Ross ROSS = Recommend OSS · open-source software intelligence for agents

CreditTone/hooker

🔥🔥 hooker is a Frida-based reverse engineering toolkit for Android. It offers a user-friendly CLI, universal scripts, auto hook generation, memory roaming to detect activities/services, one-click SOCKS5 proxy setup, Frida JustTrustMe, and BoringSSL unpinning for all apps. observed · 2026-08-28

github.com/CreditTone/hooker · JavaScript observed · 2026-08-28

Health v2 · maintenance only

70/100

  • Activity 84
  • Release rhythm 35
  • Longevity 100

Flags: no_releases no_license

How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-02. Adoption (stars, forks) is never an input.

  • gap_med: n/a
  • age_days: 2348
  • days_rel: n/a
  • days_push: 98
  • n_releases_24m: 0

Full methodology

Adoption not part of the score

5285 stars · 1266 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-29, confidence not recorded

hooker is a Frida-based reverse engineering toolkit for Android that provides a comfortable command-line interface with universal hooking scripts. It includes auto-generated hook scripts, memory roaming to detect activities/services, a Frida version of JustTrustMe, BoringSSL SSL unpinning, an embedded webserver for exposing app capabilities as HTTP APIs, and one-click SOCKS5 proxy setup.

Use cases

  • bypass SSL certificate pinning in Android apps
  • hook Java and native methods in an APK with Frida
  • dump DEX files and keystores from a running app
  • trace JNI method calls and ART method registration
  • set up a SOCKS5 proxy on a rooted Android device without extra apps
  • expose app internal functions as HTTP endpoints for automation
  • detect anti-Frida protections in an app
  • capture network traffic and SSL logs from an Android app

When to choose

  • you do Android reverse engineering with Frida and want a friendly CLI plus ready-made universal scripts
  • you need maintained SSL unpinning (JustTrustMe/BoringSSL) that works across many apps
  • you want to automate app analysis with auto-generated hook scripts or an embedded webserver API

When to avoid

  • you need a no-root solution or cannot attach Frida to the target device
  • you only want static APK analysis without a rooted device or dynamic instrumentation
  • you require a formally licensed project for commercial or compliance-sensitive use (no license is provided)

Facets

cli-tool · maturity active

reverse-engineering security cli http-server proxy developer-tools reverse-engineering security android-tools developer-tools python cli windows frida android ssl-unpinning justtrustme boringssl hook-scripts xposed apk-analysis socks5-proxy memory-roaming mcp command-line linux macos

1 source

Member repositories

RepositoryRoleHealth v2
CreditTone/hookermain70

For agents

markdown · JSON · MCP: product_card(name="CreditTone/hooker")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem