opensourceprojects.dev

A broadsheet for software that doesn't ask for your email

Hook Android and iOS methods at runtime with a FRIDA-powered web interface
GitHub RepoImpressions3

Project Description

View on GitHub

Hook Android and iOS Methods at Runtime Without Writing a Single Frida Script

You've got an app running on your test device, and you want to see what it's actually doing. Maybe you need to inspect a method's arguments, dump loaded classes, or trace a return value. The usual answer is Frida, and the usual next step is writing a pile of JavaScript to get there. Runtime Mobile Security (RMS) is a web interface built on top of Frida that lets you do most of that work by clicking instead of coding.

What It Does

RMS is a web interface powered by Frida that helps you manipulate Android and iOS apps at runtime. Instead of scripting every hook by hand, you point RMS at a running app and work through a browser-based UI.

The core capabilities, straight from the project's description: dump all loaded classes and their relative methods, hook anything on the fly, trace method arguments and return values, and load custom scripts when you need to go beyond the built-in tooling. It runs as an npm package and talks to Frida server on your target device, so the architecture is straightforward — Node.js on your desktop, Frida's CLI tools doing the instrumentation, and a web UI sitting on top as the control surface. It works on both Android and iOS, which is worth noting since a lot of runtime tooling picks one platform and stays there.

Why It's Cool

  • The web interface is the whole point. Frida is powerful, but the learning curve for writing correct hooks is real. RMS trades the script-editing loop for a UI where you browse classes, pick methods, and hook them. That's a meaningfully lower barrier for anyone who's new to runtime instrumentation, and a faster workflow for people who aren't.

  • It covers the full loop: inspect, hook, trace, extend. Dumping loaded classes and methods is step one. Hooking on the fly is step two. Tracing arguments and return values is step three. And when the built-in options aren't enough, you can load custom scripts — so the UI doesn't box you in.

  • Cross-platform from a single install. One npm package, one interface, both Android and iOS. If you work across both platforms (or you're learning mobile security and don't want to commit to one ecosystem yet), that's a practical win.

  • There's real tutorial material behind it. The README links to walkthroughs for solving OWASP UnCrackable Android App Level 1 and Level 2, plus a SANS Holiday Hack Challenge 2024 writeup and video by Andrea Lamonato. That's a strong signal — this isn't a project that just documents its features, it demonstrates them against exercises designed to test exactly this kind of tooling.

  • The prerequisites are honest. Node.js, Frida's CLI tools, and a running Frida server on the device. No hidden requirements, and the README walks you through a smoke test (frida-ps -U) so you know Frida is working before you blame RMS for anything.

How to Try It

  1. Install Node.js and Frida's CLI tools on your computer. You'll need Frida server running on the target device — the README links to the official Android and iOS setup guides.

  2. Confirm Frida actually works before going further. Run this from your desktop and check that you get a process list back:

frida-ps -U
  1. Install RMS globally via npm:
npm install -g rms-runtime-mobile-security

One note from the README: if the frida-node dependency gives you trouble, there's a linked troubleshooting post by Chichou about choosing the right Node.js version.

  1. Make sure frida-server is up on the device, then launch RMS with the rms command.

On Android, the README also points to MagiskFrida and FridaLoader for automating Frida installation, updates, and startup. Those aren't needed on iOS — with a jailbroken device, Frida starts right after boot.

The repository is at github.com/m0bilesecurity/rms-runtime-mobile-security.

Final Thoughts

RMS is best suited to mobile security researchers, pentesters, and developers doing reverse engineering or dynamic analysis who want to move faster than hand-written Frida scripts allow. If you're already fluent in Frida scripting, you might find the UI slower for complex work — but the custom script loading means you can drop back to your own code when you need to. If you're newer to runtime instrumentation, this is a reasonable place to start, especially with the OWASP UnCrackable walkthroughs as guided practice. Either way, it removes a layer of friction between you and what an app is doing at runtime, and that's a useful thing to have in your toolkit.


Follow @githubprojects for more developer tools and open source projects.

Back to Projects
Project ID: 29d9200b-ac5a-472b-af0c-6b505e92ca93Last updated: September 30, 2026 at 02:48 AM