] · [[kittymemory]] · [[kittymemory-ios]] · [[il2cpp]] · [[locusmimic]] · [[anywhere]] · [[hidemyandroid]] · [[device-reset-spoofer]] · [[usb-detection-bypass]] · [[android-faker]] · [[copg]] · [[xposed-module-kit]] · [[lsposed-universal-template]] · [[apppealing-new]] · [[canyie-pine]] · [[yahfa]] · [[bypass-hidden-api-restriction]] · [[android-hidden-api-bypass]] · [[stoic]] · [[knoxpatch]] · [[ios-jailbreak-fugu15]] · [[def1nit3lyn0tajailbreaktool]] · [[ios-location-spoofer]] · [[wloc]] · [[ptfaketouch]] · [[last-island-of-survival-ioscheat-source]] · [[game-engine-detector]] · [[ue4dumper]] · [[ue4-apk-dumper]] · [[andue4dumper]] · [[bigwhite-tool]] · [[ios-ue4dumper]] · [[ue4dumper-emulator]] · [[memdumper]] · [[zygisk-memdump]] · [[skylicht-engine]] · [[cocos2d-x]] · [[cocos4]] · [[cocos-engine]] · [[il2cpp-spy]] · [[mypower]] · [[root-socket-kit]] · [[rw-proc-mem33]] · [[skroot-linux-kernel-root]] · [[rwmem]] · [[android-mem-edit]] · [[android-memory-tool]] · [[c-android-memory-tool]] · [[so-loader]] · [[mojoelf]] · [[pwatch]] · [[pwatch-c]] · [[hardware-breakpoint]] · [[termux-app]] · [[neotty]] · [[neoterm]] · [[android-terminal-emulator]] · [[ashellyou]] · [[xfiles]] · [[file-explorer]] · [[raival-file-explorer]] · [[app-manager]] · [[butler]] · [[note]] · [[unityspeedtools]] · [[android-il2cpp-modspeed]] · [[fallguys-frida-modmenu]] · [[unflutter]] · [[flutter-re-demo]] · [[apktool]] · [[jadx]] · [[android-classyshark]] · [[bytecode-viewer]] · [[nightowl]] · [[dex2jar]] · [[dalivm]] · [[dalvikus]] · [[garlic]] · [[r2garlic]] · [[apktool-mcp-server]] · [[delamain]] · [[obfu-de-scate]] · [[dexkit-android]] · [[android-unpacker]] · [[apkid]] · [[nmmp]] · [[android-native-import-hide]] · [[android-library-remap-hide]] · [[asctool]] · [[apksigcopier]] · [[apksigner]] · [[android-proxy-mcp]] · [[lamda]] · [[rootraven]] · [[moabille]] · [[frida-ide]] · [[peetch]] · [[btrace]] · [[tracee]] · [[android-ebpf]] · [[android-kernel-exploitation]] · [[android-kernel-exploitation-lab]] · [[android-vuln]] · [[android-vuln-poc-exp]] · [[honor-of-kings-re-research]] · [[magisk]] · [[zygisk-dump-dex]] · [[zygisk-imgui-mod-menu]] · [[zygisk-imgui-modmenu]] · [[imgui-zygisk-unity]] · [[android-virtual-inject]] · [[android-virtualcam-manager]] · [[android-ptrace-injector]] · [[android-ld-preload-injector]] · [[yaui]] · [[linjector-rs]] · [[kernelsu]] · [[kernelsu-4.4]] · [[dirtypiperoot]] · [[dirtypipe-android]] · [[cheese]] · [[magiskdetector]] · [[detection]] · [[android-native-root-detector]] · [[easypixel]] · [[event-replay]] · [[android-virtual-touch]] · [[android-touch]] · [[keyattestation]] · [[keybuster]] · [[armageddon]] · [[droidshield]] · [[conbeerlib]] · [[anti-emulator]] · [[android-emulator-detection]] · [[free-rasp-android]] · [[free-rasp-ios]] · [[free-rasp-unity-poc]] · [[com-sipvlib-anticheat]] · [[free-rasp-reactnative]] · [[react-native-shieldscan]] · [[react-native-device-risk-signals]] · [[free-rasp-capacitor]] · [[free-rasp-cordova]] · [[free-rasp-flutter]] · [[free-rasp-kmp]] · [[rs-native-kit-security]] · [[trustdevice-android]] · [[trustdevice-ios]] · [[swsim]] · [[embedded-hacking]] · [[sjcam]] · [[swift-string-obfuscator]] · [[swiftshield]] · [[dprotect]] · [[cve-2026-43499-popsicle]] · [[cve-2020-0041]] · [[cve-2019-2215]] · [[cve-2024-0044]] · [[cve-2021-1961]] · [[move-certificate]] · [[magiskboot]] · [[magiskboot-linux]] · [[magiskboot-ndk-on-linux]] · [[magiskboot-build]] · [[android-boot-image-editor]] · [[qualcomm-avb-exploit-poc]] · [[payload-dumper]] · [[payload-dumper-go]] · [[android-bootable-recovery-ofrp]] · [[ofrp-device-xiaomi-mondrian]] · [[device-xiaomi-mondrian]] · [[kernel-devicetree]] · [[android-rom-list]] · [[pixel-flasher]] · [[rom-shifter]] · [[xiaomi-hyperos-bootloader-bypass]] · [[root-my-galaxy]] · [[root-my-pixel]] · [[op7t]] · [[rnidbg]] · [[ovo]] · [[android-wuwa]] · [[compile-android-driver]] · [[android-kernel-hacking-toolkit]] · [[kernel-hack]] · [[kernel-driver-hack]] · [[android-kernel-xiaomi-pipa]] · [[android-kernel-xiaomi-sweet]] · [[android-kernel-xiaomi-sm8475]] · [[android-kernel-motorola-dubai]] · [[android-kernel-oneplus-sm8250]] · [[android-kernel-oneplus-sm7250-wksu]] · [[pc-ginkgo]] · [[kernelsu-pixel4xl]] · [[kernel-msm-coral]] · [[android-kernel-samsung-universal5433]] · [[android-kernel-samsung-sm7150]] · [[android-kernel-huawei-mt6761]] · [[android-kernel-huawei-hi6250-8-exp]] · [[dpatch]] · [[simpleperf-demo]] · [[oob-entry]] · [[dopamine]] · [[dopamine2-roothide]] · [[palera1n]] · [[lightsaber]] · [[lara]] · [[dirty-zero]] · [[darksword-kexploit-fun]] · [[bad-query]] · [[xnu-1day-practice]] · [[xnu-qemu-arm64]] · [[vphone-cli]] · [[vphone-aio]] · [[usbliter8-fun]] · [[mdc0]] · [[humptylock]] · [[xnuspy]] · [[kfd]] · [[kfd-explorer]] · [[weightbufs]] · [[momentarius]] · [[cve-2026-xnu-aio-kevent-uaf]] · [[memory-server]] · [[coruna]] · [[ida-ios-helper]] · [[ida-android-breakpoint]] · [[aimachdec]] · [[ipapatch]] · [[disable-call-recording-bookrestore]] · [[xkvm-ios-injector]] · [[ios-packager]] · [[shadow]] · [[ihide]] · [[trollstore]] · [[opainject]] · [[imgui-ios-mod-menu]] · [[ios-mod-menu-template-for-theos]] · [[imgui-unity]] · [[imgui-unity-with-layout]] · [[imgui-unity-android]] · [[unity-imgui-android]] · [[polarimgui]] · [[external-imgui-android]] · [[android-native-surface]] · [[android-modmenu-semijni]] · [[android-mod-menu-kotlin]] · [[android-mod-menu]] · [[android-cheat-template]] · [[android-opengl-es-chams]] · [[android-native-app-imgui]] · [[android-imgui-menu]] · [[imgui-native-modmenu]] · [[bypass-pubg-mobile-imgui]] · [[china-pubg]] · [[pubg-mobile-pak-extract]] · [[pubg-mobile-memory-hacking]] · [[pubg-mobile-memory-hacking-examples]] · [[pubgm-pubgpatcher]] · [[pubgm-shitty-source]] · [[pubgm-sdk-and-offsets]] · [[pubgm1.6-deadgame]] · [[pokemongo-dumper]] · [[battle-cats-complete]] · [[utm]] · [[droidvm]] · [[gunyah-hypervisor]] · [[qemu-gvm]] · [[android-emulator-hypervisor-driver]] · [[anbox]] · [[android-emulator]] · [[yuzu-android]] · [[aeroot]] · [[rootavd]] · [[how-to-download-and-install-wsa]] · [[win11-apk-installer]] · [[wsapatch]] · [[wsa-pacman]] · [[wsa-builds]] · [[wsa-kernel-build]] · [[wsa-linux-kernel]] · [[magiskonwsalocal]] · [[overviews/game-hacking]] · [[overviews/reverse-engineering]] ## README map Cheat Magisk/Xposed/Frida/ART-syscall hooks (incl. 3v1lC0d3/[[root-detection-low-level]] Frida `java.io.File`/`Runtime.exec` root-detection path logging; source: wiki/sources/descriptions/3v1lC0d3__Root_Detection_Low_level.md + [[moabille]] multi-device Android/iOS TUI with Frida, Objection, adb, scrcpy, and iproxy; source: wiki/sources/descriptions/jafarm189__MOABile.md) + [[frida-ide]] web Frida IDE with JADX decompilation + Claude assistant; source: wiki/sources/descriptions/MrOplus__frida-ide.md) + RytterMohn/[[usb-detection-bypass]] LSPosed USB/ADB detection masking in Xposed; source: wiki/sources/descriptions/RytterMohn__UsbDetectionBypass.md) + CHERWING/[[xiaomi-usb-security-bypass]] Magisk MIUI USB debugging/fastboot account-SIM gate bypass for scrcpy input injection; source: wiki/sources/descriptions/CHERWING__xiaomi_usb_security_bypass.md)/Android Root Morphe patch catalog [[nai64-patches]] (root/integrity bypass, license checks, Play Integrity spoof, SSL pinning; source: wiki/sources/descriptions/Nai64__Nai64Patches.md)/curated MMRL module repository [[zamr]] (Play Integrity Fix, Zygisk, root-hide, TEESimulator; hourly refreshed JSON catalog; cheat / Magisk; source: wiki/sources/descriptions/zelect0r__zamr.md)/automated PIF profile generator [[pif-config-generator]] (Pixel build.prop tag tracking, validated JSON device profiles, pif-gen CLI; source: wiki/sources/descriptions/Elcapitanoe__pif-config-generator.md)/Android Terminal (ADB/root/shell; Shizuku/OTG/wireless; [[ashellyou]] on-device ADB utility; source: wiki/sources/descriptions/DP-Hridayan__aShellYou.md)·File·Memory·Network Explorer (incl. [[pcapdroid]] + no-root RTL8852AU monitor/inject [[rtl8852au-userspace]]; source: wiki/sources/descriptions/damanoreshkan-beep__rtl8852au-userspace.md)/kernel*/driver/bootloader bypass/ROM/device-trees/root/memory-loading/App+Kernel CVE/Cellular-SIM/IoT trees (pure-software USIM/UICC simulators such as [[swsim]] for APDU/MILENAGE / SIMtrace2 phone testing) (source: wiki/sources/descriptions/tomasz-lisowski__swsim.md); Xiaomi kernel device-tree branch index such as [[kernel-devicetree]] (MiCode; README lookup table mapping branches→devices/platform tags/release baselines; kernel bring-up / board config / compatibility research) (source: wiki/sources/descriptions/MiCode__kernel_devicetree.md); Xiaomi/Redmi kernel source branch catalog such as [[xiaomi-kernel-opensource]] (MiCode; Markdown tables mapping device/Android version→branch tags and base refs; vendor kernel discovery for driver dev, auditing, platform debugging) (source: wiki/sources/descriptions/MiCode__Xiaomi_Kernel_OpenSource.md); action-camera firmware RE such as [[sjcam]] (SJ4000 Air / Allwinner V3; AVIOCTRL TCP; Lelouch Android ARM CFW; CVE-2026-52656 PoC) (source: wiki/sources/descriptions/keowu__sjcam.md); Xiaomi HyperOS bootloader account-binding bypass PoC such as [[xiaomi-hyperos-bootloader-bypass]] (MlgmXyysd; PHP automation + Docker/shell + ADB libraries; reproducible unlock workflow; mobile bootloader restriction research) (source: wiki/sources/descriptions/MlgmXyysd__Xiaomi-HyperOS-BootLoader-Bypass.md); Xiaomi Smart Camera C400 exploit/jailbreak research such as [[xiaomi-c400-pwn]] (Python RNG-prediction exploit; Tamarin handshake models; persistent jailbreak; IoT firmware exploitation; TaszkSecLabs) (source: wiki/sources/descriptions/TaszkSecLabs__xiaomi-c400-pwn.md); Pico 2 / RP2350 embedded firmware RE course such as [[embedded-hacking]] (Pico SDK labs; GPIO→inline ARM asm; GDB/Ghidra/OpenOCD; ARM Thumb FP binary patcher; IoT / hardware hacking) (source: wiki/sources/descriptions/mytechnotalent__embedded-hacking.md); iOS jailbreak+network/location; Anti Cheat Detection:Android root; platform cats `WSA` (~9; manual install guide [[how-to-download-and-install-wsa]] (K3V1991; step-by-step Win11 setup; Developer Mode + Virtual Machine Platform; dependency packages; Explorer/PowerShell bundle install; manual workflow) (source: wiki/sources/descriptions/K3V1991__How-to-download-and-install-WSA.md); Win11 APK installers such as [[win11-apk-installer]] (source: wiki/sources/descriptions/sergiovillaverde__win11_apk_installer.md); local Magisk/KernelSU+GApps+LSPosed WSA builds via [[magiskonwsalocal]] (Python/shell extract+patch scripts; installable rooted WSA; LSPosed; source: wiki/sources/descriptions/LSPosed__MagiskOnWSALocal.md); MSIX patcher [[wsapatch]] for Win10/older Win11 (version-check + Hyper-V bypass; sideload on unsupported hosts) (source: wiki/sources/descriptions/cinit__WSAPatch.md); Flutter/Dart GUI package manager [[wsa-pacman]] (APK/XAPK double-click install, metadata, upgrade/downgrade, WSA settings shortcuts; sideload workflow) (source: wiki/sources/descriptions/alesimula__wsa_pacman.md); kernel mirror/build automation [[wsa-linux-kernel]] (stock + KernelSU branches; GitHub Actions x86_64/arm64 images; helper script for KernelSU config; reproducible WSA kernel customization) (source: wiki/sources/descriptions/WSA-Community__WSA-Linux-Kernel.md); Docker-based WSA kernel build environment [[wsa-kernel-build]] (KiruyaMomochi; packaged cross-compilation toolchain for x86_64/arm64; reproducible local/CI builds; custom kernel testing/instrumentation; Cheat WSA / Build WSA Kernel with Docker) (source: wiki/sources/descriptions/KiruyaMomochi__wsa-kernel-build.md); prebuilt customized WSA distribution [[wsa-builds]] (Magisk/KernelSU + optional GApps variants; automation scripts; install/troubleshoot/recovery docs; multi-version Windows compatibility; MustardChef) (source: wiki/sources/descriptions/MustardChef__WSABuilds.md); kernel module [[wsa-kernel-su]] (LSPosed; syscall hooks for `/system/xbin/su`; credential/SELinux adjustments; low-level C; optional superuser stealth; WSA with KernelSU) (source: wiki/sources/descriptions/LSPosed__WSA-Kernel-SU.md)), `Android Emulator` (~9; Genymotion/[[anbox]] (container-based full Android on Linux via LXC + host daemon; OpenGL ES from emulator components; archived reference; cheat / Android Emulator) (source: wiki/sources/descriptions/anbox__anbox.md) + Snapdragon on-device VM [[droidvm]] (Gunyah + crosvm/QEMU; ARM64/x86_64 guests; UEFI Linux/Windows; VirGL/GfxStream GPU, VNC, VirtFS; root required) (source: wiki/sources/descriptions/Droid-VM__DroidVM.md); ARM64 Type-1 reference HV [[gunyah-hypervisor]]; AMD/Intel QEMU research host [[qemu-gvm]]; Google KVM-on-Windows acceleration via [[android-emulator-hypervisor-driver]] (Android Studio Emulator; Win8.1+ x64); emulation-focused [[android-emulator]]; native Switch playback on-device via [[yuzu-android]] (yuzu Android port; ARM64 JIT; Vulkan/OpenGL) (source: wiki/sources/descriptions/gmh5225__yuzu-android.md) and Eden-based [[opensw]] (RemiPelloux; ARM64 JIT; Vulkan/OpenGL; build-ID-aware Atmosphere/Eden cheat import; dmnt-style cheat engine; per-game profiles; Cockpit panel; Profile build automation bridge) (source: wiki/sources/descriptions/RemiPelloux__OpenSw.md); Windows x86/x64 apps on ARM Android via [[winlator]] (Box86/Box64 + Wine + PRoot Linux container; Mesa Turnip/VirGL; virtual desktop + touch controls; cheat / Windows Emulator) (source: wiki/sources/descriptions/brunodev85__winlator.md); runtime emulator root via [[aeroot]] without system-image rewrite; AVD Magisk/root via [[rootavd]]) (source: wiki/sources/descriptions/quic__gunyah-hypervisor.md) (source: wiki/sources/descriptions/qemu-gvm__qemu-gvm.md) (source: wiki/sources/descriptions/google__android-emulator-hypervisor-driver.md) (source: wiki/sources/descriptions/jwmcglynn__android-emulator.md) (source: wiki/sources/descriptions/quarkslab__AERoot.md) (source: wiki/sources/descriptions/newbit1__rootAVD.md), `IOS Emulator` (~5; qemu-apple-silicon + Virtualization.framework vphone-cli/[[vphone-ws]]/aio PCC research VMs + [[darwin-vm]] QEMU Darwin root shell)). (source: wiki/sources/README-categories.md)