
MobSF
Open-source framework for static and dynamic security testing of Android, iOS and Windows mobile apps via a self-hosted web UI.
0 upvotes · 0 downvotes
- Category
- Mobile Security
- Pricing
- Freemium
- Platforms
- WebLinux
- Licence
- Open source
- Reviewed
- Last reviewed 30 September 2026
**What it is**
Mobile Security Framework (MobSF) is an open-source security research platform for mobile applications. It automates static and dynamic analysis for Android, iOS and Windows mobile packages, with a web UI for interactive review and integrations for DevSecOps pipelines.
**What it helps with**
- Static analysis of mobile binaries and source (APK, IPA, APPX and related formats described in the docs)
- Dynamic analysis and instrumented testing for Android and iOS applications
- Malware, privacy and configuration review workflows for mobile apps
- Generating findings for manual review or CI via REST APIs and CLI tooling
- Running locally with Docker or trying the hosted static analyser at mobsf.live
**Who it's for**
Mobile application security testers, penetration testers, malware analysts and development teams that need an open-source static/dynamic assessment workflow. Enterprise support and training are sold separately by OpenSecurity; the core framework remains open source.
**Worth knowing**
Default Docker credentials and deployment steps are documented on the project README; change defaults before any shared deployment. Dynamic analysis needs a suitable mobile runtime/emulator setup. Optional paid support does not change the open-source licence of the core project. Listing summarises public GitHub and documentation pages only.